New CMoon USB worm targets Russians in data theft attacks
ID: d4bf09fe-f01e-5cd8-9356-c2c20c0f5548
STIX ID: report--d4bf09fe-f01e-5cd8-9356-c2c20c0f5548
Feed Name: Bleeping Computer
A .NET worm named CMoon, discovered by Kaspersky in July 2024, was distributed through a compromised gas company website in Russia by replacing document links with self-extracting archives that install the worm. CMoon persists via startup shortcuts and file date tampering, propagates to USB drives (replacing files with shortcuts and staging interesting files in hidden directories), exfiltrates targeted credential and document file types (including certificate and key formats) to an attacker server (RC4-encrypted, MD5-verified), and can download additional payloads, capture screenshots, and initiate DDoS attacks; while distribution was removed from the site on July 25, its self-spreading nature raises the risk of further spread and opportunistic infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
