New APT group has emerged targeting Russian energy and aviation industry in Russia. ChamelGang, dubbed for its chameleon-like capabilities, first appeared in March. Group exploits known vulnerabilities in Microsoft Exchange Servers ProxyShell. Group uses both known malicious programs such as FRP, Cobalt Strike Beacon, Tiny Shell, as well as previously unknown malware ProxyT, Beacon loader and the DoorMe backdoor, researchers say. Group hides its malware and network infrastructure under legitimate services of established companies like Microsoft, TrendMicro and Google.”]
Source: https://threatpost.com/apt-chamelgang-targets-russian-energy-aviation/175272/

