TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Dridex Update: Moving to US Financials with VNC

2016-04-26 · Read original ↗

ATT&CK techniques detected

2 predictions
T1021.005VNC
73%
“and the appropriate function is called. static code analysis of a “ vncstartserver ” call : runtime debugging view : once the vnc server is started, the fraudster is able to remotely connect and use the victim ’ s machine. tested md5 : f6a9835201d5cae894863a46bbf12d69”
T1185Browser Session Hijacking
32%
“dridex update : moving to us financials with vnc the dridex target list was significantly expanded ( 129 redirect and injection directives ), mainly focusing on u. s. financial institutes, form - grabbing targets on social media sites ( which are also related to the united states…”

Summary

Ongoing campaign analysis has revealed that Dridex malware's latest focus has strongly shifted in recent months to US banks.