Technical analysis of Win32/Syndicasec.A, malware active in Nepal and China as far back as 2010, with a JavaScript payload registered in the Windows WMI subsystem and a system of fake blogs to discover its C&C servers, hosted on Tibet-related domains.
The post Syndicasec in the Sin Bin: targeted espionage malware in action appeared first on We Live Security.