Blog | G5 Cyber Security

New CIA Cyberweapon Malware Pandemic installed in Victims Machine and Replaced Target files where remote users use SMB to Download

Pandemic Malwares Actual Goal is to be installed in Victims Machine when the Victims remote users use SMB to download/execute PE files. The Payload files will be Replaced to the Actual Target file. This function will work in Read-only Mode and run as kernel shellcode to install File system Driver. The tool can operate both 32 and 64 bit. It will not replace the Target file if the file is opened on the machine Where Pandemic is running on.”]

Source: https://gbhackers.com/new-cia-cyberweapon-malware-pandemic-installed-in-victims-machine-and-replaced-target-files-where-remote-users-use-smb-to-download/

Exit mobile version