Cargo thieving hackers running sophisticated remote access campaigns, researchers find
ID: 3dfdd531-3f70-56a8-99ca-64f225dec0a5
STIX ID: report--3dfdd531-3f70-56a8-99ca-64f225dec0a5
Feed Name: The Record from Recorded Future News
Proofpoint researchers observed cybercriminals compromising load boards to deploy multiple remote access tools (including several ScreenConnect instances) against trucking carriers, using a novel "signing-as-a-service" to sign installers and re-sign components to evade detection and maintain persistence; attackers also scanned infected systems for cryptocurrency wallets, PayPal and banking credentials, fuel card and freight management platforms to enable cargo theft and broader financial fraud against mostly small carriers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
