Inception Group Uses POWERSHOWER Backdoor in Two-Stage Spear Phishing Attacks
#1
Quote:Backdoor uses anti-forensics techniques to hinder analysis

The Inception threat group has been observed exploiting the CVE-2017-11882 Microsoft Office memory corruption vulnerability and a PowerShell-based backdoor dubbed POWERSHOWER in their most recent multi-stage attack campaign during October 2018.

In the attack campaign recently witnessed by Palo Alto Networks' Unite 42, Inception has remodeled their attack model using a single document that employs Microsoft Word remote templates to download remote VBScript exploit payloads packaged as OLE objects.

Source: https://news.softpedia.com/news/inceptio...3623.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Thunderbird 151.0 & 140.11.0esr
Thunderbird 151.0 ...harlan4096 — 07:23
Waterfox 6.6.13
Waterfox 6.6.13 ...harlan4096 — 06:14
Subscription security: how to protect yo...
Why subscription o...harlan4096 — 06:10
Mozilla Firefox Browser 151.0
Mozilla Firefox Br...harlan4096 — 06:09
Tor Browser 15.0.14
Tor Browser 15.0.1...harlan4096 — 06:07

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (39)axuben
avatar (40)ihijudu
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>