FortiGuard Labs has recently identified a sophisticated cyberattack involving an Excel file embedded with a VBA macro designed to deploy a DLL file.
The attacker uses a multi-stage malware strategy to deliver the notorious “Cobalt Strike” payload and establish communication with a command and control (C2) server. This attack employs various evasion techniques to ensure successful payload delivery. Over the past few years, Ukraine has been a significant target due to its geopolitical situation. The history of these attacks reveals a pattern of increasing complexity and frequency, particularly during periods of geopolitical tension.
Read more…
Source: Fortinet
Related:
- ABTA hack sees personal details of 43,000 people exposed
March 16, 2017
Yahoo, Adult Friend Finder, LinkedIn, Tumblr and Daily Motion all have something in common: in 2016, details of massive hacks perpetrated against the companies were disclosed. The firms represent a handful of the companies and public bodies around the world that suffered at the hands of hackers last year. Data compromised usually included names, emails, ...
- Why is incident response automation and orchestration so hot?
March 16, 2017
I couldn’t attend the RSA Conference this year, but many cybersecurity professionals and my ESG colleagues told me that incident response (IR) automation and orchestration was one of the hottest topics in the halls of the Moscone Center—through the bar at the W hotel and even at the teahouse on the garden at Yerba Buena. Was ...
- One-third of global firms will fall in cyber attack, says report
March 5, 2017
According to a new report, if there was a cyber attack on global firms, almost 73 per cent of them will fail to identify the threat and ward off any damage to their important data and high-value assets. An era where technology is evolving in leaps and bounds, hacking is no longer a rocket science ...
- Yahoo: 32 Million Accounts Accessed via Cookie Forging Attack
March 2, 2017
An unauthorized third party accessed the company’s proprietary code and learned how to forge cookies. Yahoo believes this is the same actor that caused the 2014 data breach. “The outside forensic experts have identified approximately 32 million user accounts for which they believe forged cookies were used or taken in 2015 and 2016,” Yahoo discloses in ...
- New Global Cybersecurity Report Reveals Misaligned Incentives, Executive Overconfidence Create Advantages for Attacker
March 1, 2017
Intel Security, in partnership with the Center for Strategic and International Studies (CSIS), today released “Tilting the Playing Field: How Misaligned Incentives Work Against Cybersecurity,” a global report and survey revealing three categories of misaligned incentives: corporate structures versus the free flow of criminal enterprises; strategy versus implementation; and senior executives versus those in implementation ...
- UK crime agency arrests suspect in Deutsche Telekom cyber attack
February 23, 2017
British authorities have arrested a suspect in connection with a cyber attack that infected nearly 1 million routers used to access Deutsche Telekom’s (DTEGn.DE) internet service, German federal police said on Thursday. Britain’s National Crime Agency detained the 29-year-old Briton at one of London’s airports on Wednesday, the police said in a statement. Deutsche Telekom welcomed the ...

