HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures
ID: 654703c0-7e9f-574e-8062-eca1ed4a451c
STIX ID: report--654703c0-7e9f-574e-8062-eca1ed4a451c
Feed Name: ANY.RUN's Cybersecurity Blog
Threat Score
This report analyzes an active LATAM-targeted phishing campaign that uses fake DocuSign and NFe tax-document lures to deliver a custom HVNC backdoor capable of hidden remote desktop control, keystroke monitoring, Firefox cookie/history theft, AV/EDR discovery, and Startup-folder persistence; the analysis includes static and dynamic findings, IOCs (file hashes, IPs, domains, mutex and filenames), MITRE ATT&CK mapping, and operational detection/hunting guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
