382. Handala Hack Abuses NetBird

Hello everyone!

Today we'll look at another interesting example of the following technique: Remote Access Tools (T1219).

Scrolling the report on Handala Hack modus operandi, I've spotted an interesting tool abused by the threat actors. I'm talking about NetBird

The attackers leveraged it to reach hosts that were not directly accessible from outside the network. The tool has no detections on VirusTotal, and may be a good target for hunting, for example:

event_type: "processcreatewin"

AND

proc_file_productname: "netbird"

See you soon!

Comments

Popular posts from this blog

082. Huniting for Malicious Browser Extensions

033. Free Google Threat Intelligence Course

163. A Curious Case of Iediagcmd.exe Abuse