Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

The Gh0st Remains the Same

released on 2020-06-09 @ 07:40:49 PM
Prevailion's Tailored Intelligence Team has detected a new advanced campaign dubbed - “The Gh0st Remains the Same.” This first campaign likely commenced between May 11th and 12th, 2020. In this engagement, the victims received a compressed RAR folder that contained trojanized files. If the malicious files were engaged, they displayed decoy web pages associated with the software company "Zeplin". Zeplin is a software company that developed a platform to create a “connected space for product teams,'' and boasts over three million customers. Some of Zeplin's more prominent users include: Starbucks, Airbnb, Slack, Dropbox, Pinterest, Shopify, Feedly and MailChimp. It is likely they chose to simulate collaboration-based software with a sizable user base, as a result of the increase in working from home (WFH) during the global pandemic.