← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Threat Actor TA505 Targets Financial Enterprises Using LOLBINS and a new backdoor malware
In this research, Cybereason introduce a meticulously planned, malicious operation against a financial institution in April of 2019. This advanced operation combines a targeted phishing attack with advanced tools that gather intel on the environment. The operation chooses whether or not to create persistence and installs a sophisticated backdoor called ServHelper used to take over the network.
Indicators of Compromise (2 / 9 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| URL | http://aasdkkkdsa3442.icu/ | — | 2019-04-25 | |
| URL | http://aasdkkkdsa3442.icu/jquery/jquery.php | — | 2019-04-25 |