Intrusions by Kimsuky involved the delivery of spear-phishing emails luring ZIP file downloads and malicious file extraction to facilitate the deployment of the payloads, which are suspected to be of the same author due to source code similarities.
Attackers utilized HTML smuggling to stealthily deliver invoice-themed phishing lures with an encrypted HTML attachment, which when decrypted triggers a VBScript dropper that deploys a JavaScript file before delivering AsyncRAT.
Malicious apps masquerading as Google Chrome, Enterprise Europe, and NordVPN created with the Zombinder APK service have been used to deploy Octo2, which also featured a Domain Generation Algorithm-based command-and-control system that increased its resistance to attempted takedowns, a report from ThreatFabric revealed.
Attacks conducted until July involved the delivery of phishing messages with malicious shortcut attachments or Google Drive URLs to mainly distribute the Lumma Stealer, NetSupport, and StealC payloads, according to a Proofpoint analysis.
All four of the poisoned packages, which have already been removed from the PyPI repository, enabled encoded next-stage payload execution before deploying PondRAT for Linux and macOS, which have file upload and download, as well as arbitrary command execution capabilities.
Attackers leveraged leaked Kryptina source code to develop rebranded Mallox payloads, including the Mallox Linux 1.0 encryptor that was identical to Kryptina save for its name and appearance.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.