Fileless Attack Targets US-Taiwan Defense Event Attendees
ID: ae464705-41e9-5c6c-9d61-2a02453d3c71
STIX ID: report--ae464705-41e9-5c6c-9d61-2a02453d3c71
Feed Name: Cyble Blog
CRIL identified a targeted, fileless malware campaign impersonating US–Taiwan Defense Industry Conference registration forms: attackers distribute a ZIP containing a .pdf.lnk that drops a Confuser-protected updater.exe into the Startup folder, which downloads XOR/base64-encoded DLLs and C# source from compromised URLs, compiles and executes code in memory to evade detection, and exfiltrates stolen data to a TA-controlled server; the report includes IOCs, network indicators, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
