APT Attacks Using Cloud Storage
ID: e8f5f983-c65f-5a01-b3cd-ce9b643f1a61
STIX ID: report--e8f5f983-c65f-5a01-b3cd-ce9b643f1a61
Feed Name: ASEC
AhnLab ASEC details a targeted malware campaign in which threat actors host decoy documents and malicious scripts on cloud storage (Dropbox, Google Drive). Victims are lured by .LNK shortcut files that run Base64-encoded PowerShell, which downloads additional scripts, registers scheduled tasks for persistence, and ultimately loads a customized XenoRAT payload in-memory; the RAT provides C2 access (159.100.29.122:8811), data collection/exfiltration, and remote control. The report provides multiple IoCs (MD5s, C2 URL, attacker email addresses) and recommends caution with file extensions and cloud-hosted content.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
