How Threat Actors Use OneNote to Deploy ASyncRAT
ID: 2778ff82-fd85-5655-a578-05c067182f62
STIX ID: report--2778ff82-fd85-5655-a578-05c067182f62
Feed Name: TrustedSec blog
Threat Score
TrustedSec demonstrates how threat actors are embedding ASyncRAT delivery inside Microsoft OneNote documents to enable phishing-based deployments of an open-source remote administration tool, and provides a Sysmon configuration to detect and block the behavior.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
