Threat actors use copyright infringement phishing lure to deploy infostealers
ID: 5e482b97-13a3-567c-8b0d-d414424e02bc
STIX ID: report--5e482b97-13a3-567c-8b0d-d414424e02bc
Feed Name: Cisco Talos
Cisco Talos observed an ongoing phishing campaign targeting Facebook business/advertising users in Taiwan that uses copyright-infringement decoys and fake PDF filenames to trick victims into downloading password-protected RAR archives; those archives drop fake PDF executables which deploy LummaC2 and Rhadamanthys information stealers via Appspot/short-URL/Dropbox delivery, using heavy obfuscation, shellcode encryption, resource stuffing (>700 MB), persistence via registry/run keys and process injection, and multiple C2 domains—Talos provides analysis and associated IOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
