CoralRaider attacks use CDN cache to push info-stealer malware
ID: 8f4c0c4a-2e3e-5d7e-9c0a-7522d4889ef9
STIX ID: report--8f4c0c4a-2e3e-5d7e-9c0a-7522d4889ef9
Feed Name: Bleeping Computer
Threat Score
Cisco Talos attributes an ongoing CoralRaider campaign to a financially motivated actor using CDN cache-hosted HTA/PowerShell chains delivered via malicious LNK archives to deploy info-stealers (Cryptbot, LummaC2, Rhadamanthys). The campaign uses obfuscation, Defender exclusion modifications, a FoDHelper UAC bypass, and targets victims across multiple countries to steal credentials, financial data, and account cookies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
