CTAs Leveraging Fake Browser Updates in Malware Campaigns
ID: ba923e3c-3ebb-5fe9-8f1c-4670c4e6c637
STIX ID: report--ba923e3c-3ebb-5fe9-8f1c-4670c4e6c637
Feed Name: CISecurity.org Insights Blog
MS-ISAC reports a significant rise in opportunistic campaigns in 2H 2023 that use fake browser update pages to deliver JavaScript downloaders (SocGholish, RogueRaticate, ClearFake), which then drop secondary payloads including NetSupport, AsyncRAT, and Lumma Stealer; the report presents rising detection trends, detailed IOCs (hashes, IPs, domains, URLs), mapped MITRE ATT&CK techniques, and concrete defensive measures (training, EDR, NIDS, allowlisting, PowerShell controls, DNS filtering) to help SLTT organizations mitigate these threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
