Researchers Detail Multistage Attack Hijacking Systems with SSLoad, Cobalt Strike
ID: 1f54a7de-8127-5519-b578-bf92d5ffa8a8
STIX ID: report--1f54a7de-8127-5519-b578-bf92d5ffa8a8
Feed Name: The Hacker News
Threat Score
**FROZEN#SHADOW**: Researchers report an active phishing campaign delivering the SSLoad malware (via obfuscated JavaScript and macro-enabled Word documents or booby-trapped contact-form URLs) that fetches an MSI installer to execute payloads and beacon to C2; operators then deploy Cobalt Strike and ScreenConnect to harvest credentials, pivot laterally, and create domain administrator accounts, impacting organizations across Asia, Europe, and the Americas.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
