Secureserver.net Domain Abused in Widespread Banking Trojan Attacks
ID: 65761eed-9c4c-5b23-b959-88688359bac2
STIX ID: report--65761eed-9c4c-5b23-b959-88688359bac2
Feed Name: securityonline.info
Threat Score
A multi-stage banking trojan campaign is using secureserver.net-hosted IP-based URLs to deliver obfuscated HTA/JS/VBS payloads that download an AutoIt binary which performs sophisticated checks (AV/VM/region/language), injects into the legitimate mobsync.exe process, connects to C2 servers, and exfiltrates system details and credentials targeting Spanish- and Portuguese-speaking regions including Latin America and Europe; indicators and mitigation advice are provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
