216.73.216.226

Attack On Maritime & Defense Manufacturing

· Published 15/11/2024 18:35 · Modified 18/11/2024 21:03

Export JSON

Essential information

Published
15/11/2024 18:35
Modified
18/11/2024 21:03
Tags
2024-11-15 apt defense encryption lnk file manufacturing maritime pakistan persistence powershell stager
Related entities
1 intrusion sets (apt), 10 techniques (mitre), 3 others

Description

The DONOT group has launched a campaign targeting 's industry supporting and sectors. The attack uses a malicious disguised as an RTF, which executes commands to deliver a lure document and malware. The malware establishes through scheduled tasks, communicates with command and control servers using encrypted methods, and can download additional payloads. The campaign shows evolution in tactics, including improved and payload delivery methods. The attackers collect detailed system information from victims and can self-delete if instructed. This operation demonstrates the increasing sophistication of campaigns and the need for enhanced cybersecurity measures.

External references