Yet Another Signed Malware - Spymel
ID: 91730417-9c6e-5170-a78d-9680c22566d6
STIX ID: report--91730417-9c6e-5170-a78d-9680c22566d6
Feed Name: Zscaler Security Research Blog
Threat Score
Spymel is a .NET information-stealing Trojan distributed via malicious JavaScript in email attachments; it uses compromised DigiCert-signed binaries, persists as svchost.exe/Startup32.1.exe, logs keystrokes, can record video, resists termination, communicates with C2 (android.sh / 213.136.92.111:1216), and includes several IoCs (file hashes, domain/IP, registry keys, file locations) that Zscaler ThreatLabZ analyzed and mitigated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
