[ << ALL_FEED ]

Gapucino* is GOFFEE

More in General

Gapucino* — is GOFFEE ☕️

Today we are covering one of the most active campaigns currently underway in Russia. Other researchers call it GOFFEE.

As the initial vector, attackers use phishing emails with documents containing a malicious macro. We analyzed an example of such a document in the post !!р^д**н**c 🤔

Similar documents can be detected using the pattern:


content:"DigitalRSASignature"

In addition, experts from Cisco Talos just recently described a similar attack chain targeting Russian companies.

After gaining access to the infrastructure, the attackers use the Mythic agent QwakMyAgent, written in PowerShell, which was detailed by F.A.C.C.T. specialists.

One of the most interesting tools used by the attackers in this campaign is the IIS module Owowa (more on that in the next post).

* Gapucino.com — one of the attackers’ C2 servers.

#dfir #detect #C2 #TI
@ptescalator

More from oUth0R

More from oUth0R

More in General