Many Watering Holes, Targets In Hacks That Netted Facebook, Twitter and Apple
ID: 4be44aee-1c49-57f8-951f-1e955b86c0e3
STIX ID: report--4be44aee-1c49-57f8-951f-1e955b86c0e3
Feed Name: Security Ledger
The Security Ledger describes a broad watering‑hole campaign that compromised multiple developer and other websites to serve a Java zero‑day, infecting visitors from major firms (including Facebook, Twitter, Apple, Microsoft) with platform‑specific trojans—most notably the macOS family 'Pintsized'. Attackers used multiple compromised sites to selectively target visitors from certain organizations, established encrypted C2 channels (one observed domain: corp-aapl.com), and investigators/sinkhole operators later disrupted C2 activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
