Evasive MyloBot botnet can take over enterprise devices to steal data, spread ransomware
ID: 83e4fd9f-8816-5fb4-812e-f18c2c13eddd
STIX ID: report--83e4fd9f-8816-5fb4-812e-f18c2c13eddd
Feed Name: Security Ledger
MyloBot is a recently discovered, highly sophisticated botnet observed on a client device that achieves persistent, full system control by using anti-VM/sandbox/anti-debug techniques, memory-resident execution (reflective EXE), code injection and process hollowing; it disables Windows Defender, kills other malware, delays C2 activity for 14 days, and can download and execute secondary payloads (ransomware, banking trojans, data exfiltration), with indication that its command-and-control infrastructure is linked to dark web malware marketplaces, posing a significant enterprise risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
