An unusually large number of computers have been compromised in a targeted attack. The malware is a basic backdoor that can download and execute additional tools and commands. It collects and sends the machines IP address, operating system name and version, and Mac address to the C&C server using the URL in the Sendvmd registry key mentioned above. It then compresses this information before transferring it to a remote directory. The other tools used by the group are public tools, and include Infostealer/Sha432.exe and PowerShell backdoors.”]

