Estimated reading time: 8 minutes
Recently, Seqrite Lab saw a phishing campaign delivering formbook stealers through email attachments. Formbook, as seen since 2016, has evolved in many ways from stealth features to evasion techniques. Being sold on hacking forums as Malware as a Service,...Search Results
Estimated reading time: 5 minutes
Introduction: Attackers are continuously developing different techniques to infect systems and steal sensitive information. A recent campaign a multi-stage infection chain that starts with a LNK file, which lures the victim into opening an invoice in a web browser....Estimated reading time: 7 minutes
Malware can hide inside legitimate-looking files, exploit vulnerabilities, execute malicious scripts, or remain dormant until specific conditions are met. For security teams, identifying a suspicious file is only the beginning. They also need to understand what it does, how...Estimated reading time: 11 minutes
Executive Summary MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model. In the attack chain, MacSync binaries are native stagers and multi-part exfiltration engines....Estimated reading time: 9 minutes
Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Campaign Timeline Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – LNK-Based Initial Access Stage 2 – Split Payload Reconstruction via ftp Script Stage 3 –...
Estimated reading time: 11 minutes
Contents Introduction Campaign Overview Initial Access Infection Chain Technical Analysis Stage 1: Initial Delivery (Archive→JavaScript) Stage 2: PowerShell Loader1 Analysis Stage 3: PowerShell Loader2 Analysis Stage 4 – Phantom Stealer v3.5.0: Data Harvesting and Exfiltration Campaign Attribution Conclusion IOC’s...
Estimated reading time: 8 minutes
Introduction Seqrite Labs recently identified a malware distribution campaign that abused the credibility of government institutions to increase infection success rates. The threat actors impersonated legitimate government departments and distributed malicious emails disguised as official notifications related to taxation,...
Estimated reading time: 11 minutes
Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 – Initial Infection through LNK file Stage 2 – PowerShell Downloader Analysis Stage 3 – The .NET Dropper...
Estimated reading time: 7 minutes
Table of Contents Introduction Infection Chain Technical Analysis Conclusion Seqrite Coverage Indicators of Compromise (IOCs) MITRE ATT&CK Mapping Introduction The Seqrite Threat Research Team identified a targeted spear-phishing campaign disguised as a legitimate business invoice. The phishing email impersonates a legitimate...