Cranefly threat group uses innocent-looking info-stealer
Briefly

A threat group that targets corporate emails is delivering dropper malware through a novel technique that uses Microsoft Internet Information Services (IIS) logs to send commands disguised as web access requests.The dropper, dubbed Geppei, is being used by a group Symantec threat researchers call Cranefly to install other undocumented malware.
Read at Theregister
[
add
]
[
|
|
]