Attackers Stitch Together Frankenstein Campaign Using Free Tools
#1
Quote:Threat actors behind a highly-targeted series of cyber attacks spanning from January to April 2019 have been seen employing malicious tools built using freely available components to infect victims with malware designed to harvest credentials.
 
The campaign was named 'Frankenstein' by Cisco Talos, a name which "refers to the actors' ability to piece together several unrelated components — leveraged four different open-source techniques to build the tools used during the campaign."
 
The Frankenstein campaign operators used the following open source components to build their malicious tools:
• An article to detect when your sample is being run in a VM
• A GitHub project that leverages MSbuild to execute a PowerShell command
• A component of GitHub project called "Fruityc2" to build a stager
• A GitHub project called "PowerShell Empire" for their agents

As the researchers further discovered, the threat actors made it their mission to avoid detection, checking for running programs such as Process Explorer and if the infected machine was actually a virtual machine environment.

"The threat actors also took additional steps to only respond to GET requests that contained predefined fields, such as a non-existent user-agent string, a session cookie, and a particular directory on the domain. The threat actors also used different types of encryption in order to protect data in transit," says the Cisco Talos report.

SOURCE: https://www.bleepingcomputer.com/news/se...ree-tools/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mullvad retires OpenVPN support on deskt...
OpenVPN gets the a...harlan4096 — 09:32
AdGuard VPN for Mac 2.8.2
AdGuard VPN for Ma...harlan4096 — 09:30
AMD FSR Redstone launched: ML-based Ups...
FSR Redstone’s ML Fr...harlan4096 — 09:29
(PC Game - Epic) Hogwarts Legacy (Dec 12...
  Hogwarts Legacy ...Mehdi — 18:56
AdGuard for Android 4.12.2
AdGuard for Androi...harlan4096 — 09:01

[-]
Birthdays
Today's Birthdays
avatar (43)ivyhuv
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>