Keitaro TDS abused to deliver AutoIT-based loader targeting German speakers · Blog · Sublime Security
ID: 884d590b-1334-5b5f-951b-11639dec97d2
STIX ID: report--884d590b-1334-5b5f-951b-11639dec97d2
Feed Name: Sublime Security Blog
This report documents a targeted malvertising campaign that uses Keitaro TDS redirects to deliver a deliberately oversized ISO which, once mounted, extracts a password-protected executable that builds and runs an AutoIt-based loader. The payload performs AV/service checks, drops numerous artifacts to %LocalAppData%, creates a scheduled task (DragonMapper) for persistence, and exhibits behaviors consistent with information-stealer families; the report includes file hashes, malicious domains, and network indicators.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
