Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

EVASIVE MANEUVERS BY THE WEKBY GROUP

released on 2015-07-09 @ 12:15:33 AM
ThreatStream Labs recently became aware of a campaign beginning on 30 June 2015 by the omniprescent Wekby threat actors (a/k/a TG-0416, APT-18, Dynamite Panda). The Wekby actors have recently been observed compromising organizations in the Manufacturing, Technology and Utilities verticals, but have had a long standing interest in the HealthCare industry. This campaign uses obfuscated variants of the HTTPBrowser tool that use DNS as a control channel.