With the ability to deploy a remote shell allowing remote access to infected devices and memory modification, sedexp has been used by threat actors to facilitate the obfuscation of modified Apache configuration files, web shells, and the udev rule.
Attacks commenced with the download of malicious ZIP files purporting to be pirated movies that contain an LNK file, which links with a memory-only JavaScript dropper-hosting content delivery network to execute PEAKLIGHT, according to an analysis from Mandiant.
According to ESET researchers who discovered the campaign, the malware, which they named NGate, mimicked legitimate banking apps, convincing victims to download a malicious app via phishing messages that claimed their devices were compromised.
Intrusions commence with brute-force attempts to guess the PostgreSQL database's credentials, which when achieved would be followed by the establishment of a superuser role that would ensure database access even after modifications to the original credentials.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.