Hackers breach ISP to poison software updates with malware
ID: eb30261e-364c-5260-8ac8-a9b734e1036b
STIX ID: report--eb30261e-364c-5260-8ac8-a9b734e1036b
Feed Name: Bleeping Computer
Volexity reported that the Chinese APT StormBamboo compromised an ISP and abused insecure HTTP-based software update workflows and DNS poisoning to push backdoored installers (including MACMA and POCOSTICK/MGBot) to Windows and macOS victims; the attackers also installed a malicious Chrome extension (ReloadText) to steal cookies and mail data. The activity suggests a supply-chain or adversary-in-the-middle approach, with corroborating telemetry and prior related incidents observed by ESET and Symantec.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
