382. Handala Hack Abuses NetBird
Hello everyone!
Today we'll look at another interesting example of the following technique: Remote Access Tools (T1219).
Scrolling the report on Handala Hack modus operandi, I've spotted an interesting tool abused by the threat actors. I'm talking about NetBird.
The attackers leveraged it to reach hosts that were not directly accessible from outside the network. The tool has no detections on VirusTotal, and may be a good target for hunting, for example:
event_type: "processcreatewin"
AND
proc_file_productname: "netbird"
See you soon!

Comments
Post a Comment