Kryptovaluta-ticker:
sysadmin fra Cyber Security News

CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

Tushar Subhra Dutta
4 hours ago
8 Visninger
0 Kommentarer
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

CAV3RN is a modular espionage framework that is becoming harder to see on a network. Its newest communication component hides remote-control traffic behind Google Apps Script, a service many organizations use legitimately. That design can make a harmful connection look less unusual at first glance. The framework has been used against targets in Israel and has continued to gain new components. Researchers have not described the initial infection route in this update, but once installed, its modules can exchange messages, collect software details, receive tasks, and update parts of the toolkit without restarting the host. Analysts at Securelist identified the new communication and control functions while tracking the cluster...

Læs hele artiklen hos kilden.

Deltag i diskussionen — kommenter, stem og del links.

Registrer
Var dette nyttigt?
Del:

Kommentarer (0)

Log venligst ind eller opret dig for at deltage i diskussionen

Ingen kommentarer ennå. Bli den første til å kommentere!