MSUpdater Trojan And Link To Targeted Attacks
ID: e285cc99-6860-59a5-8841-be7fa70df906
STIX ID: report--e285cc99-6860-59a5-8841-be7fa70df906
Feed Name: Zscaler Security Research Blog
Threat Score
This joint Zscaler and Seculert report describes a targeted campaign delivering a VM-aware remote access Trojan via malicious PDFs that exploit an Adobe vulnerability (CVE-2010-2883). The malware decrypts functionality at runtime, communicates with command-and-control servers over encoded HTTP using Microsoft Update-like filenames and paths to evade detection, and includes indicators and TTPs useful for detection and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
