APT Attacks in Singapore Telecom: UNC3886 ORB Tracking Explained

APT attacks by UNC3886 target Singapore telecom using ORB networks. Learn practical ORB tracking techniques to uncover hidden infrastructure with Scout.

Installation scripts and the #GobRAT and #Bulbature malware can be found on some servers. Other servers provide a view of the administration interface used to manage compromised hosts and launch attacks.

「日本の Linux ルーターを標的とする新しい GobRAT リモート アクセス トロイの木馬 」: The Hacker News

「日本の Linux ルーターを標的とする新しい GobRAT リモート アクセス トロイの木馬 」

https://thehackernews.com/2023/05/new-gobrat-remote-access-trojan.html

https://blogs.jpcert.or.jp/ja/2023/05/gobrat.html

#prattohome #TheHackerNews #マルウェア #GobRAT

New GobRAT Remote Access Trojan Targeting Linux Routers in Japan

Linux routers in Japan are under attack by a sneaky new villain named GobRAT.

The Hacker News
New GobRAT Remote Access Trojan Targeting Linux Routers in Japan

Linux routers in Japan are under attack by a sneaky new villain named GobRAT.

The Hacker News
New Go-written GobRAT RAT targets Linux Routers in Japan

A new Golang remote access trojan (RAT), tracked as GobRAT, is targeting Linux routers in Japan, the JPCERT Coordination Center warns. JPCERT/CC is warning of cyberattacks against Linux routers in Japan that have been infected with a new Golang remote access trojan (RAT) called GobRAT. Threat actors are targeting Linux routers with publicly exposed WEBUI to execute […]

Security Affairs