Attackers Stitch Together Frankenstein Campaign Using Free Tools
#1
Quote:Threat actors behind a highly-targeted series of cyber attacks spanning from January to April 2019 have been seen employing malicious tools built using freely available components to infect victims with malware designed to harvest credentials.
 
The campaign was named 'Frankenstein' by Cisco Talos, a name which "refers to the actors' ability to piece together several unrelated components — leveraged four different open-source techniques to build the tools used during the campaign."
 
The Frankenstein campaign operators used the following open source components to build their malicious tools:
• An article to detect when your sample is being run in a VM
• A GitHub project that leverages MSbuild to execute a PowerShell command
• A component of GitHub project called "Fruityc2" to build a stager
• A GitHub project called "PowerShell Empire" for their agents

As the researchers further discovered, the threat actors made it their mission to avoid detection, checking for running programs such as Process Explorer and if the infected machine was actually a virtual machine environment.

"The threat actors also took additional steps to only respond to GET requests that contained predefined fields, such as a non-existent user-agent string, a session cookie, and a particular directory on the domain. The threat actors also used different types of encryption in order to protect data in transit," says the Cisco Talos report.

SOURCE: https://www.bleepingcomputer.com/news/se...ree-tools/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
WhatsApp Adds Security Warning Before Us...
WhatsApp has intro...harlan4096 — 08:21
uBOLite 2026.625.1633
uBOLite 2026.625.1...harlan4096 — 07:35
7-Zip 26.02
7-Zip 26.02 Wha...harlan4096 — 07:23
AMD to bring back Ryzen 7 5800X3D as AM...
AMD has officially r...harlan4096 — 07:12
Windows Secure Boot Certificate Expiry E...
Microsoft’s long-p...harlan4096 — 07:04

[-]
Birthdays
Today's Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
Decimuss's profile Decimuss

>