A massive malicious email campaign from the TA505 group has been recently discovered targeting users in Germany and Austria through which the threat actors are spreading FlawedGrace RAT through emails.
This current campaign has been linked with the TA505 hacking group, whose members have used the Dridex banking Trojan and tools in their past attacks, and here are the tools we have mentioned below:-
With a range of small waves of e-mails delivering only a few thousand messages at each stage the attacks began, and while the number of letters spiked in late September to hundreds of thousands.
The whole scenario got changed in late September and in early October 2021; as in this time frame the hacking group, TA505 began sending higher email volumes to more industries, which accounts for tens to hundreds of thousands.
If we will compare the current campaign with the earlier campaigns of TA505, then you will see lots of similarities between them. And the similarities are:-
Here the threat actors after opening malicious Microsoft Excel attachments trick the users into activating macros and then install the next stage downloaders by downloading an obfuscated MSI file.
Once done the above procedures, after that, they install an updated version of the FlawedGrace remote access Trojan. While here in this stage, the loader scaffolds are coded in uncommon languages, and here they are:-
FlawedGrace is first discovered in November 2017, and it is a full-featured RAT that is written in C++, which is specifically designed to prevent reverse engineering and analysis.
The Trojan can receive and follow the following commands through a custom binary protocol on TCP port 443 from its C&C:-
Apart from this, the TA505 is a financially motivated hacking group that is well-renowned for conducting malicious email campaigns on an unprecedented scale.
Not only that even this group also changes their TTPs frequently and that’s why this group is considered as one of the leaders in the cybercrime world.
The text-to-dense representation techniques vary, evolving from character bi-grams to advanced subword vectorizers, combating OOV…
In the ever-evolving realm of cybersecurity, Promon, a trailblazer in mobile security solutions, has brought…
Hackers use Remote Access Trojans (RATs) to gain unauthorized access and control over a victim's…
Black Basta, the fourth-most active ransomware strain with more than 329 victims, has reportedly made…
Notepad++ has been discovered with an uncontrolled search path vulnerability, which could allow threat actors…
WhatsApp has announced the rollout of a new feature to safeguard sensitive conversations. The Secret…