Source |
The Hacker News |
Identifiant |
8340811 |
Date de publication |
2023-05-31 14:00:00 (vue: 2023-05-31 09:06:54) |
Titre |
Rat RomCom Utilisation du Web Deceptive of Rogue Software Sites pour des attaques secrètes RomCom RAT Using Deceptive Web of Rogue Software Sites for Covert Attacks |
Texte |
Les acteurs de la menace derrière RomCom Rat tirent parti d'un réseau de faux sites Web annonçant des versions voyous de logiciels populaires au moins depuis juillet 2022 pour infiltrer des cibles.
La société de cybersécurité Trend Micro suit le cluster d'activités sous le nom du vide Rabisu, également connu sous le nom de Scorpius tropical (unité 42) et UNC2596 (Mandiant).
"Ces sites de leurre sont probablement destinés uniquement à un petit
The threat actors behind RomCom RAT are leveraging a network of fake websites advertising rogue versions of popular software at least since July 2022 to infiltrate targets.
Cybersecurity firm Trend Micro is tracking the activity cluster under the name Void Rabisu, which is also known as Tropical Scorpius (Unit 42) and UNC2596 (Mandiant).
"These lure sites are most likely only meant for a small |
Notes |
★★
|
Envoyé |
Oui |
Condensat |
2022 activity actors advertising also are attacks behind romcom cluster covert cybersecurity deceptive fake firm infiltrate july known least leveraging likely lure mandiant meant micro most name network only popular rabisu rat rat are rogue romcom scorpius since sites small software targets these threat tracking trend tropical unc2596 under unit using versions void web websites which |
Tags |
Threat
Prediction
|
Stories |
|
Move |
|