Get a Pentest and security assessment of your IT network.

News

Is APT27 Abusing COVID-19 To Attack People ?!

Security researcher Marco Ramilli analyzed a new Coronavirus (COVID-19)-themed attack gathering evidence of the alleged involvement of an APT group. The first stage is a fake PDF file used to run initial infection chain. Stage 1 carved Stage 2 from its body by extracting bytes and decoding them using base64 encoding. Stage 2 is a Microsoft compressed CAB file described in the following table. The following image shows the beautified code section of the analyzed file. The attacker copied certutils from local system, by using (ertu.exe) in order to avoid command line detection from public sandboxes.”]

Source: https://securityaffairs.co/wordpress/99977/apt/apt27-abusing-covid-19.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin