IcedID Trojan Rebooted with New Evasive Tactics
#1
Information 
Quote:Juniper identifies phishing campaign targeting business customers with malware using password protection, among other techniques, to avoid detection.
 
Threat actors have enhanced a banking trojan that has been widely used during the COVID-19 pandemic with new functionality to help it avoid detection by potential victims and standard security protections.
 
Attackers have implemented several new features — including a password-protected attachment, keyword obfuscation and minimalist macro code—in a recent phishing campaign using documents trojanized by the widely used banking trojan IcedID, according to a new report by Juniper Networks security researcher Paul Kimayong.
 
The campaign, which researchers discovered in July, also uses a dynamic link library (DLL) — a Microsoft library that contains code and data that can be used by more than one program at the same time — as its second-stage downloader. This “shows” a new maturity level of this threat actor,” he observed.
 
The latest version of IcedID identified by the Juniper team is being distributed using compromised business accounts where the recipients are customers of the same businesses. This boosts the likelihood of the campaign’s success, as the sender and the recipient already have an established business relationship, Kimayong noted.

Read more: https://threatpost.com/icedid-trojan-reb...cs/158425/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Version 9.6.4 for Windows
Version 9.6.4 for ...harlan4096 — 06:46
AMD confirms focus shifts to RDNA3 and R...
Goodbye Radeon RX ...harlan4096 — 06:45
F-Droid says Google's statement about "S...
A month ago, F-Dro...harlan4096 — 06:44
Google Chrome to enable HTTPS by default...
Google has announc...harlan4096 — 06:41
Revo Registry Cleaner
Revo Registry Cleane...jasonX — 01:51

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>