Operation DupeHike Attacking Employees Using Weaponized Documents DUPERUNNER Malware
ID: 50bdce89-5571-5221-a6b6-6a18d987211c
STIX ID: report--50bdce89-5571-5221-a6b6-6a18d987211c
Feed Name: cybersecurityNews.com
Threat Score
Operation DupeHike is a targeted phishing campaign attributed to UNG0902 that uses ZIP-embedded .LNK shortcuts to execute PowerShell and download a C++ implant (DUPERUNNER) which performs reconnaissance and injection to deploy an AdaptixC2 HTTP beacon; the campaign targets HR/payroll personnel in Russian corporate environments and uses infrastructure identified at IP 46.149.71.230 and ASNs 48282/9123.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
