HeptaX: Unauthorized RDP Connections In Cyberespionage
ID: f6a26fca-dce8-5b77-9678-03df5a6a6a7e
STIX ID: report--f6a26fca-dce8-5b77-9678-03df5a6a6a7e
Feed Name: Cyble Blog
Threat Score
CRIL identified an ongoing multi-stage campaign dubbed “HeptaX” that starts from malicious .lnk attachments and uses PowerShell and BAT scripts to persist, create a hidden admin account (BootUEFI), disable UAC, weaken RDP authentication, and deploy ChromePass to harvest browser credentials; the report provides detailed stage analysis, C2 infrastructure (157.173.104.153), IoCs, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
