A newly observed malware campaign is using simple Windows scripts to open the door to remote control and data theft. The chain relies on Visual Basic Script, or VBS, and PowerShell, two tools present on business computers, making an infection appear less unusual. Campaign operators use several DuckDNS hosts, a layered malware delivery chain that supplies multiple addresses to deliver or support the attack against potential victims. Once a victim runs the script, the activity can progress from a small launcher to a hidden payload built for 64-bit Windows systems. Since the initial files use familiar Windows features, employees and defenses may treat activity as ordinary unless behavior is checked closely. Threat...
Read the full article at the source.
Comments (0)
No comments yet. Be the first to comment!