Read all Blogs from this Author
On 29th March 2023, reports emerged of malicious activities originating from a signed 3CX desktop application. Trojanized versions of the 3CX desktop app load a DLL with malicious content. The DLL launches a multi-staged attack on the victim machine, the final stage being the deployment of an unidentified info stealer.
In the latest threat actor attack against VMware ESXi servers, a custom ESXiArgs ransomware script is used to exploit the old RCE vulnerability (CVE-2021-21974). Here is a technical analysis of the files used in the ransomware attack.
Read all Whitepapers and reports from this Author
Read all knowledge base articles from this Author