Thread Rating:
  • 1 Vote(s) - 5 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Attackers Stitch Together Frankenstein Campaign Using Free Tools
#1
Quote:Threat actors behind a highly-targeted series of cyber attacks spanning from January to April 2019 have been seen employing malicious tools built using freely available components to infect victims with malware designed to harvest credentials.
 
The campaign was named 'Frankenstein' by Cisco Talos, a name which "refers to the actors' ability to piece together several unrelated components — leveraged four different open-source techniques to build the tools used during the campaign."
 
The Frankenstein campaign operators used the following open source components to build their malicious tools:
• An article to detect when your sample is being run in a VM
• A GitHub project that leverages MSbuild to execute a PowerShell command
• A component of GitHub project called "Fruityc2" to build a stager
• A GitHub project called "PowerShell Empire" for their agents

As the researchers further discovered, the threat actors made it their mission to avoid detection, checking for running programs such as Process Explorer and if the infected machine was actually a virtual machine environment.

"The threat actors also took additional steps to only respond to GET requests that contained predefined fields, such as a non-existent user-agent string, a session cookie, and a particular directory on the domain. The threat actors also used different types of encryption in order to protect data in transit," says the Cisco Talos report.

SOURCE: https://www.bleepingcomputer.com/news/se...ree-tools/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
F-Secure 19.4
What's new in the ...harlan4096 — 09:44
Thunderbird Supernova 115.10.1
Thunderbird Supern...harlan4096 — 09:41
Microsoft Edge 124.0.2478.51
Version 124.0.2478...harlan4096 — 09:40
Rogue Anti-Malware 15.16.1
V15.16.1 04/12/202...harlan4096 — 09:39
Intel Xeon 6 6980P “Granite Rapids-AP” C...
Intel Xeon 6 specs...harlan4096 — 09:37

[-]
Birthdays
Today's Birthdays
avatar (36)RobertUtelt
Upcoming Birthdays
avatar (43)wapedDow
avatar (42)techlignub
avatar (41)Stevenmam
avatar (48)onlinbah
avatar (49)steakelask
avatar (43)Termoplenka
avatar (41)bycoPaist
avatar (47)pieloKat
avatar (41)ilyagNeexy
avatar (49)donitascene
avatar (49)Toligo

[-]
Online Staff
There are no staff members currently online.

>