TerminalFix: PNG Steganography, (Mon, Sep 21st)

Microsoft Security Research published an interesting blog post “TerminalFix campaign deploys a reverse tunnel through multistage intrusion” about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.

Continue reading TerminalFix: PNG Steganography, (Mon, Sep 21st)→

Posted in Uncategorized

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.

Continue reading LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)→

Posted in Uncategorized