#AGAMEMNON

Malware/Tool

2024-06-12 • Insights on Cyber Threats Targeting Users and Enterprises in Brazil

It was delivered through malicious links to DOCX job-offer lures sent by email, with likely additional delivery through social media and WhatsApp, in campaigns consistent with Operation Dream Job. Another observed variant received commands and payloads from a command-and-control server, parsed command parameters using double-semicolon delimiters, and executed additional payloads. Its supported execution methods included reflective loading and use of the open-source Tartarus-TpAllocInject technique. The cited activity affected targets in Brazil and South Korean organizations.

Tagged Reports

« Back