FIN7 targets American automaker’s IT staff in phishing attacks
ID: b936daa4-1aa7-5700-8bd3-b45973b821a4
STIX ID: report--b936daa4-1aa7-5700-8bd3-b45973b821a4
Feed Name: Bleeping Computer
Threat Score
FIN7 targeted privileged IT employees at a large U.S. automaker with spear-phishing that led to a typosquatted Advanced IP Scanner installer (WsTaskLoad.exe) which executed a multi-stage loader (including WAV/DLL/shellcode) to decrypt dmxl.bin and deploy the Anunak backdoor; researchers observed LoLBas, obfuscated PowerShell ('PowerTrash'), scheduled tasks and OpenSSH usage, though the intrusion did not progress beyond the initial host.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
