The Nansh0u Campaign – Hackers Arsenal Grows Stronger
Guardicore researchers detail the Nansh0u campaign's growing arsenal, with three attacks traced to South African IPs hosted by VolumeDrive.
Guardicore security researchers analyzed three attacks detected in early April through the Guardicore Global Sensor Network (GGSN). All three attacks originated from source IP addresses in South Africa hosted by the VolumeDrive ISP. The write-up catalogs the expanding arsenal and tooling used by the Nansh0u campaign attackers and includes indicators of compromise.
- Guardicore detected three Nansh0u attacks sourced from South African IPs hosted by VolumeDrive ISP in early April.
- The write-up catalogs the campaign's expanding arsenal of attack tools and infrastructure.
- Indicators of compromise (IoCs) are provided for defenders.
In the beginning of April, three attacks detected in the Guardicore Global Sensor Network (GGSN) caught our attention. All three had source IP addresses originating in South-Africa and hosted by VolumeDrive ISP (see IoCs).
The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at akamai.com.