Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Medium
A campaign they targeting Brazilian banking customers. The threat-actors were using script interpreters (think wscript.exe and powershell.exe) to execute scripts that pulled the previously-stored malware from multiple directory locations to inject into DLLs. By executing from digitally signed code, such as the DLLs targeted, the requests the malware makes are less suspicious. Some anti-virus software may even ignore the code’s activity since it was a digitally signed and therefore seen as a trusted application. DLLs from Avira, AVG, Avast, Damon Tools, Steam, and NVIDIA were the more frequent vendors used in this campaign. The infection begins with an MSI installer that contains both legitimate and malicious files. After installing, the legitimate binary is run, which loads the malicious DLL.