216.73.216.6

Threat Actor Targets Manufacturing Industry With Malware

· Published 05/12/2024 17:33 · Modified 06/12/2024 16:25

Export JSON

Essential information

Published
05/12/2024 17:33
Modified
06/12/2024 16:25
Tags
2024-12-05 amadey bot amp url code injection dll sideloading lnk file lumma stealer manufacturing powershell process injection
Related entities
11 techniques (mitre), 2 malware, 1 others

Description

A sophisticated cyberattack campaign targeting the industry has been identified, utilizing a deceptive disguised as a PDF document. The attack leverages multiple Living-off-the-Land Binaries and Google Accelerated Mobile Pages to evade detection. The threat actor employs various techniques, including and , to deploy and . These malware strains enable the attacker to gain control and exfiltrate sensitive information from victim machines. The campaign's infection chain involves multiple stages of and uses legitimate system tools to execute malicious commands. The attackers demonstrate adaptability by using URL shortening and AMP URLs to bypass traditional security mechanisms.

External references