In live incidents, SoupDealer bypassed hostābased antivirus checks by confirming no security products were active before proceeding.
Thatās a pretty narrow victim demographic. Windows has Defender enabled out of the box. I donāt see any investigation on the C2 connection, either, so Iām left wondering who the attacked and intended targets are.
threaded - newest
Yikes š¬
<img alt="" src="https://lemmy.world/pictrs/image/3386f6c0-28a5-49e9-a1e0-cb915c601ccb.gif">
Thatās a pretty narrow victim demographic. Windows has Defender enabled out of the box. I donāt see any investigation on the C2 connection, either, so Iām left wondering who the attacked and intended targets are.
And it downloads Tor to connect to C2. So itās a machine with Internet access AND without security mesures.
So it might be a target with poor IT. A windows machine shouldnāt be left without AV, especially if it has Internet access.
Why would somebody only target machines in Turkey?
Greece has entered the chat
oh wait. yeah, look Iām not a smart man
Iām a smart man and I think your question still stands. Why shouldnāt they get along like normal people. (Intentionally no question mark.)