BlindEagle Hackers Attacking Organization to Abuse Trust and Bypass Email Security Controls
ID: 55de8330-1c4d-5d59-a40e-fbf9dad57ba1
STIX ID: report--55de8330-1c4d-5d59-a40e-fbf9dad57ba1
Feed Name: cybersecurityNews.com
BlindEagle targeted a Colombian government institution by compromising an internal email account to send phishing messages with an SVG attachment that redirects victims to a fake portal. The portal delivers obfuscated JavaScript that triggers a fileless infection: scripts deobfuscate payloads, a PowerShell command retrieves a PNG from the Internet Archive containing the Caminho downloader, which pulls a text payload from a Discord CDN and decodes it in memory before injecting the DCRAT RAT into a hollowed MSBuild.exe process, enabling keylogging and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
