Malware Delivery via Cloud Services Exploits Unicode Trick to Deceive Users
ID: 5fdb468f-73ee-586c-bbbe-3e70670b85da
STIX ID: report--5fdb468f-73ee-586c-bbbe-3e70670b85da
Feed Name: The Hacker News
CLOUD#REVERSER is a phishing-driven malware campaign that uses an executable disguised as an Excel file via the Unicode right-to-left override to trick victims. The payload drops obfuscated VBScript and PowerShell files that create scheduled-task persistence (masquerading as Chrome updates), download additional PowerShell scripts and binaries from Google Drive and Dropbox, and can execute payloads in memory to maintain C2 and exfiltrate data; the on-the-fly nature of the downloaded scripts allows actors to modify capabilities after compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
