Blog | G5 Cyber Security

FIN7 Group Uses JavaScript and Stealer DLL Variant in New Attacks

A newly discovered RTF document family is being leveraged by the FIN7 group (also known as the Carbanak gang) This document is used in phishing campaigns to execute a series of scripting languages containing multiple obfuscation mechanisms. The document contains messages enticing the user to click on an embedded object that executes scripts which are used to infect the system with an information stealing malware variant. This malware is then used to steal passwords from popular browsers and mail clients which are sent to remote nodes that are accessible to the attackers.”]

Source: https://blog.talosintelligence.com/2017/09/fin7-stealer.html

Exit mobile version