Source |
Checkpoint Research |
Identifiant |
8358787 |
Date de publication |
2023-07-19 11:48:57 (vue: 2023-07-19 12:07:08) |
Titre |
BYOS & # 8211;Regrouper votre propre voleur BYOS – Bundle Your Own Stealer |
Texte |
> Faits saillants: Introduction Au cours des derniers mois, nous avons surveillé un nouveau voleur / bot inconnu, nous avons surnommé & # 160; bundlebot, & # 160; répartir sous le radar et abusant dotnet & # 160; bundle & # 160; (unique), format autonome.Ce format de compilation DOTNET est pris en charge depuis environ quatre ans, de .NET Core 3.0+ à DotNet8 +, et il y a déjà des familles de logiciels malveillants connues qui les abusent (par exemple, & # 160; Ducktail).Le [& # 8230;]
>Highlights: Introduction During the past few months, we have been monitoring a new unknown stealer/bot, we dubbed BundleBot, spreading under the radar and abusing dotnet bundle (single-file), self-contained format. This format of dotnet compilation has been supported for about four years, from .net core 3.0+ to dotnet8+, and there are already some known malware families abusing it (e.g., Ducktail). The […]
|
Notes |
★★
|
Envoyé |
Oui |
Condensat |
ducktail spreading >highlights: about abusing already are been bundle byos compilation contained core dotnet dotnet bundle dotnet8+ dubbed bundlebot during families file format four from has have introduction known malware monitoring months net new own past radar self single some stealer stealer/bot supported under unknown years your |
Tags |
Malware
|
Stories |
|
Move |
|