Njrat Campaign Using Microsoft Dev Tunnels, (Thu, Feb 27th)
ID: 3edeabd8-38d6-5344-96c6-bfc39d6302af
STIX ID: report--3edeabd8-38d6-5344-96c6-bfc39d6302af
Feed Name: SANS ISC Diary
Threat Score
Observed NJRat samples abusing Microsoft Dev Tunnels (devtunnels.ms) as C2 reachability: the report lists two SHA256 samples with the same ImpHash, shows devtunnel C2 URLs and an extracted config (including USB propagation capability), and recommends monitoring for devtunnels.ms in DNS logs to detect similar activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
