Taurus: The New Stealer in Town
ID: f4653db7-7f8a-58ab-9bc8-b6e4740728b0
STIX ID: report--f4653db7-7f8a-58ab-9bc8-b6e4740728b0
Feed Name: Zscaler Security Research Blog
This report analyzes the "Taurus" info‑stealer (attributed to the Predator the Thief group) observed in June 2020: phishing emails with malicious Word macros download an AutoIt interpreter and encoded scripts from GitHub, decode and inject shellcode into dllhost.exe, perform anti-sandbox checks, steal browser credentials, cookies, crypto wallets, FTP/email/app credentials and system data, compress results in-memory and exfiltrate to XORed C2 endpoints; the report includes technical details, MITRE ATT&CK mappings, and IOCs (file hashes, domains, and an IP for the attacker panel).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
