A new sophisticated stealing campaign named “Steal-It” has been discovered that exfiltrates NTLMv2 hashes using customized versions of Nishang's Start-CaptureServer PowerShell script.
It is believed that the Steal-It campaign may be attributed to APT28 (aka Fancy Bear) based on its similarities with the APT28 cyber attack.
Fancy Bear is a Russian cyber espionage group that uses zero-day exploits, spear phishing, and malware
Read more
Tags: Spear Phishing, Cyber Attack, exploits, Hashes, PowerShell, and, phishing, Cyber espionage, stealing, hacks, NTLMv2, attack, script, Scripts, APT28
Related Posts
- The Top 3 Countries With The Best Cyber Warfare Capabilitiesa
- Summary of the Threat and Vulnerability Roundup for the week of July 30th to August 5tha
- Hackers Use Weaponized PDFs and Chat Apps for C2 to Evade Detectiona
- Hackers Leverage USB Flash Drives to Attack Public and Private Sectors Globallya
- Hackers Attack Facebook Business Users Aggressively to Steal Login Credentialsa