45
Search: “Obfuscated PowerShell script”
632 stories
57
30
35
57
42
42
30
42
42
47
42
47
42
42
57
42
42
30
42
42
Cortex XDR™ Detects New Phishing Campaign Installing NetSupport Manager RAT
Cortex XDR threat hunters uncovered a phishing campaign delivering the NetSupport Manager RAT via a fake password-protected NortonLifelock Word document.
Unit 42 identified a January 2020 phishing campaign using a Microsoft Word document disguised as a password-protected NortonLifelock file. Enabling macros triggered an obfuscated command that built alpaca.bat in the temp directory, which used msiexec to download an MSI payload from quickwaysignstx.com, filtered on the Windows Installer user-agent string. The payload installed a PowerShell script and the campaign, which has delivered NetSupport Manager RAT since at least 2018, showed related activity dating back to early November 2019.
42
30
30
47
30
42
30
45
45
APT32, a new APT group alleged linked to the Vietnamese Government is targeting foreign corporations
57
30
30
30
60
30
57
57
42
57