Hackers Target Online Gambling Sites
Threat Actor Targets Gambling and Betting in Southeast Asia Gambling and betting operations in Southeast Asia have been targeted in a campaign active since May 2019, Trend Micro reports. Dubbed DRBControl , the adversary behind the attacks is using a broad range of tools for cyber-espionage purposes, including publicly available and custom utilities that allow it to elevate privileges, move laterally in the compromised environments, and exfiltrate data. The intrusion begins with spear-phishing Microsoft Word files, with three different document versions identified: they embed an executable, a BAT file, and PowerShell code, respectively. Two very similar variations of the employed phishing content were observed. The first two document versions execute the same payload onto the target system, and the third one is believed to be leading to the same piece of malware too. DRBControl employed two previously unknown backdoors in this campaign, but also used known...