So Your CFO's Phone Has Been Pwned: A DFIR Journey
ID: 0389fb2f-d60e-5a5d-bdc4-391b7c3848c4
STIX ID: report--0389fb2f-d60e-5a5d-bdc4-391b7c3848c4
Feed Name: Censys Blog
Threat Score
This article uses two hypothetical SOC incidents—an Android banking trojan (ERMAC/HookBot) and an iPhone compromise involving a DarkSword iOS exploit chain and credential-phishing—to demonstrate mobile incident response: preserve devices, gather APKs/network telemetry, pivot on IOCs to historical infrastructure using Censys, and expand scope across the enterprise while converting findings into durable detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
