UDPGangster Campaigns Target Multiple Countries
ID: e99cd94a-0974-5178-a475-4c011337d866
STIX ID: report--e99cd94a-0974-5178-a475-4c011337d866
Feed Name: Fortinet Blog
FortiGuard Labs details UDPGangster, a UDP-based backdoor used in targeted phishing campaigns attributed to the MuddyWater group that delivered the malware via macro-enabled Microsoft Word documents targeting Turkey, Israel, and Azerbaijan. The report describes the macro dropper, persistence (copying to %AppData%\RoamingLow as SystemProc.exe and registry startup), numerous anti-analysis and sandbox-detection techniques, C2 communication (notably 157.20.182.75:1269), supported remote commands, and provides IOCs and Fortinet detection/mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
