Fake Screenshot Lures Target Web3 Support Staff with Multi-Stage Malware Attack
ID: 44f403f5-9dd7-540e-9289-380a9fa520f1
STIX ID: report--44f403f5-9dd7-540e-9289-380a9fa520f1
Feed Name: GBHackers
This report documents an active, sophisticated campaign (linked to APT‑Q‑27/GoldenEyeDog) that targets Web3 support teams by sending look‑alike screenshot links which execute signed .NET loaders; those loaders retrieve manifests from AWS S3 dead drops and stage a DLL sideloading chain that unpacks a memory‑resident Farfli backdoor communicating with 37 hard‑coded C2 IPs over TCP/15628. The writeup includes detailed TTPs (obfuscation, anti‑debug checks, Run registry persistence, service 'Windows Eventn', UAC tampering), IOCs (filenames and SHA256 hashes), and actionable defenses (block C2 traffic, enforce visible file extensions, sandbox support workflows, EDR coverage).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
