BlindEagle Hackers Attacking Government Agencies with Powershell Scripts
ID: 5f2fac99-ece1-5fdc-b448-4af2fad44e19
STIX ID: report--5f2fac99-ece1-5fdc-b448-4af2fad44e19
Feed Name: cybersecurityNews.com
Threat Score
BlindEagle staged a sophisticated phishing campaign against a Colombian government agency using a malicious SVG to redirect victims to a fake judicial portal; interacting with the portal triggered a multi-stage, fileless chain (JavaScript and PowerShell) that used steganography and in-memory execution to deploy the Caminho downloader and DCRAT RAT (which patches AMSI), achieving persistence via scheduled tasks and registry changes and evading traditional detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
