Recent Cases of Watering Hole Attacks, Part 1
ID: d6eb93d9-b6a1-59f8-ab56-60bd922afab6
STIX ID: report--d6eb93d9-b6a1-59f8-ab56-60bd922afab6
Feed Name: JPCERT Blog
JPCERT/CC documents a 2023 watering-hole campaign that compromised a university research lab website to display a fake Adobe Flash Player update and trick users into downloading FlashUpdateInstall.exe; the dropper displays a decoy document while creating system32.dll which is injected into Explorer (Early Bird Injection) to run a Cobalt Strike Beacon (v4.5, watermark '666666'). The report includes C2 domains hosted on Cloudflare Workers, multiple malware hashes, Cobalt Strike configuration and observed anti-analysis/AV termination behaviors, providing actionable IOCs and TTPs for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
