Ephemeral, In-Memory Attack Used With New IE 0Day
ID: 68c4c479-efd1-50eb-8218-b295960be44c
STIX ID: report--68c4c479-efd1-50eb-8218-b295960be44c
Feed Name: Security Ledger
Threat Score
FireEye reported attackers using a newly discovered Internet Explorer zero-day on a high-value watering-hole site to deploy an ephemeral, diskless in-memory variant of the Hydraq (McRAT) Trojan; the campaign exploited an information-leak and an out-of-bounds memory vulnerability affecting Windows XP and Windows 7 (IE 7–9), and the payload's non-persistent, memory-only execution made detection and forensic recovery difficult.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
