Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le novembre 20, 2017, 14:00:11

Titre: [Trend]Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks
Posté par: igor51 le novembre 20, 2017, 14:00:11
Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks

The waves of backdoor-laden spam emails we observed during June and July that targeted Russian-speaking businesses were part of bigger campaigns. The culprit appears to be the Cobalt group, based on the techniques used. In their recent campaigns, Cobalt used two different infection chains, with social engineering hooks that were designed to invoke a sense of urgency in its recipients—the bank’s employees.


Of note were Cobalt’s other targets. Their first spam run also targeted a Slovenian bank, while the second run targeted financial organizations in Azerbaijan, Belarus, and Spain.


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks


Source: Cobalt Strikes Again: Spam Runs Use Macros and CVE-2017-8759 Exploit Against Russian Banks (http://feeds.trendmicro.com/~r/Anti-MalwareBlog/~3/Xw1UeY8MtJ8/)