A look at the recent BuleHero botnet payload
ID: 4dcbc565-8b11-55be-a806-337021592f34
STIX ID: report--4dcbc565-8b11-55be-a806-337021592f34
Feed Name: Zscaler Security Research Blog
This report analyzes the BuleHero botnet, a modular malware campaign that uses leaked ShadowBroker SMB exploits (EternalBlue/EternalRomance/EternalChampion), many web-application RCEs (Tomcat, Struts, WebLogic, Drupal, Solr, ThinkPHP), credential theft (Mimikatz), and remote execution tools (PsExec/WMIC) to spread laterally, deploy XMRig miners and Gh0st RAT, persist via services and scheduled tasks, and manipulate firewall/associations; the document includes detailed IOCs (URLs, IPs, and file hashes) and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
