Hidden in Plain Sight: TA397’s New Attack Chain Delivers Espionage RATs
(www.proofpoint.com)
from Joker@sh.itjust.works to cybersecurity@infosec.pub on 17 Dec 13:03
https://sh.itjust.works/post/29612635
from Joker@sh.itjust.works to cybersecurity@infosec.pub on 17 Dec 13:03
https://sh.itjust.works/post/29612635
> - Proofpoint observed advanced persistent threat (APT) TA397 targeting a Turkish defense sector organization with a lure about public infrastructure projects in Madagascar.Key findings
> - The attack chain used alternate data streams in a RAR archive to deliver a shortcut (LNK) file that created a scheduled task on the target machine to pull down further payloads.
> - TA397 was observed manually delivering WmRAT and MiyaRAT malware families in the final stages of this attack chain. Both malware families are designed to enable intelligence gathering and exfiltration.
> - Proofpoint assesses TA397 campaigns are almost certainly intelligence collection efforts in support of a South Asian government’s interests.
threaded - newest