#HYDSEVEN
Malware/Tool
2019-06-19 • サイバー救急センターレポート 特別編集号
HYDSEVEN is a threat group that conducted cryptocurrency-theft operations from 2016 through 2019 against targets in several countries, including Japan and Poland. Its intrusions commonly began with spear-phishing that impersonated academics or researchers and used malicious VBA macros, software exploits, or fake installers. The group deployed NetWire and Ekoms/Mokes payloads, sometimes through PowerShell or HTA and VBScript stages, and continued operating through at least early 2019.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days