SEC spoofed, malware hosted on US gov't server in new DNS attack

screen-shot-2017-10-12-at-08-30-38.jpg File Photo

Researchers have discovered a new version of the DNS Messenger attack which masquerades as the US Securities and Exchange Commission (SEC) and hosts malware on compromised government servers.

On Wednesday, security researches from Cisco Talos revealed the results of an investigation into DNS Messenger, a fileless attack which uses DNS queries to push malicious PowerShell commands on compromised computers.

A new version of this attack, which the team say is "highly targeted in nature," now attempts to compromise victim systems by pretending to be the SEC Electronic Data Gathering Analysis, and Retrieval (EDGAR) system -- recently at the heart of a data breach related to financial fraud -- in specially crafted phishing email campaigns.

These spoofed emails made them seem legitimate, but should a victim open them and download a malicious attachment contained within, a "multi-stage infection process" begins.

The malicious attachments used in this campaign are Microsoft Word documents. However, rather than using macros or OLE objects to gain a foothold into a system, the threat actors used a less common method of infection, Dynamic Data Exchange (DDE), to perform code execution and install a remote access Trojan (RAT).

http://www.zdnet.com/article/sec-spoofed-malware-hosted-on-us-govt-...

Views: 168

Comment

You need to be a member of 12160 Social Network to add comments!

Join 12160 Social Network

"Destroying the New World Order"

TOP CONTENT THIS WEEK

THANK YOU FOR SUPPORTING THE SITE!

mobile page

12160.info/m

12160 Administrators

 

Latest Activity

tjdavis posted a video

Jupiter Med Bed System 2026 Overview and Quick Look! #medbed

🔷 Jupiter Med Bed System 2026 Overview & Quick Look 🔷👉 Learn more or order here: - 6-8 week lead time - Special pricinghttps://healthylifetechnology.com/p...
13 hours ago
Doc Vega posted blog posts
yesterday
cheeki kea favorited FREEDOMROX's blog post THE END: 2046
yesterday
cheeki kea commented on Doc Vega's blog post What is Consciousness and Does it Have to be In a Certain Body?
"Um err... is it whatever the brain believes it to be, will manifest. You know what, there really…"
yesterday
Sandy posted a video

The future of ai exposed in new ad 😱 *must see* #palantirtechnologies #ai #conspiracy

Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
yesterday
Doc Vega posted blog posts
Friday
Doc Vega posted a blog post

Who was the Better Drummer Paul McCartney or Ringo?

 In contrast to the earlier interviews with Paul McCartney before the alleged fatal car accident in…See More
Wednesday
FREEDOMROX posted a blog post

THE END: 2046

Hello again my fellow travelers in life.     Today, I will not delve into politics, the economy,…See More
Tuesday
FREEDOMROX commented on FREEDOMROX's blog post Common Sense look at Elon gated Musk rat
"Just to show I am still around... :P"
Tuesday
FREEDOMROX favorited Doc Vega's blog post Why Was The TV Show “The Outer Limits” Such a Threat?
Tuesday
Doc Vega posted a blog post

The Undeclared Ongoing War With China

 Just one day after meeting with President Trump in China. Xi Ji Ping has a meeting with Russian…See More
Monday
Doc Vega's 2 blog posts were featured
May 18
tjdavis posted a photo
May 17
Doc Vega posted a blog post

The US Federal Government Who is Really in Charge? Tulsi Gets Raided?

 Just 24 hours ago the office of Intelligence Director, Tulsi Gabbard was raided by the CIA at…See More
May 15
tjdavis posted photos
May 14
tjdavis posted a blog post
May 13
Doc Vega posted a blog post

The Latest Craze

Their demonic little waysThe news is just a biased arrayThe higher taxes they want you to…See More
May 12
cheeki kea commented on cheeki kea's photo
Thumbnail

A Banished Poet

"An interesting snippet from world poetry day this year to learn of the first poet excited from the…"
May 12
cheeki kea posted a photo
May 12
cheeki kea commented on Sandy's photo
Thumbnail

FB_IMG_1772349325558

"Good Point!  Our Indo European friends in Iran gave the devil a good write down ( and Jesus a…"
May 11

© 2026   Created by truth.   Powered by

Badges  |  Report an Issue  |  Terms of Service

content and site copyright 12160.info 2007-2019 - all rights reserved. unless otherwise noted