mirror of
https://github.com/cert-orangecyberdefense/cti
synced 2026-06-08 14:45:26 +00:00
image
This commit is contained in:
committed by
GitHub
parent
447ea5dfda
commit
afdade9fab
@@ -3,6 +3,8 @@ Our investigation identified overlaps across these campaigns, and related sample
|
||||
|
||||
#CTI #ThreatIntel #STXRAT
|
||||
|
||||

|
||||
|
||||
1/ Our investigation started from the publicly documented FileZilla campaign, which used a fake FileZilla website to distribute trojanized FileZilla 3.69.5 packages.
|
||||
The campaign used two delivery variants:
|
||||
a portable archive containing the legitimate FileZilla package plus a malicious version.dll
|
||||
@@ -27,4 +29,5 @@ Notably, credential theft is only activated after successful C2 interaction.
|
||||
|
||||
7/ We published a full advisory for our customers on the infection chain, overlaps, and malware analysis. Related IoCs are also available in this public GitHub repository.
|
||||
|
||||
|
||||
|
||||
|
||||
Reference in New Issue
Block a user