Get a Pentest and security assessment of your IT network.

News

xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection

In June 2019, we observed one of these overlapping domains, specifically, windows64x[.]com, being used as the C2 server for a new. backdoor that weve named CASHY200. This. backdoor used DNS tunneling to communicate with its C2. server, specifically by issuing DNS A queries to the actor controlled name server at the aforementioned domain. By analyzing the lineage of this tool, we found that actors may have used CASH.Y200 when targeting Kuwait government organizations starting in the spring of 2018 and continuing throughout 2019.”]

Source: https://unit42.paloaltonetworks.com/more-xhunt-new-powershell-backdoor-blocked-through-dns-tunnel-detection/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

Linux bug leaves 1.4 billion Android users vulnerable to hijacking attacks