logo

HeptaX: Unauthorized RDP Connections In Cyberespionage

ID: f6a26fca-dce8-5b77-9678-03df5a6a6a7e

STIX ID: report--f6a26fca-dce8-5b77-9678-03df5a6a6a7e

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2024-11-08

Date Updated: 2026-07-16

...
...

CRIL identified an ongoing multi-stage campaign dubbed “HeptaX” that starts from malicious .lnk attachments and uses PowerShell and BAT scripts to persist, create a hidden admin account (BootUEFI), disable UAC, weaken RDP authentication, and deploy ChromePass to harvest browser credentials; the report provides detailed stage analysis, C2 infrastructure (157.173.104.153), IoCs, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.