Mmastodon TechnologyCybersecurity first seen 7 h ago, last 7 h ago, peak #2
Attackers use fileless malware delivered via small MSI package
Original: The attack isn't rocket science but from an attacker perspective quite neat. The MSI is quite small and contains, appart
Security researchers are discussing a malware attack delivered through a small Windows installer package that contains little obviously suspicious code beyond attacker hostnames. The payload uses a randomly generated readme file to evade signature-based detection, then retrieves its code and executes it directly in memory, leaving minimal traces on disk. Observers describe the technique as technically simple but elegantly effective from an attacker's point of view.
Why now: Cybersecurity commentators find the fileless execution and anti-detection techniques noteworthy for their simplicity and effectiveness
MSI installer malwareinfosec community
Evidence
- The attack isn't rocket science but from an attacker perspective quite neat. The MSI is quite small and contains, appart from the hostnames little "suspicious" code. The random readme prevents signature based detection. As the code is retrieved and directly executed in memory,… · realn2s@infosec.exchange · 2
API: https://socialmediatrends-api.osmike.com/v1/trends/349413