216.73.217.22

Like PuTTY in Admin's Hands

· Published 27/08/2025 16:22 · Modified 27/08/2025 19:43

Export JSON

Essential information

Published
27/08/2025 16:22
Modified
27/08/2025 19:43
Tags
2025-08-27 broomstick kerberoasting malvertising oyster putty trojanized
Related entities
16 techniques (mitre), 2 malware

Description

The LevelBlue Managed Detection and Response team handled incidents related to a campaign distributing versions of the terminal emulator. The malicious software, masquerading as legitimate , was downloaded by privileged users and exhibited behaviors such as , suspicious PowerShell execution, and persistence via scheduled tasks. The threat actors used sponsored ads on search engines to deliver the malware, which was signed by various entities and utilized multiple domains for distribution. The campaign highlights the importance of following security best practices across all organizational levels and emphasizes the need for robust verification mechanisms in advertising networks to prevent abuse.

External references