Auteur Sujet: [FireEye]SANNY Malware Delivery Method Updated in Recently Observed Attacks  (Lu 2702 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
SANNY Malware Delivery Method Updated in Recently Observed Attacks

[html]

Introduction


 

In the third week of March 2018, through FireEye’s Dynamic Threat
  Intelligence, FireEye discovered malicious macro-based Microsoft Word
  documents distributing SANNY malware to multiple governments
  worldwide. Each malicious document lure was crafted in regard to
  relevant regional geopolitical issues. FireEye has tracked the SANNY
  malware family since 2012 and believes that it is unique to a group
  focused on Korean Peninsula issues. This group has consistently
  targeted diplomatic entities worldwide, primarily using lure documents
  written in English and Russian.


 

As part of these recently observed attacks, the threat actor has
  made significant changes to their usual malware delivery method. The
  attack is now carried out in multiple stages, with each stage being
  downloaded from the attacker’s server. Command line evasion
  techniques, the capability to infect systems running Windows 10, and
  use of recent User Account Control (UAC) bypass techniques have also
  been added.


 

Document Details


 

The following two documents, detailed below, have been observed in
  the latest round of attacks:


 


  MD5 hash: c538b2b2628bba25d68ad601e00ad150
 SHA256
  hash:

  b0f30741a2449f4d8d5ffe4b029a6d3959775818bf2e85bab7fea29bd5acafa4

    Original Filename:


Tags: