SANS Internet Storm Center, InfoCON

Malicious Script Delivering More Maliciousness, (Wed, Feb 4th)

Today, I received an interesting email with a malicious attachment. When I had a look at the automatic scan results, it seemed to be a malicious script to create a Chrome Injector to steal data. Because InfoStealers are very common these days, it looked “legit” but there was something different. The .bat file looks to be a fork of the one found in many GitHub repositories[1].
favicon
isc.sans.edu
isc.sans.edu
favicon
bsky.app
Hacker & Security News on Bluesky @hacker.at.thenote.app
Create attached notes ...