DarkHydrus APT Uses Google Drive to Send Commands to RogueRobin Trojan
#1
Quote:New malicious campaigns attributed to DarkHydrus APT group show the adversary's use of a new variant of the RogueRobin Trojan and of Google Drive as an alternative command and control (C2) communication channel.

The group's latest activity was observed against targets in the Middle East, luring them with Excel documents laced with malicious VBA code (macro).

For security reasons, macros are disabled by default in the Microsoft Office suite, and they do not run unless the user enables the feature manually.

According to research from Palo Alto Networks' Unit 42, the text file hides a Windows Script Component (.SCT) file that delivers a version of the RogueRobin trojan. Originally, this custom payload is PowerShell-based, but it looks like the threat actor ported it to a compiled variant.

In a report this week, Unit 42 writes that "in addition to checks for common analysis tools running on the system. The Trojan also checks to see if a debugger is attached to its processes and will exit if it detects the presence of a debugger."

Source: https://www.bleepingcomputer.com/news/se...in-trojan/
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Hasleo software (formerly called EasyUE...
Hasleo WinToUSB V10....jasonX — 16:10
AxCrypt 3.0.0.94
AxCrypt 3.0.0.94: ...harlan4096 — 11:41
NVIDIA GeForce Game Ready 596.49 driver
Highlights  Gam...harlan4096 — 11:40
AMD launches six new Ryzen PRO 9000 CPUs...
AMD Ryzen PRO 9000...harlan4096 — 11:39
AMD HDMI 2.1 DSC patches could bring 4K ...
AMDGPU HDMI 2.1 pa...harlan4096 — 11:37

[-]
Birthdays
Today's Birthdays
avatar (45)tiojusop
avatar (42)Damiennug
avatar (40)acoraxe
Upcoming Birthdays
avatar (28)akiratoriyama
avatar (48)Jerrycix
avatar (40)awedoli
avatar (82)WinRARHowTo
avatar (39)axuben
avatar (40)ihijudu
avatar (49)contjrat
avatar (44)knigiJow
avatar (46)1stOnecal
avatar (50)Mirzojap
avatar (36)idilysaju
avatar (40)GregoryRog
avatar (45)mediumog
avatar (40)odukoromu
avatar (46)Joanna4589

[-]
Online Staff
There are no staff members currently online.

>