New DEEP#GOSU Malware Campaign Targets Windows Users with Advanced Tactics
ID: 9d248249-4248-51a5-9109-f28cfc628a09
STIX ID: report--9d248249-4248-51a5-9109-f28cfc628a09
Feed Name: The Hacker News
Securonix and reporting outlets detail a sophisticated DEEP#GOSU campaign linked to the North Korean APT Kimsuky that uses weaponized .LNK files in ZIP attachments to execute embedded PowerShell and VBScript, fetch additional modules from Dropbox/Google Docs, and deploy a TruRat .NET remote access trojan to perform keylogging, clipboard capture, reconnaissance and data exfiltration, with persistence via scheduled tasks and WMI; the report also contextualizes this activity with other state-linked campaigns and crypto-laundering by Lazarus/Andariel.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
