Blind Eagle Uses Proton66 Hosting for Phishing, RAT Deployment on Colombian Banks

The use of the Russian bulletproof hosting service Proton66 has been strongly linked to the threat actor known as Blind Eagle.

In a report released last week, Trustwave SpiderLabs claimed that by diverging from digital assets associated with Proton66, it was able to establish this connection and uncover an active threat cluster that uses Visual Basic Script (VBS) files as its initial attack vector and installs commercially available remote access trojans (RATS).

A lot of threat actors use bulletpro.Even though Visual Basic Script (VBS) may seem antiquated, hosting companies like Proton66 continue to use it because they willfully disregard abuse reports and requests for legal takedowns. This facilitates the uninterrupted operation of malware delivery systems, command-and-control servers, and phishing websites by attackers read more about Blind Eagle Uses Proton66 Hosting for Phishing RAT Deployment on Colombian Banks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *