Bit9: 32 Pieces of Malware Whitelisted In Targeted Hack
ID: 56c1dd46-9c63-5297-9208-98e269f71551
STIX ID: report--56c1dd46-9c63-5297-9208-98e269f71551
Feed Name: Security Ledger
Bit9’s corporate network was compromised via a SQL injection that allowed attackers to access accounts and an inactive code-signing server; the attackers signed 32 malicious files (HiKit, HomeUNIX, Hydraq variants) and used them in watering-hole style attacks against three customer networks, effectively bypassing Bit9’s whitelisting defenses. Analysis points to sophisticated, information-gathering malware and possible attribution to actors in China/APAC, with evidence including C2 beacons and references to sinkholed IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
