Writeup on nbc.com distributing Citadel malware
ID: 1ddf8acc-1deb-5053-b47c-355b16a4e47c
STIX ID: report--1ddf8acc-1deb-5053-b47c-355b16a4e47c
Feed Name: Fox-IT blog
Threat Score
The blog reports a drive-by compromise of NBC.com where an injected iframe redirected visitors to the RedKit exploit kit that served Citadel banking malware (malicious JAR/PDF). The malware was configured to manipulate traffic for a long list of US financial institutions, had low AV detection at the time, and was active for several hours; the post includes example malicious URLs and a brief timeline.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
