Attack Trends Related to DangerousPassword
ID: bfc8f9c3-eae0-5e73-9329-2a6c1f31b666
STIX ID: report--bfc8f9c3-eae0-5e73-9329-2a6c1f31b666
Feed Name: JPCERT Blog
Threat Score
JPCERT/CC documents ongoing DangerousPassword APT attacks against cryptocurrency exchanges using varied social-engineering and file-delivery techniques (CHM via LinkedIn, OneNote with embedded MSI, VHD files, and macOS AppleScript). The malware family deploys MSI/DLL payloads that collect and exfiltrate host information via HTTP POST, implements AV-detection and evasion behaviors, and the report supplies C2 domains/IPs and numerous malware hashes for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
