Study of a targeted attack on a Russian enterprise in the mechanical-engineering sector
ID: d36a6dc2-3781-50b6-8406-01b10b513513
STIX ID: report--d36a6dc2-3781-50b6-8406-01b10b513513
Feed Name: Dr.Web News
**Executive summary:** In October 2023 a Russian mechanical‑engineering enterprise was targeted via phishing emails carrying password‑protected ZIPs that installed a commodity stealer (Trojan.Siggen21.39882/WhiteSnake) which staged a JavaScript backdoor (JS.BackDoor.60) and SpyBotNET to exfiltrate files, capture screenshots and record audio; the report details the infection chain, persistence techniques (modified .lnk with ADS, registry changes), and provides indicators of compromise and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
