Cisco Talos Discovered Indigo-Drop target military and government organizations in South Asia

Monday Cisco Talos discovered a multistage attack used to infect target endpoint with customized Cobalt Strike beacons. The malware campaign use military themed malicious ms office document help Talos to determine that it is used to attack military and government organization in south asia the malware containing the full RAT capabilities.
Talos described its working as "The attack consists of a highly modular dropper executable we're calling "IndigoDrop" dropped to a victim's endpoint using maldocs. IndigoDrop is responsible for obtaining the final payload from a download URL for deployment. The final payloads currently observed by Talos are Cobalt Strike beacons."
Read Full report at Cisco Talos Blog post

No comments:

Critical FFmpeg Vulnerability in Home Assistant: File Theft & Root Access Explained

  Critical Home Assistant FFmpeg Vulnerability Allows File Theft and Root Command Execution A newly disclosed security vulnerability in Home...