CAV3RN is a modular espionage framework that is becoming harder to see on a network. Its newest communication component hides remote-control traffic behind Google Apps Script, a service many organizations use legitimately. That design can make a harmful connection look less unusual at first glance. The framework has been used against targets in Israel and has continued to gain new components. Researchers have not described the initial infection route in this update, but once installed, its modules can exchange messages, collect software details, receive tasks, and update parts of the toolkit without restarting the host. Analysts at Securelist identified the new communication and control functions while tracking the cluster...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!