216.73.216.226

Analysis report on recent phishing attacks by APT-C-48 (CNC)

· Published 03/12/2024 16:30 · Modified 03/12/2024 16:51

Export JSON

Essential information

Published
03/12/2024 16:30
Modified
03/12/2024 16:51
Tags
2024-12-03 anti-debugging anti-vm apt-c-48 spear-phishing
Related entities
5 observables, 1 intrusion sets (apt), 15 techniques (mitre), 5 others

Description

(CNC), a South Asian government-backed APT group, has been targeting government, military, education, research, healthcare, and media sectors. They use emails with resume-related topics to deliver malicious payloads. The group modifies executable file icons to resemble PDF files and adds spaces to filenames to hide extensions. Upon execution, the malware downloads a decoy document and additional attack components. The sample employs and techniques, self-deletion mechanisms, and establishes persistence through scheduled tasks. The attack pattern and tactics are consistent with previous activities, particularly their focus on the education and research sectors.

External references