Brand Trust as a Weapon: Multi-Brand Impersonation Campaigns Deliver JWrapper Malware
ID: f27a347f-e34b-517d-8c3e-ce5101bcc579
STIX ID: report--f27a347f-e34b-517d-8c3e-ce5101bcc579
Feed Name: Cofense Blog
Threat Score
**Executive Summary:** Cofense PDC observed a phishing campaign impersonating DocuSign/Adobe that delivers a JWrapper-wrapped SimpleHelp remote access client (RAT) via malicious installer downloads; the report details infection flow, persistence techniques, observed command execution, C2 infrastructure, and provides IOCs and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
