Nobelium Coverage Advisory
ID: 7c6dc549-d530-563d-9a69-b58bb787b368
STIX ID: report--7c6dc549-d530-563d-9a69-b58bb787b368
Feed Name: Zscaler Security Research Blog
Microsoft and Zscaler observed a sophisticated Nobelium (APT) email-based campaign that used spearphishing via a malicious HTML dropper which writes an ISO containing an LNK that executes a Cobalt Strike beacon; the campaign targeted roughly 3,000 accounts across ~150 organizations and is linked to the SolarWinds threat actor. Zscaler mapped detections (malware and threat names), recommended network and sandboxing controls, and updated protections to detect the IOCs and variants.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
