Get a Pentest and security assessment of your IT network.

News

Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks

An unusually large number of computers have been compromised in a targeted attack. The malware is a basic backdoor that can download and execute additional tools and commands. It collects and sends the machines IP address, operating system name and version, and Mac address to the C&C server using the URL in the Sendvmd registry key mentioned above. It then compresses this information before transferring it to a remote directory. The other tools used by the group are public tools, and include Infostealer/Sha432.exe and PowerShell backdoors.”]

Source: https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/tortoiseshell-apt-supply-chain

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months