Threat actors using MacroPack to deploy Brute Ratel, Havoc and PhantomCore payloads
#MacroPack
https://blog.talosintelligence.com/threat-actors-using-macropack/
#MacroPack
https://blog.talosintelligence.com/threat-actors-using-macropack/
Threat actors using MacroPack to deploy Brute Ratel, Havoc and PhantomCore payloads
Cisco Talos recently discovered several related Microsoft Office documents uploaded to VirusTotal by various actors between May and July 2024 that were all generated by a version of a payload generator framework called “MacroPack.”
