#Moneyholic

Incident/Operation

2019-08-29 • Operaion Moneyholic

Operation Moneyholic was a financially motivated targeted campaign associated with the threat activity known as Konni and aimed at cryptocurrency exchanges and users. Operators used researched spear-phishing lures, including HWP documents containing embedded EPS code that exploited a Ghostscript vulnerability, to run encrypted shellcode. The infection downloaded scripts and batch files, established startup persistence, collected system information, and allowed operators to deliver additional malware selectively after determining that a host was a desired target.

Tagged Reports

« Back