Hackers push USB malware payloads via news, media hosting sites
ID: 5fbd1b8a-27f8-50f4-8528-c9ec4a9f6a04
STIX ID: report--5fbd1b8a-27f8-50f4-8528-c9ec4a9f6a04
Feed Name: Bleeping Computer
Mandiant-tracked UNC4990 (active since 2020) operates a financially motivated USB-based infection campaign: victims executing malicious LNK files on removable drives trigger a PowerShell script that fetches intermediary Base64/AES-encoded payloads covertly hosted in benign content on platforms like GitHub, Vimeo, and Ars Technica; these payloads lead to the EMPTYSPACE downloader which installs the QUIETBOARD multi-component backdoor and cryptocurrency miners, enabling remote command execution, USB propagation, clipboard theft for crypto theft, persistence, and information collection, with observed crypto proceeds exceeding $55,000 and primary targeting of users in Italy.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
