216.73.217.22

APT Attacks Using Cloud Storage

· Published 11/06/2024 10:09 · Modified 11/06/2024 10:31

Export JSON

Essential information

Published
11/06/2024 10:09
Modified
11/06/2024 10:31
Tags
2024-06-11 apt cloud dropbox powershell xenorat
Related entities
1 observables, 11 techniques (mitre), 1 malware

Description

The report describes a malicious campaign where threat actors utilize services like Google Drive, OneDrive, and to distribute malware and collect user information. The attack process starts with a malicious shortcut file (LNK) that executes scripts to download decoy documents and additional malware from the attacker's storage. The scripts collect system information, which is uploaded to the , and then download and execute the remote access trojan. The malware allows the threat actor to perform various malicious activities on the compromised system.

External references