Tag: living off the land
Ursnif reloaded: tracing the latest trojan campaigns
Published 3 years ago
On the 9th of October our customers started reporting the same kind of incident over the span of a few hours. The identified activity appears to be linked to the banking Trojan Ursnif, a long active malware, whose roots can be traced back to 2007 together with ZeuS and SpyEye, still with strong infection capabilities in …
Continue reading “Ursnif reloaded: tracing the latest trojan campaigns”
Spear-phishing campaign leveraging on MSXSL
Published 4 years ago
We have identified an ongoing spear-phishing campaign targeting a variety of entities with malicious RTF documents exploiting three different vulnerabilities: CVE-2017-8570, CVE-2017-11882 and CVE-2018-0802 and taking advantage of a misplaced trust binary, Microsoft’s msxsl, to run a JScript backdoor. The whole attack chain leverages on system’s signed components to remain under the radar as much as possible and it shares many …
Continue reading “Spear-phishing campaign leveraging on MSXSL”
From False Positive to True Positive: the story of Mavinject.exe, the Microsoft Injector
Published 4 years ago
Mavinject is a legitimate Windows component that can be used, and abused, to perform arbitrary code injections inside any running process. As this is a common component on Windows, it can be leveraged to perform living-off-the-land attacks.
A dive into MuddyWater APT targeting Middle-East
Published 4 years ago
MuddyWater is a threat actor that caught our attention for their extensive use of “Living off the Land” attacks in a targeted campaign aimed at the Middle East. During our investigation we reconstruct the evolution of the vectors used and how the group operates to target their victims, evade detections and move laterally inside the compromised …
Continue reading “A dive into MuddyWater APT targeting Middle-East”