Suivre

A new targets 🇫🇷 french entities with unique attack chain.

Proofpoint observed new, targeted activity impacting French entities in the construction and government sectors. The threat actor used macro-enabled Word documents to distribute the Chocolatey installer package, an open-source package installer. The attack targeted French entities in the construction, real estate, and government industries. The attacker used a resume themed subject and lure purporting to be information. The attacker used steganography, including a cartoon image, to download and install the Serpent backdoor. The attacker also demonstrated a novel detection bypass technique using a Scheduled Task.

proofpoint.com/us/blog/threat-

· · 0 · 0 · 0
Inscrivez-vous pour prendre part Ă  la conversation
nanao

Comme le soleil, les machines ne se couchent jamais.