Security-X

Forum Security-X => News => Discussion démarrée par: igor51 le septembre 10, 2018, 12:00:55

Titre: [SecList]LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company
Posté par: igor51 le septembre 10, 2018, 12:00:55
LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company

Since March 2018 we have discovered several infections where a previously unknown Trojan was injected into the lsass.exe system process memory. This campaign was active immediately prior to Central Asian high-level meeting and we suppose that actor behind still follows regional political agenda.
Source: LuckyMouse signs malicious NDISProxy driver with certificate of Chinese IT company (https://securelist.com/luckymouse-ndisproxy-driver/87914/)