Fake Browser Updates Lead to BOINC Volunteer Computing Software | Huntress
ID: a0a7a1ae-339f-5856-b2a0-44ea76b8531d
STIX ID: report--a0a7a1ae-339f-5856-b2a0-44ea76b8531d
Feed Name: Huntress Blog
Threat Score
Huntress documents a July 2024 campaign where compromised websites deliver Fake Browser Update (update.js) payloads that install fileless AsyncRAT via obfuscated PowerShell and a maliciously-configured BOINC client used as a C2 mechanism; the report includes IOCs (domains, IPs, file hashes), persistence artifacts (scheduled tasks, registry), detection opportunities, MITRE ATT&CK mappings, and evidence of thousands of clients connecting to malicious BOINC servers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
