logo

APT Attacks Using Cloud Storage

ID: e8f5f983-c65f-5a01-b3cd-ce9b643f1a61

STIX ID: report--e8f5f983-c65f-5a01-b3cd-ce9b643f1a61

Feed Name: ASEC

Threat Score
75/100

Date Published: 2024-06-11

Date Updated: 2026-04-26

Author: yeeun

...
...

AhnLab ASEC details a targeted malware campaign in which threat actors host decoy documents and malicious scripts on cloud storage (Dropbox, Google Drive). Victims are lured by .LNK shortcut files that run Base64-encoded PowerShell, which downloads additional scripts, registers scheduled tasks for persistence, and ultimately loads a customized XenoRAT payload in-memory; the RAT provides C2 access (159.100.29.122:8811), data collection/exfiltration, and remote control. The report provides multiple IoCs (MD5s, C2 URL, attacker email addresses) and recommends caution with file extensions and cloud-hosted content.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.