Malware Distributed as Copyright Violation-Related Materials (Beast Ransomware, Vidar Infostealer)
ID: 84b2f18a-9fd9-5c9b-97aa-a4e76a04509c
STIX ID: report--84b2f18a-9fd9-5c9b-97aa-a4e76a04509c
Feed Name: ASEC
Threat Score
AhnLab ASEC identifies a phishing campaign distributing two payloads—Beast ransomware and Vidar infostealer—via external download links in copyright/resume-themed emails; attackers nest an ALZ archive inside a downloaded ZIP to bypass compression-detection, deliver two executables (one encryptor, one infostealer), and employ SMB scanning for lateral movement and resilient C2 mechanisms (using Telegram/Steam) to exfiltrate data and maintain command-and-control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
