Security-X
Forum Security-X => News => Discussion démarrée par: igor51 le août 15, 2017, 20:00:55
-
ShadowPad in corporate networks
In July 2017, during an investigation, suspicious DNS requests were identified in a partner’s network. The source of the queries was a software package produced by NetSarang. Our analysis showed that recent versions of the software had been surreptitiously modified to include an encrypted payload that could be remotely activated by a knowledgeable attacker.
Source: ShadowPad in corporate networks (https://securelist.com/shadowpad-in-corporate-networks/81432/)