StormBamboo Compromises ISP to Abuse Insecure Software Update Mechanisms
ID: 154c9b6e-0978-5c5a-85fa-22a937a8484d
STIX ID: report--154c9b6e-0978-5c5a-85fa-22a937a8484d
Feed Name: Volexity Blog
Volexity documents a mid-2023 campaign by the StormBamboo threat actor that compromised an ISP’s DNS infrastructure to poison DNS responses and abuse insecure HTTP-based automatic update mechanisms, resulting in deployment of multiple malware families (including MACMA and POCOSTICK), a DNS/HTTP interception tool (CATCHDNS) for network appliances, and a cookie-exfiltrating Chrome extension; the report contains technical analysis, extracted configurations, and IOCs and detection rules for defenders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
