Google's Cloud Run Service Spreads Several Bank Trojans
ID: 037a4418-5e37-597c-af51-d0eeecddc7b8
STIX ID: report--037a4418-5e37-597c-af51-d0eeecddc7b8
Feed Name: Dark Reading
Threat Score
Cisco Talos observed a surge in phishing campaigns (since Sept 2023) that abuse Google Cloud Run to host malicious installers and drop banking Trojans—including Astaroth, Mekiotio, and Ousaban—targeting over 300 institutions across 15 Latin American countries and increasingly spreading into Europe and North America; the campaigns use invoice/tax-themed lures, cloaking (e.g. geoplugin checks), and shared cloud infrastructure, and the report provides IOCs and mitigation advice.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
