cognitive cybersecurity intelligence

News and Analysis

Search

Multi-Vector Malware Exploiting Outlook API, DNS & ICMP Tunneling for C2

The newly identified malware “Squidoor,” suspected to be created by a Chinese threat actor, is a sophisticated tool targeting sectors such as government, defence, telecommunications, education, and aviation in Southeast Asia and South America. It uses advanced communication methods including API Outlook and DNS tunneling to infiltrate networks, maintain persistence, and extract sensitive data. Squidoor also uses Living-Off-the-Land Binary-and-Script (LOLBAS) techniques and blends malicious traffic with legitimate network activity to avoid detection.

Source: gbhackers.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts