When Hackers are Quicker than Antiviruses: Cobalt Group Bypasses Antivirus Protection
ID: 06cdde5f-a8d0-5259-8745-a57cf86b7c82
STIX ID: report--06cdde5f-a8d0-5259-8745-a57cf86b7c82
Feed Name: Group-IB Blog
The report details a mass phishing campaign by the Cobalt criminal group targeting financial institutions that leveraged the long-standing Microsoft Equation Editor vulnerability CVE-2017-11882 to deliver malicious RTF attachments, deploy obfuscated HTA/PowerShell loaders and Cobalt-Strike beacons; it includes timeline, sample MD5s, domains and IPs, describes how the exploit was modified to evade AV detection, and recommends disabling the vulnerable component or applying Microsoft's patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
