Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le septembre 06, 2017, 02:00:35

Titre: [Trend]A360 Drive Abused to Deliver Adwind, Remcos, Netwire RATs
Posté par: igor51 le septembre 06, 2017, 02:00:35
A360 Drive Abused to Deliver Adwind, Remcos, Netwire RATs

Cloud-based storage platforms have a history of cybercriminal abuse, from hosting malicious files and directly delivering malware to even making them part of a command-and-control (C&C) infrastructure. GitHub was misused this way when the Winnti group used it as a conduit for its C&C communications.


We saw a similar—albeit a lot simpler and less creative—attack on Autodesk® A360, comparable to the way file-sharing sites are being used to host malware. Abusing A360 as a malware delivery platform can enable attacks that are less likely to raise red flags. It resembled the way Google Drive was misused as a repository of stolen data, for instance.


The payloads we saw during our research—remote access tools (RATs)—are also notable. We found that after they were downloaded and executed, the RATs/backdoors would phone back to their respective command-and-control servers, which are resolvable via free DNS services. It’s not a novel technique, but our correlation of the indicators of compromise (IoCs) suggests that a potentially sustained, cybercriminal operation took advantage of this platform.


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


A360 Drive Abused to Deliver Adwind, Remcos, Netwire RATs


Source: A360 Drive Abused to Deliver Adwind, Remcos, Netwire RATs (http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/H8pD0WREXG0/)