Cyber-Actors are “Laundering Trust” to Hijack the Global Supply Chain
ID: fd511b02-4aa6-5d9d-878e-02cc72f9946a
STIX ID: report--fd511b02-4aa6-5d9d-878e-02cc72f9946a
Feed Name: securityonline.info
Proofpoint uncovered a month-long, operator-driven intrusion campaign targeting transportation firms that began with load-board phishing delivering a VBS decoy and PowerShell-based remote access installation. The actor deployed multiple RMM/backdoor tools (ScreenConnect, Pulseway, SimpleHelp) for redundancy, executed extensive PowerShell reconnaissance to identify financially valuable targets (banks, fuel card services, fleet payment platforms, browser extensions and crypto wallets), and abused a third-party signing-as-a-service (signer.bulbcentral.com) to re-sign malicious binaries, enabling trust bypass and prolonged persistence for financial theft and cargo diversion operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
