Malware Devil

Tuesday, November 3, 2020

PoloBear: Malicious C2 server targeting vulnerable CMS

On October 24, 2020, the behavioral analytic DOMAIN_ANALYSIS_TLS alerted on the domain polobear[.]shop across multiple financial and energy environments. This was easily identifiable by using IronNet’s Collective Defense products (IronDefense and IronDome), which allow for easy querying of geographically dispersed events. With this information, IronNet’s cyber operation capability, the CYOC, acted to ensure how and to what extent these other customers were impacted.

The post PoloBear: Malicious C2 server targeting vulnerable CMS appeared first on Security Boulevard.

Read More

The post PoloBear: Malicious C2 server targeting vulnerable CMS appeared first on Malware Devil.



https://malwaredevil.com/2020/11/03/polobear-malicious-c2-server-targeting-vulnerable-cms-5/?utm_source=rss&utm_medium=rss&utm_campaign=polobear-malicious-c2-server-targeting-vulnerable-cms-5

No comments:

Post a Comment

Barbary Pirates and Russian Cybercrime

In 1801, the United States had a small Navy. Thomas Jefferson deployed almost half that Navy—three frigates and a schooner—to the Barbary C...