Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement
Credit to Author: Joseph C Chen| Date: Mon, 18 Sep 2023 00:00:00 +0000
While monitoring Earth Lusca, we discovered an intriguing, encrypted file on the threat actor’s server — a Linux-based malware, which appears to originate from the open-source Windows backdoor Trochilus, which we’ve dubbed SprySOCKS due to its swift behavior and SOCKS implementation.
Read more