Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

New WhiteShadow downloader uses Microsoft SQL to retrieve malware

released on 2019-09-26 @ 09:20:23 PM
Proofpoint researchers encountered new Microsoft Office macros, which collectively act as a staged downloader that we dubbed “WhiteShadow.” Since the first observed occurrence of WhiteShadow in a small campaign leading to infection with an instance of Crimson RAT, we have observed the introduction of detection evasion techniques. These changes include ordering of various lines of code as well as certain basic obfuscation attempts.