Ransomware can turn one careless click into a business-wide emergency. An incident at QNET shows how quickly that risk can grow when attackers use trusted Windows tools to launch a second stage of an intrusion. The attack began after a user opened a malicious file, likely delivered through email or a browser download. It launched mshta.exe, a legitimate Windows utility, which contacted attacker-controlled infrastructure to collect a remote payload and prepare persistent activity. Microsoft analysts noted that the operation used a living-off-the-land method, meaning it relied on a built-in tool rather than an obvious malware program. That approach can blend into normal system activity and give attackers time to steal...
Læs hele artiklen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!