Digitally Signed Bandook Trojan Reemerges in Global Spy Campaign
#1
Information 
Quote:A wave of targeted cyberattack campaigns bent on espionage is cresting around the globe, using a strain of a 13-year old backdoor trojan named Bandook.
 
According to Check Point Research, Bandook was last spotted being used in 2015 and 2017/2018, in the “Operation Manul” and “Dark Caracal” campaigns, respectively. The malware then all but disappeared from the threat landscape – but it’s now having a resurgence.
 
According to the firm, dozens of digitally signed variants of this commodity malware are popping up in an unusually large variety of sectors and locations. Targeted entities include those in the government, financial, energy, food industry, healthcare, education, IT and legal sectors. And, they have been located in Chile, Cyprus, Germany, Indonesia, Italy, Singapore, Switzerland, Turkey and the U.S.

“This further reinforces a previous hypothesis that the malware is not developed in-house and used by a single entity, but is part of an offensive infrastructure sold by a third party to governments and threat actors worldwide, to facilitate offensive cyber-operations,” according to researchers at Check Point, in a recent posting.

In these latest attacks, the malware arrives on targets’ computers in the form of a malicious Microsoft Word document delivered inside a .zip file. Check Point found that the themes of the documents revolve around cloud-based services like Office365, OneDrive and Azure – recipients are promised access to other documents if they click “Enable Content.”

Read more: https://threatpost.com/digitally-signed-...gn/161676/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
New User Alert: Use This Ibotta Code [ZV...
Our special ZVFTJQW ...lucasbitz1995 — 12:54
Ibotta Referral Code [ZVFTJQW]: Get an $...
Using the exclusive ...Nion888 — 12:53
Ibotta Friend Referral Code [ZVFTJQW]: G...
The ZVFTJQW Ibotta c...lucasbitz1995 — 12:53
Insta360 Coupon Code – [INRSGY42P4A] Fre...
Finding a valid Inst...Banana12121230 — 12:52
New Ibotta Members [ZVFTJQW]: Unlock a $...
By using the Ibotta ...Nion888 — 12:52

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>