logo

DNS Early Detection – Malicious Trojan Installers for WINSCP and PUTTY – Breaking the Kill Chain

ID: 97119ddf-6b8b-5dcb-914e-f041a98f6445

STIX ID: report--97119ddf-6b8b-5dcb-914e-f041a98f6445

Feed Name: Infoblox Threat Intel Blog

Threat Score
75/100

Date Published: 2024-08-29

Date Updated: 2026-04-28

Author: Michael Zuckerman

...
...

Infoblox analyzes a Rapid7-reported malvertising campaign that lures IT personnel to typo-squatted sites hosting trojanized WinSCP and PuTTY installers; the installers side-load a malicious DLL that executes a Sliver beacon, enables persistence (services, scheduled tasks), disables defenses via a vulnerable driver, supports lateral movement and exfiltration, and has been used in attempted ransomware deployments, while Infoblox highlights early DNS-based detection and blocking of the malicious domains.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.