TA558 Hackers Weaponize Images for Wide-Scale Malware Attacks
ID: bb115ae6-5a4d-5c70-88c9-e3cec649716b
STIX ID: report--bb115ae6-5a4d-5c70-88c9-e3cec649716b
Feed Name: The Hacker News
TA558 (campaign codename SteganoAmor) is leveraging steganography—embedding obfuscated VBS, PowerShell, and exploit-laden documents inside images and text files—to deliver a range of malware (Agent Tesla, FormBook, Remcos RAT, LokiBot, GuLoader, Snake Keylogger, XWorm) via phishing emails that exploit CVE-2017-11882; attacks have targeted industrial, services, electric power and construction sectors across Latin America and other countries, using compromised SMTP/FTP and paste/image hosting for payload staging and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
