Vietnamese Threat Actor's Strategy On Digital Marketers
ID: 0ca4b64a-7e62-5b22-bfcb-e1a9bb811db7
STIX ID: report--0ca4b64a-7e62-5b22-bfcb-e1a9bb811db7
Feed Name: Cyble Blog
Executive Summary: Cyble Research and Intelligence Labs (CRIL) uncovered a targeted, multi-stage malware campaign delivering a modified Quasar RAT via a malicious LNK/Powershell chain and AES-encrypted payloads; the campaign uses extensive sandbox/VM and debugger detection, privilege escalation (PowerShell/CMSTP), persistence, and defense evasion, is attributed to a Vietnamese threat actor targeting Meta Ads/digital marketing professionals, and includes IOCs and MITRE ATT&CK mappings for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
