logo

Study of a targeted attack on a Russian enterprise in the mechanical-engineering sector

ID: d36a6dc2-3781-50b6-8406-01b10b513513

STIX ID: report--d36a6dc2-3781-50b6-8406-01b10b513513

Feed Name: Dr.Web News

Threat Score
75/100

Date Published: 2024-03-11

Date Updated: 2026-04-27

...
...

**Executive summary:** In October 2023 a Russian mechanical‑engineering enterprise was targeted via phishing emails carrying password‑protected ZIPs that installed a commodity stealer (Trojan.Siggen21.39882/WhiteSnake) which staged a JavaScript backdoor (JS.BackDoor.60) and SpyBotNET to exfiltrate files, capture screenshots and record audio; the report details the infection chain, persistence techniques (modified .lnk with ADS, registry changes), and provides indicators of compromise and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.