Phishing campaign spreading CARROTBAT dropper focuses on cryptocurrency...
#1
Quote:A phishing campaign targeting the Korean peninsula is using a malicious dropper called CARROTBAT to deliver decoy documents and secondary payloads such as remote access trojans to its victims.

Dubbed Fractured Block, the campaign began last March, but has noticeably picked up steam in the last three months, according to a blog post by Josh Grunzweig and Kyle Wilhoit, researchers at Palo Alto Networks’ Unit 42 division.

Unit 42 has so far identified 29 unique CARROTBAT samples, noting that their final payloads have varied between the FTP-based RAT SYSCON and the recently discovered Oceansalt malware implant that uses code associated with APT1 (aka Comment Crew), a reputed Chinese APT actor.

Unit 42 describes CARROTBAT as “a dropper that allows an attacker to drop and open an embedded decoy file” saved as one of 11 different formats, “followed by the execution of a command that will download and run a payload on the targeted machine. This command will attempt to download and execute a remote file via the Microsoft Windows built-in certutil utility.”

Source: https://www.scmagazine.com/home/security...interests/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Messages In This Thread
Phishing campaign spreading CARROTBAT dropper focuses on cryptocurrency... - by silversurfer - 30 November 18, 18:11

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
GFYI [Official] HitmanPro.Alert Mother'...
GIVEAWAY HAS ENDED. ...jasonX — 05:07
GFYI [Official] Master PDF Editor Mothe...
GIVEAWAY HAS ENDED. ...jasonX — 05:07
ON1 Software
  20 Years of O...jasonX — 05:02
Celebrating 20 Years of ON1: ON1 Photo C...
Celebrating 20 Years...jasonX — 05:00
AntGROUP Inc. / VCap-developer
VCap Downloader ...jasonX — 04:58

[-]
Birthdays
Today's Birthdays
avatar (47)vadimTob
avatar (37)leannauu4
Upcoming Birthdays
avatar (38)Tedscolo
avatar (45)brakasig
avatar (44)JamesReshy
avatar (46)Francisemefe
avatar (39)leoniDup
avatar (38)Patrizaancem
avatar (38)biobdam
avatar (41)zacforat
avatar (46)NemrokReks
avatar (37)Barrackleve
avatar (39)Julioagopy
avatar (49)aolaupitt2558
avatar (39)storoBox
avatar (47)kinotHeemn
avatar (38)Ceballos1976
avatar (39)efynu
avatar (31)horancos

[-]
Online Staff
jasonX's profile jasonX
Administrator

>