Kaspersky discovers C++ version of BellaCiao malware (securelist.com)
from Joker@sh.itjust.works to cybersecurity@infosec.pub on 20 Dec 21:22
https://sh.itjust.works/post/29790171

Introduction

> BellaCiao is a .NET-based malware family that adds a unique twist to an intrusion, combining the stealthy persistence of a webshell with the power to establish covert tunnels. It surfaced for the first time in late April 2023 and has since been publicly attributed to the APT actor Charming Kitten. One important aspect of the BellaCiao samples is how they exhibit a wealth of information through their respective PDB paths, including a versioning scheme we were able to work out once we analyzed historical records. > > Recently, we were investigating an intrusion that involved a BellaCiao sample (MD5 14f6c034af7322156e62a6c961106a8c) on a computer in Asia. Our telemetry indicated another suspicious, and possibly related, sample on the same machine. After further investigation of the sample, it turned out to be a reimplementation of an older BellaCiao version, but written in C++.

#cybersecurity

threaded - newest

Railcar8095@lemm.ee on 20 Dec 22:06 collapse

Rust fork when?