New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure
Afghan telecom providers and South Asian critical infrastructure organizations are the targets of a new campaign delivering a previously undocumented backdoor called…
Afghan telecom providers and South Asian critical infrastructure organizations are the targets of a new campaign delivering a previously undocumented backdoor called…
SHEETCORD is a Go-based backdoor that uses Google Sheets API for command-and-control. It is delivered via a fake NIC website and combines…
Google Sheets is abused by SHEETCORD for command-and-control communications, allowing the threat actor to issue commands and exfiltrate data via a legitimate…
Vivaldi is among the browsers targeted by SHEETCORD's browser shortcut hijacking persistence mechanism.
Brave is among the browsers targeted by SHEETCORD's browser shortcut hijacking persistence mechanism.
Opera is among the browsers targeted by SHEETCORD's browser shortcut hijacking persistence mechanism.
SHEETCORD uses PowerShell to execute remote commands on infected systems, providing the threat actor with a powerful scripting interface.
SHEETCORD uses a Visual Basic Script in the Windows Startup folder to establish persistence on infected systems.