![]() |
|
TA505 Spear Phishing Campaign Uses LOLBins to Avoid Detection - Printable Version +- Geeks for your information (https://www.geeks.fyi) +-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105) +--- Forum: Privacy & Security News (https://www.geeks.fyi/forumdisplay.php?fid=107) +--- Thread: TA505 Spear Phishing Campaign Uses LOLBins to Avoid Detection (/showthread.php?tid=6771) |
TA505 Spear Phishing Campaign Uses LOLBins to Avoid Detection - silversurfer - 25 April 19 Quote:The TA505 hacking group ran a spear phishing campaign targeting a financial institution during April with the help of a signed version of the ServHelper backdoor and a number of LOLBins designed to help the operation evade detection. Quote:LOLBins are deceptive because their execution seems benign at first, or even sometimes safe. In addition, the use of a signed and verified file with certification increases the likelihood that the malware will stay under the radar. SOURCE: https://www.bleepingcomputer.com/news/security/ta505-spear-phishing-campaign-uses-lolbins-to-avoid-detection/ |