Acronis TRU Alliance {VirusTotal}: Tracking FileFix, Shadow Vector, and SideWinder
ID: 9142d31a-1246-5c0d-b3b6-f5bdf61d2b34
STIX ID: report--9142d31a-1246-5c0d-b3b6-f5bdf61d2b34
Feed Name: TRU Security by Acronis
Acronis Threat Research Unit (TRU), in collaboration with VirusTotal, presents practical threat-hunting case studies for three active campaigns: FileFix (a ClickFix web-based clipboard-driven PowerShell delivery), SideWinder (document-based attacks leveraging CVE-2017-0199 and CVE-2017-11882 targeting South Asia), and Shadow Vector (judicial-themed SVG lures targeting Colombia). The report explains how VirusTotal features (Livehunt, Retrohunt, VT Diff, content search, metadata filters) were used to create and refine YARA rules, recover IOCs and payload artifacts, and map infrastructure and delivery chains, and it supplies example YARA rules, hashes, and hunting guidance to reproduce and extend the detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
