Fake Coding Challenges Steal Sensitive Data Via FogDoor.
ID: f5d711b7-0442-5581-8999-3394e7ab4da0
STIX ID: report--f5d711b7-0442-5581-8999-3394e7ab4da0
Feed Name: Cyble Blog
Cyble CRIL discovered a targeted campaign that lures Polish-speaking developers with a fake GitHub "FizzBuzz" recruitment challenge containing an ISO that executes a PowerShell script to install the "FogDoor" backdoor. FogDoor uses geofencing to target Polish victims, retrieves commands from a social media profile (Dead Drop Resolver), steals browser cookies, Wi‑Fi credentials, and user files, stages and uploads exfiltrated data to file-sharing services, notifies the attacker via temporary webhooks, and maintains persistence via a scheduled task; the report includes IOCs (file hashes, URLs), MITRE ATT&CK mappings, and mitigation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
