Hackers now use AppDomain Injection to drop CobaltStrike beacons
ID: b782de24-edd6-574c-813e-697e53570843
STIX ID: report--b782de24-edd6-574c-813e-697e53570843
Feed Name: Bleeping Computer
Threat Score
NTT Japan observed a July 2024 campaign using AppDomainManager Injection and the GrimResource MSC exploit to create malicious exe.config and DLL files adjacent to signed Microsoft executables, enabling stealthy execution of Cobalt Strike beacons; victims include government, military, and energy organizations in Taiwan, the Philippines, and Vietnam, and overlaps with other reporting suggest (low-confidence) APT41 involvement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
