Glupteba Campaign Exploits MikroTik Routers
ID: e49ce94a-0ed1-5a67-9a1a-fb3827063adf
STIX ID: report--e49ce94a-0ed1-5a67-9a1a-fb3827063adf
Feed Name: Zscaler Security Research Blog
This report analyzes a Glupteba malware campaign that installs kernel rootkits and persistence mechanisms, performs UAC bypass and privilege escalation, propagates laterally using the EternalBlue/DoublePulsar exploit, compromises MikroTik routers via CVE-2018-14847 to run attacker-supplied tasks, and deploys an XMRig miner; it details embedded modules, C2 retrieval via a Bitcoin OP_RETURN payload, provides MITRE ATT&CK mappings, and lists domains, IPs, and hashes as IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
