Novel attack on Windows spotted in phishing campaign run from and targeting China
ID: 7b511d39-1949-52ee-8dd7-2d3ebd551419
STIX ID: report--7b511d39-1949-52ee-8dd7-2d3ebd551419
Feed Name: The Register (Security)
Securonix researchers uncovered a covert phishing campaign called SLOW#TEMPEST targeting Chinese-speaking entities; attackers used zip attachments containing a malicious LNK that executed a renamed LicensingUI.exe to sideload a malicious dui70.dll (Cobalt Strike implant). The intruders deployed multiple post-exploitation tools for scanning, port forwarding, AD enumeration, credential theft, shellcode loading and exfiltration, maintained persistence and lateral movement for over two weeks, and used IPs hosted on Tencent cloud; no firm attribution was established.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
