EastWind Attack Deploys PlugY and GrewApacha Backdoors Using Booby-Trapped LNK Files
Briefly

PlugY, downloaded via CloudSorcerer, provides extensive commands and uses three protocols for C2 communication - Kaspersky.
Malware like GrewApacha deploys through DLL side-loading using GitHub to store C2 server details; CloudSorcerer enables espionage via Graph, Yandex, and Dropbox - Kaspersky.
Read at The Hacker News
[
|
]