Thread Rating:
  • 0 Vote(s) - 0 Average
  • 1
  • 2
  • 3
  • 4
  • 5
Share Post: Reddit Facebook
Cobalt cybercrime gang abused Google App Engine in recent attacks
#1
The Cobalt hacking group has been using Google App Engine to distribute malware through PDF decoy documents. The group targeted more than 20 other government and financial institutions worldwide.
 
Cobalt crime gang is a Russian hacking crew that has been active since at least 2016, it targeted banks worldwide, the group leveraged spear-phishing emails to compromise target systems, spoofed emails from financial institutions or a financial supplier/partner.
 
In August, security experts from Netscout’s ASERT uncovered a campaign carried out by the group that targeted the NS Bank in Russia and Carpatica/Patria in Romania.
 
Recently that hacking crew leveraged URL redirection in PDF decoy documents to deliver malicious payloads to the victims. Threat actors used HTTPS URLs to point to Google App Engine, with this technique attackers attempt to trick the victim into believing they are accessing a resource from Google.
 
Attackers used specially crafted PDF documents created with the Adobe Acrobat 18.0 that contained the malicious URLs in a compressed form.
 
“Most of the PDF’s we observed were created using Adobe Acrobat 18.0. They contained the malicious URL in a compressed form in the PDF stream using Flat Decode (Filter/FlateDecode).” reads the analysis published by Netskope.

For : http://www.cyberdefensemagazine.com/coba...t-attacks/
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Ransomware gang uses new Microsoft Exchange exploit to breach servers tarekma7 0 590 12-21-2022 , 09:00 AM
Last Post: tarekma7
  Digital security giant Entrust breached by ransomware gang mrtrout 0 672 07-23-2022 , 12:02 AM
Last Post: mrtrout
  Cybercrime Group Asking Insiders for Help in Planting Ransomware mrtrout 0 552 08-21-2021 , 10:47 PM
Last Post: mrtrout
  SynAck ransomware gang releases decryption keys for old victims mrtrout 0 627 08-13-2021 , 07:10 AM
Last Post: mrtrout
  Refunds Offered to Victims of Ziggy Ransomware Gang Bjyda 0 841 03-31-2021 , 07:55 PM
Last Post: Bjyda

Forum Jump:


Users browsing this thread: 1 Guest(s)