Blog | G5 Cyber Security

Tortoiseshell Group Targets IT Providers in Saudi Arabia in Probable Supply Chain Attacks

An unusually large number of computers have been compromised in a targeted attack. The malware is a basic backdoor that can download and execute additional tools and commands. It collects and sends the machines IP address, operating system name and version, and Mac address to the C&C server using the URL in the Sendvmd registry key mentioned above. It then compresses this information before transferring it to a remote directory. The other tools used by the group are public tools, and include Infostealer/Sha432.exe and PowerShell backdoors.”]

Source: https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/tortoiseshell-apt-supply-chain

Exit mobile version