Suivre

The FBI has learned of a criminal group who self identifies as the « OnePercent Group » and who have used Cobalt Strike to perpetuate attacks against companies since November 2020.

OnePercent Group actors compromise victims through a phishing email in which an attachment is opened on Microsoft operating systems by the user. The attachment's macros infect the system with the IcedID . IcedID downloads additional software to include Cobalt Strike. Cobalt Strike moves laterally in the network, primarily with PowerShell remoting.

📎 (PDF) ic3.gov/Media/News/2021/210823

Inscrivez-vous pour prendre part à la conversation
nanao

Comme le soleil, les machines ne se couchent jamais.