Briefing Malware
BLOG CERT SOGETI ESEC
CERT BRIEFING MALWARE

Briefing Malware - 22/06/2021

22nd of June 2021 - Winners of the 25th week : njRAT, Redline and Lokibot.

Some links points at extended actionnable intelligence (Threat Bulletins, TTPs, signatures, etc) on our Threat Intelligence Platform Anomali. This access is limited to our clients.

 

Threat statistics report

Publication date:

22/06/2021

Distribution :

TLP : WHITE  

What's new?

Redline (NC)

Digital artists targeted in RedLine infostealer campaign

Multiple accomplished digital artists report on Twitter that they got hacked after being approached to create new digital art. They were approached either via Instagram, Twitter DM (message) or directly via email. The attackers have masqueraded themselves to appear from the genuine Skylum product website; often claiming to be from South Korea while redirecting artists towards a fake clone of the Skylum website. The victim was asked to download an archive from this site, where the archive contained Redline stealer malware inside an Exe.

https://securityboulevard.com/2021/06/digital-artists-targeted-in-redline-infostealer-campaign/

Download the report