FIN7 Cybercrime Group Targeting U.S. Auto Industry with Carbanak Backdoor
ID: b48ef918-e87e-5cec-b9fd-62627e8bb86d
STIX ID: report--b48ef918-e87e-5cec-b9fd-62627e8bb86d
Feed Name: The Hacker News
Threat Score
FIN7 conducted a targeted spear-phishing campaign against a large U.S. automotive manufacturer using a fake IP-scanner site that redirected to a Dropbox-hosted executable (WsTaskLoad.exe) which deployed a multi-stage payload culminating in the Carbanak/Anunak backdoor; additional payloads (POWERTRASH) and persistence via OpenSSH were observed, but the infection was detected and the affected system removed before lateral movement or confirmed ransomware deployment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
