GRUzzly Bear :verified: · @1nternaut
239 followers · 107 posts · Server infosec.exchange

RT @Cyber_O51NT@twitter.com

Targets European Government Organizations and Continues to Iterate Custom PlugX Variant recordedfuture.com/reddelta-ta

#reddelta

Last updated 2 years ago

New research from Insikt Group has observed activity attributed to likely Chinese state-sponsored threat activity group using a customized variant of the backdoor (heavily customized for anti-analysis for detection evasion). More in the report: recordedfuture.com/reddelta-ta

#reddelta #plugx

Last updated 2 years ago

avallach · @xorhex
160 followers · 162 posts · Server infosec.exchange

/ have expanded to using ISO files in addition to RAR and ZIP files.

Also, the config decryption key changed to jOh752oCI for their more recent variants of .

go.recordedfuture.com/hubfs/re

#reddelta #MustangPanda #plugx

Last updated 2 years ago

ITSEC News · @itsecbot
687 followers · 32461 posts · Server schleuss.online