Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Targets victims’ data and social media accounts

released on 2024-04-04 @ 07:53:01 PM
Cisco Talos discovered a financially motivated threat actor, believed to be of Vietnamese origin, operating since at least 2023. This group, dubbed 'CoralRaider,' targets victims across multiple Asian and Southeast Asian nations, aiming to steal credentials, financial data, and social media accounts, including business and advertisement profiles. The campaign employs RotBot, a customized QuasarRAT variant, and XClient stealer as payloads. The actors utilize the dead drop technique, leveraging legitimate services to host C2 configuration files and Living-off-the-Land binaries, such as Windows Forfiles.exe and FoDHelper.exe.