Israeli Entities Targeted by Cyberattack Using Donut and Sliver Frameworks
ID: 05b6136a-94de-5016-8201-6a1d477792e5
STIX ID: report--05b6136a-94de-5016-8201-6a1d477792e5
Feed Name: The Hacker News
Cybersecurity researchers detailed a targeted campaign dubbed 'Supposed Grasshopper' that uses realistic WordPress sites to deliver VHD files containing a Nim-based downloader; that downloader fetches Donut-generated shellcode from attacker infrastructure which is used to deploy the Sliver C2 framework. The activity leverages publicly available open-source tooling and dedicated infrastructure to target various Israeli entities, and the report also references a separate Excel-based Orcinius trojan infection chain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
