Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Netbounce Threat Actor Tries to Get Added to Whitelists to Evade Detection

released on 2021-03-12 @ 04:38:39 PM
On the 12th of February, FortiGuard Labs received a request via email from a person representing a company called Packity Networks asking to whitelist their software. The sender claimed it to be a false-positive that inflicts a significant impact on their business. Fortinet's investigation led to the discovery of a new group Fortinet has labeled "Netbounce" and it also exposed their malware delivery infrastructure. What made this stand out among others is their unique set of tools and techniques. Fortinet was able to find several variants developed in-house by this group, each serving a different purpose. This blog post, presents the measures taken by the Netbounce group to make the campaign look as legitimate as possible, and the actions FortiGuard Labs took to discover the real intentions of this threat actor.