Compromised WordPress Sites Distribute Adwind RAT
ID: feb7591b-d3cf-57e2-8163-b557eb98d341
STIX ID: report--feb7591b-d3cf-57e2-8163-b557eb98d341
Feed Name: Zscaler Security Research Blog
Threat Score
Zscaler ThreatLabZ documents a campaign (since April 2020) where attackers compromise WordPress sites to host multi-layer encrypted JAR files that ultimately deploy the Adwind (jRAT) remote access Trojan; the report includes detailed multi-stage decryption analysis, attribution to the Qarallax crypting service, MITRE ATT&CK mapping, and extensive IOCs (URLs, hashes, IPs) to aid detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
