DNS Early Detection – Malicious Trojan Installers for WINSCP and PUTTY – Breaking the Kill Chain
ID: 97119ddf-6b8b-5dcb-914e-f041a98f6445
STIX ID: report--97119ddf-6b8b-5dcb-914e-f041a98f6445
Feed Name: Infoblox Threat Intel Blog
Infoblox analyzes a Rapid7-reported malvertising campaign that lures IT personnel to typo-squatted sites hosting trojanized WinSCP and PuTTY installers; the installers side-load a malicious DLL that executes a Sliver beacon, enables persistence (services, scheduled tasks), disables defenses via a vulnerable driver, supports lateral movement and exfiltration, and has been used in attempted ransomware deployments, while Infoblox highlights early DNS-based detection and blocking of the malicious domains.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
