Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

New Python based payload MechaFlounder used by Chafer

released on 2019-03-04 @ 04:34:01 PM
Unit 42 has observed Chafer activity since 2016, however, Chafer has been active since at least 2015. This new secondary payload is Python-based and compiled into executable form using the PyInstaller utility. This is the first instance where Unit 42 has identified a Python-based payload used by these operators. Unit 42 has also identified code overlap with OilRig’s Clayside VBScript but at this time track Chafer and OilRig as separate threat groups. Unit 42 has named this payload MechaFlounder for tracking purposes and discuss details below.