Freight Hacker Wields Code-Signing Service to Evade Defenses
ID: 552d63b3-0618-58c0-a9ee-8064bec7a5c1
STIX ID: report--552d63b3-0618-58c0-a9ee-8064bec7a5c1
Feed Name: Proofpoint Blog
Proofpoint researchers uncovered a financially motivated cybercriminal group targeting freight and logistics companies via phishing that delivers VBS and PowerShell payloads to install RMM tools (SimpleHelp, Pulseway, ConnectWise ScreenConnect) for remote control, credential theft and cargo diversion. The actors notably used a third-party code-signing service to fraudulently sign ScreenConnect installers (domains observed: amtechcomputers.net, signer.bulbcentral.com) to evade defenses, and deployed multiple scripts to enumerate accounts, collect browsing/banking data, and exfiltrate to attacker-controlled Telegram bots.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
