Citrine Sleet's intrusion against Radiant Capital commenced in September with the spoofing of a former contractor on Telegram to lure a Radiant developer into downloading a ZIP file featuring a decoy PDF file and the InletDrift macOS malware, which facilitated backdoor injection, according to the investigation.
UAC-0185 targeted the organizations with phishing emails purporting to be invitations for a Kyiv-based defense conference last week that sought to facilitate compromise with the MeshAgent and UltraVNC tools, said CERT-UA, which previously noted MeshAgent to have been leveraged to compromise more than 100 Ukrainian state computers.
Well-known online forums have been leveraged to spread the cracked software, which was claimed by threat actors to function only if targets would deactivate their antivirus systems, according to a Kaspersky analysis.
After leveraging artificial intelligence to create a website establishing the app's legitimacy, threat actors proceeded to lure targets on Telegram into downloading the app to join a meeting regarding an investment opportunity, a report from Cado Security revealed.
Venom Spider leveraged the VenomLNK tool to facilitate initial access in both campaigns, the first of which involved the tool being used to show a decoy PNG image while executing RevC2, which enabled Chromium browser cookie and credential exfiltration, shell command execution, screenshot capturing, and traffic proxying, according to an analysis from Zscaler ThreatLabz.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.