Government Hit by Multi-Malware Cyberattack via Cloudflare Service
ID: ba0b2a78-e33c-55a4-8225-1a07448f22e2
STIX ID: report--ba0b2a78-e33c-55a4-8225-1a07448f22e2
Feed Name: securityonline.info
Threat Score
eSentire TRU uncovered a phishing-based campaign against government targets that used a TryCloudflare-proxied WebDAV server to distribute encrypted and highly obfuscated payloads (obfuscated .bat and Python files) which deployed XWorm, AsyncRAT, VenomRAT and PureLogs Stealer; the attack chain employed in-memory shellcode (Donut loader), direct syscalls and Early Bird APC injection to evade EDR and achieve persistence and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
