New window in dark mode

More in Phishing & sandbox
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…
- PT ESC cyber intelligence group presented an overview of cyberattacks for Q2 2026 ✍️
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q2 2026 ✍️ The report…
- Citizen, update yourself 🫵
Citizen, update yourself 🫵 Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing…
- NetMedved: summer campaign against Russian organizations
NetMedved: Summer Campaign Against Russian Organizations 🐻👍 The PT ESC cyber intelligence group has recorded a…
- AI-95 with a malicious additive ⛽️
AI-95 with a malicious additive ⛽️ In mid-June, the Threat Intelligence team discovered several resources at…
A New Window in Dark Mode 🫣
During the monitoring of new network threats in the network expertise department, suspicious traffic was noticed that was generated by the file INTIMACAO_2025_006647.exe. It was masquerading as a PDF, and translated from Portuguese it meant “Court Summons” (screenshot 1).
After execution on the host, a decoy document opened and network interaction with the Google API was initiated, and outwardly it resembled legitimate requests rather than typical C2 exchange. This story intrigued us, so we decided to dig deeper into the analysis of the sample and understand what exactly it does and what role the unexpected network requests to Google play in this scheme 🔍
Let’s move straight to behavioral analysis. After execution, several PowerShell scripts were dropped into the /Temp directory: Clean_policies, Get_token, and Apply_cbcm. The purpose of the first was to prepare the infected machine — cleaning the registry of existing local policies and settings of various Chromium browsers, as well as restarting browser processes to promptly apply the changes made (screenshot 2). After that, Get_token.ps1 contacted a remote server and pulled a certain token from there (screenshot 3). Finally, the third script, Apply_cbcm (screenshot 4), wrote the obtained token into Chrome policies at the system registry level.
🙆 After a closer look at the parameter names, everything became quite clear: the malware set CloudManagementEnrollmentToken and enabled CloudPolicyOverridesPlatformPolicy, that is, it explicitly switched the browser to prioritize cloud policies. Such a set of names practically stated outright the use of Chrome Browser Cloud Management (judging by the Google Cloud blog, this mechanism was supposed to fight evil, not join it) and that the main goal here was to bind the browser to a remote management console created by the attackers.
It was precisely the consequences of these scripts’ work that we first saw in the network dump (screenshot 5). First, a regular GET request to the C2 servidorunico.com returned that very enrollment token. Then, after the value was written into the registry, the browser automatically raised the next stage of the chain — it itself initiated registration in Google’s infrastructure and sent a POST to the API endpoint with the parameter request=register_browser. The key marker in this request was in the Authorization header, where the token was passed as GoogleEnrollmentToken, and it was this that turned the outwardly legitimate traffic to Google into an indicator of the browser being bound to remote cloud management.
🌐 This tactic gives the attacker a persistent lever of control over the browser. As soon as the user “takes the bait,” the attacker gains the ability to centrally deploy malicious policies and extensions or configure a proxy to intercept traffic. The most unpleasant part is that some of the activity looks like legitimate administration, so without context such a compromise is quite easy to miss.
Stay tuned and happy hunting!
IoCs:
SHA256: 4442e1b545f0a571af113b0cc7455ecba1a603c81bbf84a52b9e61d332f97233
C2: servidorunico.com




#network #C2 #phishing #AVLab
@ptescalator
More in Phishing & sandbox
- ⚡Fake news — THAT'S ALL
⚡Fake news — B U L L S H I T PT ESC specialists discovered an…
- PT ESC cyber intelligence group presented an overview of cyberattacks for Q2 2026 ✍️
PT ESC Cyber Intelligence Group presented an overview of cyberattacks for Q2 2026 ✍️ The report…
- Citizen, update yourself 🫵
Citizen, update yourself 🫵 Recently, a sample mir-pay.apk flew into our sandbox. At first glance, nothing…
- NetMedved: summer campaign against Russian organizations
NetMedved: Summer Campaign Against Russian Organizations 🐻👍 The PT ESC cyber intelligence group has recorded a…
- AI-95 with a malicious additive ⛽️
AI-95 with a malicious additive ⛽️ In mid-June, the Threat Intelligence team discovered several resources at…







