Rewterz Threat Alert – Titanium Malware: the Platinum group strikes again
November 11, 2019Rewterz Threat Alert – Scammers Abusing a New Firefox Browser Lock Bug
November 12, 2019Rewterz Threat Alert – Titanium Malware: the Platinum group strikes again
November 11, 2019Rewterz Threat Alert – Scammers Abusing a New Firefox Browser Lock Bug
November 12, 2019Severity
High
Analysis Summary
Adwind is a remote access Trojan known to evade detection upon entry and to communicate with a command-and-control server once connected. The Trojan can steal sensitive information, such as credentials, as well as spy through a user’s webcam and log a user’s keystoke activity. The new addition to the modified remote access Trojan uses multi-layer obfuscation by containing various file extensions to avoid detection, with iDefense suspecting it to be tailored specifically to this industry. The malware originated from compromised Westnet accounts.
Impact
- Information Theft
- Credential Theft
- Unauthorized Access
Indicators of Compromise
Hostname
members[.]westnet[.]com[.]au
Source IP
185[.]205.210[.]48
URL
hxxp[:]//members[.]westnet.com[.]au/~
Remediation
- Block the threat indicators at their respective controls.
- Do not download files/software from random sources on the internet.