#Moneyholic
Incident/Operation
2019-08-29 • Operaion Moneyholic
Operation Moneyholic was a financially motivated targeted campaign associated with the threat activity known as Konni and aimed at cryptocurrency exchanges and users. Operators used researched spear-phishing lures, including HWP documents containing embedded EPS code that exploited a Ghostscript vulnerability, to run encrypted shellcode. The infection downloaded scripts and batch files, established startup persistence, collected system information, and allowed operators to deliver additional malware selectively after determining that a host was a desired target.
-
2
Tagged Reports
-
1
Unique Authors
-
22
Active Days