Briefing Malware
BLOG CERT SOGETI ESEC
CERT BRIEFING MALWARE

Briefing Malware - 15/06/2021

15th of June 2021 - Winners of the 24th week : Redline, njRAT and Lokibot.

Some links points at extended actionnable intelligence (Threat Bulletins, TTPs, signatures, etc) on our Threat Intelligence Platform Anomali. This access is limited to our clients.

 

Threat statistics report

Publication date:

15/06/2021

Distribution :

TLP : WHITE  

What's new?

Redline (NC)

Google Pay Per Click (PPC) advertisement leads to infostealers

Adversaries will use any possible method to gather targets, even throughout pay-per-click (PPC) ads in Google’s search results to rise a malicious website as a top search result.

Those advertisements will lure victims towards malicious Anydesk, Dropbox or Telegram packages wrapped as an ISO.

https://blog.morphisec.com/google-ppc-ads-deliver-redline-taurus-and-mini-redline-infostealers

Download the report