MINEBRIDGE Remote-access Trojan (RAT) 2021
ID: 403450d6-dd84-572d-97f1-0eb3abf29fef
STIX ID: report--403450d6-dd84-572d-97f1-0eb3abf29fef
Feed Name: Zscaler Security Research Blog
Threat Score
**Zscaler ThreatLabZ describes a TA505-linked campaign deploying the MINEBRIDGE RAT via macro-laden Word resume lures that use LOLBins and TeamViewer DLL side-loading to gain persistence, hook APIs, exfiltrate TeamViewer credentials and system information, and communicate with hardcoded C2 domains; the report includes detailed TTP mapping and comprehensive IOCs (hashes, filenames, domains, network paths).**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
