German Manufacturing Under Phishing Attacks: Tracking a Stealthy AsyncRAT Campaign
ID: 322af21e-2573-564a-afbb-9557578d773d
STIX ID: report--322af21e-2573-564a-afbb-9557578d773d
Feed Name: ANY.RUN's Cybersecurity Blog
Threat Score
This report analyzes a focused phishing campaign targeting German manufacturing firms that used localized invoice lures and a Dropbox-hosted ZIP containing a malicious .url/.lnk to exploit CVE-2024-43451 via WebDAV, enabling deployment of AsyncRAT and XWorm; sandbox data and multiple related submissions indicate active exploitation, low vendor detections on VirusTotal, and a reproducible attack pattern useful for proactive threat hunting and IOC enrichment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
