Ande Loader Malware Targets Manufacturing Sector in North America
ID: 55139a87-6219-59d9-9105-b1b6d1f717cb
STIX ID: report--55139a87-6219-59d9-9105-b1b6d1f717cb
Feed Name: The Hacker News
Threat Score
The report details Blind Eagle (APT-C-36) expanding operations in North America by delivering remote access trojans (Remcos, NjRAT and others) via phishing emails that use password-protected RAR/BZ2 archives containing VBScript which launches Ande Loader; crypters and alternative delivery (Discord CDN) are observed, and related loader activity (DBatLoader) abusing a vulnerable driver to disable security tools is also noted.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
