cognitive cybersecurity intelligence

News and Analysis


Polyglot files used to spread new backdoor

Proofpoint has said that a recent phishing message used a “business-to-business sales lure” to exploit the relationship between a sender and targets. The message contained false URLs seeming to belong to INDIC Electronics, but actually linked to a bogus “” archive, including an Excel spreadsheet and two PDFs. These turned out to be a LNK file and two polyglots, which ultimately led to the Sosano backdoor hidden in the zip file.

Source: –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts