SyncFuture Campaign Abuses Enterprise Security Tools to Deploy Malware
ID: 4175a3d9-47d4-5034-9ebb-cf39d34e0994
STIX ID: report--4175a3d9-47d4-5034-9ebb-cf39d34e0994
Feed Name: GBHackers
Threat Score
A detailed analysis of the ‘SyncFuture Espionage Campaign’ describes a sophisticated, multi-stage intrusion targeting Indian residents that starts with tax-themed phishing and DLL side-loading, employs anti-analysis and UAC-elevation techniques, and culminates in deploying legitimate SyncFuture TSM enterprise software (and signed kernel drivers) repurposed as a persistent espionage backdoor capable of data theft, screen recording, and remote control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
