Fraud Investigation Reveals Sophisticated Python Malware
ID: ebe303c4-8733-5cc7-b920-4f3118d52fec
STIX ID: report--ebe303c4-8733-5cc7-b920-4f3118d52fec
Feed Name: Infosecurity Magazine (News)
Threat Score
Secuinfra uncovered a sophisticated Python-based malware deployment discovered after a fraud investigation: attackers used hidden PowerShell downloads (svchoss.exe) from an IP hosted in Tencent networks, deployed an obfuscated PyInstaller payload and a concealed Python environment, and operated Cobalt Strike beacons and persistence via startup scripts; extracted artifacts indicate credential- and wallet-theft and active unauthorized PayPal transfers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
