Skip to main content

Russian Army Exhibition Decoy Leads to New BISKVIT Malware


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
By Jasper Manuel and Rommel Joven | August 20, 2018 A few days ago, the FortiGuard Labs team found a malicious PPSX file exploiting CVE-2017-0199 that had been crafted for Russian speakers. The filename “????????” when translated means “Exhibition”. On further examination, the PPSX file seems to have been targeted at an exhibition being held annually in Russia called Army 2018 International Military and Technical Forum. This is one of the largest exhibitions of military weapons and special equipment, not only in Russia, but also one of the outstanding events among similar exhibitions in the world. The discovery of this malicious document is very timely since the event is scheduled to be held August 21-26, 2018. 

Figure 03. Overview of attack Full Article.

0 replies

Be the first to reply!

Reply