216.73.217.22

Private HTS Program Continuously Used in Attacks

· Published 17/07/2024 14:19 · Modified 17/07/2024 14:35

Export JSON

Essential information

Published
17/07/2024 14:19
Modified
17/07/2024 14:35
Tags
2024-07-17 quasar rat south korea
Related entities
1 observables, 10 techniques (mitre), 1 malware, 2 others

Description

This report outlines a continuous campaign where a threat actor distributes malware, including , through a private home trading system (HTS) named HPlus. The malware is initially delivered via an MSI installer, and users who request remote assistance inadvertently execute the AnyDesk software. The updater program connects to an FTP server controlled by the attacker to retrieve a compressed file containing additional malware components. While users may lose investments through the scam, the threat actor can now gain control of infected systems and steal data. The report emphasizes the importance of using official HTS from reputable institutions and keeping software up-to-date.

External references