DuckPond
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@piefed.world to cybersecurity@infosec.pubEnglish · 2 days ago

SoupDealer Malware Bypasses Every Sandbox, AV's and EDR/XDR in Real-World Incidents

cybersecuritynews.com

external-link
message-square
9
link
fedilink
33
external-link

SoupDealer Malware Bypasses Every Sandbox, AV's and EDR/XDR in Real-World Incidents

cybersecuritynews.com

cm0002@piefed.world to cybersecurity@infosec.pubEnglish · 2 days ago
message-square
9
link
fedilink
SoupDealer Java loader evades all defenses, targeting Windows users in Türkiye via phishing, loading payloads in memory over Tor.
alert-triangle
You must log in or # to comment.
  • frongt@lemmy.zip
    link
    fedilink
    arrow-up
    14
    ·
    2 days ago

    In live incidents, SoupDealer bypassed host‐based antivirus checks by confirming no security products were active before proceeding.

    That’s a pretty narrow victim demographic. Windows has Defender enabled out of the box. I don’t see any investigation on the C2 connection, either, so I’m left wondering who the attacked and intended targets are.

    • Hirom@beehaw.org
      link
      fedilink
      arrow-up
      2
      ·
      2 days ago

      And it downloads Tor to connect to C2. So it’s a machine with Internet access AND without security mesures.

      So it might be a target with poor IT. A windows machine shouldn’t be left without AV, especially if it has Internet access.

  • sad_detective_man@leminal.space
    link
    fedilink
    arrow-up
    5
    ·
    2 days ago

    Why would somebody only target machines in Turkey?

    • H4kii the Posnaniese@floss.social
      link
      fedilink
      arrow-up
      1
      ·
      1 day ago

      @sad_detective_man @cm0002 Turkey is also somehow a border of the NATO - that can also be a key

    • ButtermilkBiscuit@feddit.nl
      link
      fedilink
      arrow-up
      5
      ·
      2 days ago

      Greece has entered the chat

      • sad_detective_man@leminal.space
        link
        fedilink
        arrow-up
        5
        ·
        2 days ago

        oh wait. yeah, look I’m not a smart man

        • lurch (he/him)@sh.itjust.works
          link
          fedilink
          arrow-up
          5
          ·
          2 days ago

          I’m a smart man and I think your question still stands. Why shouldn’t they get along like normal people. (Intentionally no question mark.)

  • salacious_coaster@infosec.pub
    link
    fedilink
    arrow-up
    5
    arrow-down
    1
    ·
    2 days ago

    Yikes 😬

  • SendMePhotos@lemmy.world
    link
    fedilink
    arrow-up
    2
    arrow-down
    1
    ·
    2 days ago

cybersecurity@infosec.pub

cybersecurity@infosec.pub

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !cybersecurity@infosec.pub

An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!

Community Rules

  • Be kind
  • Limit promotional activities
  • Non-cybersecurity posts should be redirected to other communities within infosec.pub.

Enjoy!

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 56 users / day
  • 203 users / week
  • 812 users / month
  • 981 users / 6 months
  • 1 local subscriber
  • 4.8K subscribers
  • 175 Posts
  • 136 Comments
  • Modlog
  • mods:
  • shellsharks@infosec.pub
  • tweedge@infosec.pub
  • BE: 0.19.12
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org