Fresh Loader Targets Aviation Victims with Spy RATs
#1
Information 
Quote:A cyberattack campaign that goes after aviation targets has been uncovered, which is spreading remote access trojan (RAT) malware bent on cyber-espionage.
 
Researchers from Microsoft said this week on Twitter that spear-phishing emails are the main attack vector. Individuals in the aerospace and travel sectors are being targeted with a range of gambits, such as using the ruse of needing transportation-charter help.
 
“The campaign uses emails that spoof legitimate organizations, with lures relevant to aviation, travel or cargo,” according to Microsoft.
Quote:The bones of this campaign have been observed elsewhere. Morphisec in an earlier analysis last week was the first to break down the loader used in the aviation attacks. It said that it too has seen Snip3 being used to deliver both ASyncRAT or RevengeRAT, “which often come from an open-source RAT platform originally available through the NYANxCAT Github repository.” It didn’t specify the industry targets.
 
Researchers there, again dovetailing with Microsoft’s observations, also identified a campaign that used Agent Tesla (and another one that used NetWire RAT).
 
Morphisec described Snip3 as a “highly sophisticated crypter-as-a-service” that’s been used to deliver a wide range of RAT families onto victim machines, starting in February of this year.

Read more: Fresh Loader Targets Aviation Victims with Spy RATs | Threatpost
Reply


Messages In This Thread
Fresh Loader Targets Aviation Victims with Spy RATs - by silversurfer - 13 May 21, 17:48

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Surfshark VPN : Award-winning VPN servi...
Surfshark New Pric...jasonX — 10:21
Surfshark VPN : Award-winning VPN servi...
Surfshark New Pric...jasonX — 10:21
AntGROUP Inc. / VCap-developer
Ant Download Manager...jasonX — 10:20
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 10:07
Mozilla Firefox Browser 150.0.3
Mozilla Firefox Br...harlan4096 — 07:22

[-]
Birthdays
Today's Birthdays
avatar (41)axylisyb
avatar (44)tukrublape
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (38)owysykan
avatar (49)beautgok
avatar (39)axuben
avatar (40)ihijudu
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
avatar (49)contjrat
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>