Fake updates campaign abuses BOINC
ID: 18afd4c1-342e-570a-8f64-e569aa724859
STIX ID: report--18afd4c1-342e-570a-8f64-e569aa724859
Feed Name: Arctic Wolf Blog
Arctic Wolf Labs analyzed a July 2024 SocGholish/FakeUpdate campaign where compromised websites delivered Update.js which invoked PowerShell to fetch an obfuscated SVG script (f15.svg) and a second-stage payload (1.php?s=boicn), ultimately installing a BOINC client configured to a spoofed Rosetta@home project; the actor created scheduled tasks for persistence, modified registry and firewall settings, performed local account and group enumeration, and attempted to deploy a local proxy, with multiple IoCs and mapped MITRE TTPs provided, though the intrusion was interrupted before clear C2 or post-compromise objectives were observed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
