Tracking Subaat: Targeted Phishing Attack Leads to Threat Actor’s Repository
By Unit 42, Palo Alto Networks
Added
In mid-July, Palo Alto Networks Unit 42 identified a small targeted phishing campaign aimed at a government organization. While tracking the activities of this campaign, we identified a repository of additional malware, including a web server that was used to host the payloads used for both this attack as well as others. We’ll discuss how we discovered it, as well as possible attribution towards the individual behind these attacks.
Tags
Malware Web application Threat actor Phishing Attack campaign C2 3rd party services Integrity Social engineering Injection attack-Topic Map
