Auteur Sujet: [Trend]Untangling the Patchwork Cyberespionage Group  (Lu 3003 fois)

0 Membres et 1 Invité sur ce sujet

Hors ligne igor51

  • Admin
  • Mega Power Members
  • *****
  • Messages: 10419
[Trend]Untangling the Patchwork Cyberespionage Group
« le: décembre 11, 2017, 14:00:44 »
Untangling the Patchwork Cyberespionage Group

Patchwork (also known as Dropping Elephant) is a cyberespionage group known for targeting diplomatic and government agencies that has since added businesses to their list of targets. Patchwork’s moniker is from its notoriety for rehashing off-the-rack tools and malware for its own campaigns. The attack vectors they use may not be groundbreaking—what with other groups exploiting zero-days or adjusting their tactics—but the group's repertoire of infection vectors and payloads makes them a credible threat.


We trailed Patchwork’s activities over the course of its campaigns in 2017. The diversity of their methods is notable—from the social engineering hooks, attack chains, and backdoors they deployed. They’ve also joined the Dynamic Data Exchange (DDE) and Windows Script Component (SCT) abuse bandwagons and started exploiting recently reported vulnerabilities. These imply they’re at least keeping an eye on other threats and security flaws that they can repurpose for their own ends. Also of note are its attempts to be more cautious and efficient in their operations.


Post from: Trendlabs Security Intelligence Blog - by Trend Micro


Untangling the Patchwork Cyberespionage Group


Source: Untangling the Patchwork Cyberespionage Group

Tags: