New Voldemort malware abuses Google Sheets to store stolen data
ID: 8c1f1cdf-c63a-514a-b2ba-ac6f2d7c48e8
STIX ID: report--8c1f1cdf-c63a-514a-b2ba-ac6f2d7c48e8
Feed Name: Bleeping Computer
**Voldemort backdoor phishing campaign:** Proofpoint observed a global phishing campaign (began Aug 5, 2024) distributing a previously undocumented C-based backdoor named "Voldemort" via tax-themed lures to over 70 organizations (20,000+ emails, peak ~6,000/day), primarily targeting insurance, aerospace, transportation, and education; attackers use Google AMP/InfinityFree landing pages, search-ms redirection to WebDAV-hosted LNK/ZIP files that trigger a Python loader, DLL side-loading with a legitimate Cisco executable, and Google Sheets as a resilient C2/exfiltration channel; recommended mitigations include restricting external file-sharing, blocking TryCloudflare usage, and monitoring for suspicious PowerShell activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
