TA584 Actors Leveraging ClickFix Social Engineering to Deliver Tsundere Bot Malware
ID: 28984cee-de81-57ed-b23d-fc4aa80b488d
STIX ID: report--28984cee-de81-57ed-b23d-fc4aa80b488d
Feed Name: cybersecurityNews.com
Threat Score
TA584 has been observed distributing a new Node.js-based malware called Tsundere Bot via sophisticated phishing lures and the ClickFix social-engineering flow; the malware uses EtherHiding (retrieving configuration from Ethereum smart contracts), enforces geofencing/anti-analysis checks, can lead to ransomware deployment, and communicates with a reported C2 at 193.17.183.126:3001.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
