Italian Businesses Hit by Weaponized USBs Spreading Cryptojacking Malware
ID: 1d5e11e8-4b75-51bf-bb38-260a1c22ad9f
STIX ID: report--1d5e11e8-4b75-51bf-bb38-260a1c22ad9f
Feed Name: The Hacker News
UNC4990, assessed to operate from Italy and active since late 2020, is conducting multi-industry USB-borne infection campaigns that begin with malicious LNK shortcuts on removable drives and use PowerShell to fetch the EMPTYSPACE (BrokerLoader/Vetta Loader) downloader from third-party hosts; EMPTYSPACE then retrieves next-stage payloads including the QUIETBOARD Python backdoor, which can hijack clipboard cryptocurrency addresses, propagate to removable drives, take screenshots, gather system information, and load additional modules such as coin miners.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
