Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
1 résultat taggé CV  ✕
The Curious Case of an Egg-Cellent Resume https://thedfirreport.com/2024/12/02/the-curious-case-of-an-egg-cellent-resume/#services
02/12/2024 09:33:50
QRCode
archive.org
  • Initial access was via a resume lure as part of a TA4557/FIN6 campaign.
  • The threat actor abused LOLbins like ie4uinit.exe and msxsl.exe to run the more_eggs malware.
  • Cobalt Strike and python-based C2 Pyramid were employed by the threat actor for post-exploitation activity.
  • The threat actor abused CVE-2023-27532 to exploit a Veeam server and facilitate lateral movement and privilege escalation activities.
  • The threat actor installed Cloudflared to assist in tunneling RDP traffic.
  • This case was first published as a Private Threat Brief for customers in April of 2024.
  • Eight new rules were created from this report and added to our Private Detection Ruleset.
thedfirreport EN 2024 Egg-Cellent Resume lure CV Resume Cloudflared
4368 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio