382. Handala Hack Abuses NetBird

Hello everyone!

Today we'll look at another interesting example of the following technique: Remote Access Tools (T1219).

Scrolling the report on Handala Hack modus operandi, I've spotted an interesting tool abused by the threat actors. I'm talking about NetBird

The attackers leveraged it to reach hosts that were not directly accessible from outside the network. The tool has no detections on VirusTotal, and may be a good target for hunting, for example:

event_type: "processcreatewin"

AND

proc_file_productname: "netbird"

See you soon!

Comments

Popular posts from this blog

343. Ransomware Gangs Abuse SystemSettingsAdminFlows to Evade Defenses

391. Hunting for TeamPCP's Stealer

082. Huniting for Malicious Browser Extensions