Dridex Activity Continues
ID: 0003aa96-c64b-57f6-8956-596341bcb66a
STIX ID: report--0003aa96-c64b-57f6-8956-596341bcb66a
Feed Name: Zscaler Security Research Blog
Dridex banking malware has shown renewed activity after a takedown, with attackers distributing malicious Office/MHTML attachments that use obfuscated macros to download a packed Dridex executable; campaigns include both unsigned and digitally signed binaries (multiple forged/legitimate-seeming certificates). The report documents recent hosting IPs/URLs, MD5 hashes of samples, observed TTPs (macro-based delivery, custom packer, certificate abuse) and geographic hosting distribution, and warns of a steady increase in infections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
