cognitive cybersecurity intelligence

News and Analysis

Search

Russian Shuckworm APT is back with updated GammaSteel malware

Russian Shuckworm APT is back with updated GammaSteel malware

A script collected system information from computers, sending it back to the C2 server. A second script, a GammaSteel variant, exfiltrated files with specific extensions from directories using PowerShell web requests. If unsuccessful, it used cURL command line tool with a Tor proxy. The web service write.as may have been an alternative data exfiltration channel.

Source: www.csoonline.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts