Kryptovalutaticker:
sysadmin från Cyber Security News

CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

Tushar Subhra Dutta
4 hours ago
11 Visningar
0 Kommentarer
CAV3RN Uses Google Apps Script as C2 Relay to Hide Malware Traffic Behind Google Infrastructure

CAV3RN is a modular espionage framework that is becoming harder to see on a network. Its newest communication component hides remote-control traffic behind Google Apps Script, a service many organizations use legitimately. That design can make a harmful connection look less unusual at first glance. The framework has been used against targets in Israel and has continued to gain new components. Researchers have not described the initial infection route in this update, but once installed, its modules can exchange messages, collect software details, receive tasks, and update parts of the toolkit without restarting the host. Analysts at Securelist identified the new communication and control functions while tracking the cluster...

Läs hela artikeln hos källan.

Delta i diskussionen — kommentera, rösta och dela länkar.

Registrera
Var detta hjälpsamt?
Dela:

Kommentarer (0)

Vänligen logga in eller registrera dig för att delta i diskussionen

Inga kommentarer ännu. Bli först med att kommentera!