logo

Attack Trends Related to DangerousPassword

ID: bfc8f9c3-eae0-5e73-9329-2a6c1f31b666

STIX ID: report--bfc8f9c3-eae0-5e73-9329-2a6c1f31b666

Feed Name: JPCERT Blog

Threat Score
80/100

Date Published: 2023-05-12

Date Updated: 2026-04-19

Author: 朝長 秀誠 (Shusei Tomonaga)

...
...

JPCERT/CC documents ongoing DangerousPassword APT attacks against cryptocurrency exchanges using varied social-engineering and file-delivery techniques (CHM via LinkedIn, OneNote with embedded MSI, VHD files, and macOS AppleScript). The malware family deploys MSI/DLL payloads that collect and exfiltrate host information via HTTP POST, implements AV-detection and evasion behaviors, and the report supplies C2 domains/IPs and numerous malware hashes for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.