Malware flies, malware runs, malware sits in the sandbox ⏳

More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…
Malware flies, malware runs, malware sits in the sandbox ⏳
In mid-August, we reported on a new large-scale campaign by the PhantomCore group, detected by the Threat Intelligence department of the Positive Technologies Expert Security Center (PT ESC TI).
A few days after the publication of the study, PT Sandbox helped prevent an attack on Russian defense and industrial enterprises, as well as the banking sector, which used an obfuscated variation of the PhantomRShell tool employed by PhantomCore.
🗓 This happened on August 24. At the same time, in open malware information aggregation systems, data on the samples appeared only on the morning of August 25, and a day later, the malware was still not detected by most popular antivirus solutions.
The attack began with an email from a completely legitimate sender—their account had been compromised. The attachment in archive format turned out to be a polyglot file assembled from three sequentially concatenated objects of different types: a DLL (containing a backdoor-type malicious payload), a PDF (to distract attention), and a ZIP archive (with an LNK file inside for persistence on the system).
Thanks to backdoor traffic analysis, the sandbox was able to correlate this sample with the PhantomRShell tool, which allows the attacker to remotely execute arbitrary code.
🤨 Details of the attack and how the hackers managed to send this payload from a legitimate sender are covered in an article on Habr.
#ti #apt #malware
@ptescalator
More in General
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Ding, ding — who's there?
Ding, ding — who's there? 🔔 The cyber intelligence group of Positive Technologies' expert security center…
- Enterprise-grade validation system with schema support
Enterprise-grade validation system with schema support (c) The author of a dozen trojans who forgot to…
- One less feathered thief — plus one hundred rating points!
One less feathered thief — plus one hundred rating points! 😵 The Threat Intelligence team at…
- DragonDoll: a matryoshka in the world of Android spies
DragonDoll: a matryoshka in the world of Android spies 🪆 At the beginning of this spring,…



