Skip to main content

Kaspersky Warns of Fileless Malware Hidden in Windows Event Logs


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

By Ionut Arghire on May 04, 2022

 

Threat hunters at Kaspersky are publicly documenting a malicious campaign that abuses Windows event logs to store fileless last stage Trojans and keep them hidden in the file system.

In a research report published Wednesday, Kaspersky said the first phase of the campaign started around September 2021, with the threat actor luring victims into downloading a digitally-signed Cobalt Strike module.

The use of event logs for malware stashing is a technique that Kaspersky’s security researchers say they have not seen before in live malware attacks.
 

 

>> Full Article <<

2 replies

Jamesharris85
New Voice
Forum|alt.badge.img+4

Thats a new one on me, interesting read 


kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Popular Voice
  • 512 replies
  • May 5, 2022

Same. And apparently a new one for Kaspersky, too!

The use of event logs for malware stashing is a technique that Kaspersky’s security researchers say they have not seen before in live malware attacks.

 

Hackers are keeping us on our toes!


Reply