MLTBackdoor Malware Family Fuels Ransomware Attacks
ID: 22ee83ba-1782-5a81-a1d1-da31f1f5cfb9
STIX ID: report--22ee83ba-1782-5a81-a1d1-da31f1f5cfb9
Feed Name: securityonline.info
Threat Score
Zscaler ThreatLabz identified MLTBackdoor, a sophisticated backdoor associated with ransomware operators that uses ClickFix social engineering to deliver malicious PowerShell, employs heavy MBA and control-flow flattening obfuscation, supports Beacon Object Files for fileless capability, and maintains resilient, ECDH/AES-256-GCM encrypted C2 communications with a DGA fallback; organizations should monitor anomalous PowerShell activity and strengthen endpoint detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
