EastWind Attack Deploys PlugY and GrewApacha Backdoors Using Booby-Trapped LNK Files
As part of a spear-phishing campaign codenamed EastWind, a new campaign aims to deliver multiple backdoors and trojans to the Russian government and IT organizations.
The attack chains are distinguished by the use of RAR archive attachments that contain a Windows shortcut (LNK) file. Opening the LNK file initiates the infection sequence, which leads to the deployment of malware like GrewApacha, an upgraded CloudSorcerer backdoor, and an implant called PlugY that was previously unreported.
According to Russian cybersecurity firm Kaspersky, PlugY is downloaded through the CloudSorcerer backdoor, has an extensive set of commands, and supports three different protocols for communicating with the command-and-control server read more about EastWind Attack Deploys PlugY and GrewApacha Back...

