The financially motivated threat actor known as FIN7 has been seen distributing MSIX installers that ultimately lead to the deployment of NetSupport RAT by using malicious Google advertising that mimic reputable firms.
According to a report released earlier this week by cybersecurity firm eSentire, the threat actors impersonated well-known organizations, such as AnyDesk, WinSCP, BlackRock, Asana, Concur, The Wall Street Journal, Workable, and Google Meet, using malicious websites.
A persistent e-crime outfit that has been operating since 2013, FIN7 (also known as Carbon Spider and Sangria Tempest) first dabbled in attacks aimed at point-of-sale (PoS) devices to steal payment data before refocusing on ransomware campaigns to penetrate large firms.
The threat actor has improved its strategies and malware library over time, utilizing a variety of unique malware families like read more FIN7 Hacker Group Leverages Malicious Google Ads to Deliver NetSupport RAT.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
