A Cereal Offender: Analyzing the CORNFLAKE.V3 Backdoor
ID: e7044f73-8552-5996-b455-b7ffe6b22fec
STIX ID: report--e7044f73-8552-5996-b455-b7ffe6b22fec
Feed Name: Threat Intelligence
Threat Score
### Executive summary Since June 2024 Mandiant has tracked UNC5518 using fake CAPTCHA ("ClickFix") pages to deliver downloader scripts that provide access-as-a-service; those access points have been used by financially motivated UNC5774 to deploy CORNFLAKE.V3, a JavaScript/PHP backdoor that supports persistence, multiple payload types, and abuse of Cloudflare Tunnels to proxy command-and-control communications.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
