Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Red Leaves Implant - overview

released on 2017-04-10 @ 03:38:03 PM
This technical note discusses a relatively undocumented implant used by the APT10 group. This is named “Red Leaves” after strings found in the malware. The sample discussed was found during an incident response engagement in March 2017. The earliest evidence obtained shows it has been in use since at least November 2016.