Attackers Stitch Together Frankenstein Campaign Using Free Tools
#1
Quote:Threat actors behind a highly-targeted series of cyber attacks spanning from January to April 2019 have been seen employing malicious tools built using freely available components to infect victims with malware designed to harvest credentials.
 
The campaign was named 'Frankenstein' by Cisco Talos, a name which "refers to the actors' ability to piece together several unrelated components — leveraged four different open-source techniques to build the tools used during the campaign."
 
The Frankenstein campaign operators used the following open source components to build their malicious tools:
• An article to detect when your sample is being run in a VM
• A GitHub project that leverages MSbuild to execute a PowerShell command
• A component of GitHub project called "Fruityc2" to build a stager
• A GitHub project called "PowerShell Empire" for their agents

As the researchers further discovered, the threat actors made it their mission to avoid detection, checking for running programs such as Process Explorer and if the infected machine was actually a virtual machine environment.

"The threat actors also took additional steps to only respond to GET requests that contained predefined fields, such as a non-existent user-agent string, a session cookie, and a particular directory on the domain. The threat actors also used different types of encryption in order to protect data in transit," says the Cisco Talos report.

SOURCE: https://www.bleepingcomputer.com/news/se...ree-tools/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Attackers Stitch Together Frankenstein Campaign Using Free Tools - by silversurfer - 04 June 19, 18:50

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
AirVPN
AirVPN UK Infrastr...jasonX — 20:29
AIDA64 by FinalWire
AIDA64 v8.25 RELEASE...jasonX — 19:46
Google Updates Wear OS to Deliver Earthq...
Google is updating...harlan4096 — 12:28
HWiNFO v8.42
HWiNFO v8.42 Re...harlan4096 — 11:04
Mozilla Firefox Browser 148.0
Mozilla Firefox Br...harlan4096 — 08:24

[-]
Birthdays
Today's Birthdays
avatar (44)Baihu
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>