216.73.216.6

Unauthorized RDP Connections For Cyberespionage Operations

· Published 26/10/2024 14:24 · Modified 28/10/2024 12:55

Export JSON

Essential information

Published
26/10/2024 14:24
Modified
28/10/2024 12:55
Tags
2024-10-26 bat scripts chromepass credential-theft cyberespionage multi-stage attack persistence powershell rdp uac bypass
Related entities
1 intrusion sets (apt), 11 techniques (mitre), 1 malware, 1 others

Description

Cyble Research and Intelligence Labs uncovered an ongoing cyberattack campaign utilizing malicious LNK files to gain unauthorized Remote Desktop access on compromised systems. The sophisticated chain employs and to evade detection, create administrative accounts, and alter Remote Desktop settings. The campaign, named 'HeptaX', has been active since 2023, targeting various sectors with consistent techniques. It involves the deployment of , a tool for stealing saved passwords from Chromium-based browsers. The attack begins with a ZIP file containing a malicious shortcut, likely distributed via phishing emails, and progresses through multiple stages of payload downloads and executions, ultimately enabling the threat actors to establish remote access for further malicious activities.

External references