Get a Pentest and security assessment of your IT network.

News

Threat Spotlight: Group 72, Opening the ZxShell

ZxShell (aka Sensocode) is a Remote Administration Tool (RAT) used by Group 72 to conduct cyber-espionage operations. The analysts involved were able to identify command and control (C2) servers, dropper and installation methods, means of persistence, and attack tools that are core to the RATs purpose. The researchers used their analysis to provide detection coverage for Snort, Fireamp, and ClamAV. The paper is a technical analysis on the functionality of Zx Shell.”]

Source: https://blog.talosintelligence.com/2014/10/threat-spotlight-group-72-opening.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

SEA has stolen invoices that shows Microsoft charges FBI for user data

News

Greek police arrested a man running the BTC-e Bitcoin exchange to launder more than US$4bn worth of the Bitcoin