Unit 42

Unit 42

@unit42_intel · Twitter ·

Fake IT support campaign delivers a malicious MSI that sideloads a trojanized DLL via a signed binary, then uses WMI to launch a custom reverse shell tunneled over a local port (localhost:9001) to an AWS API Gateway C2. Detection and indicators: https://bit.ly/4ycFn7h

The image is a flowchart illustrating a cyberattack process. It includes labeled steps connecting "Attacker Endpoint," "DLL Sideloading," "Reverse Shell," and "Target CMD." A flowchart illustrating a file processing sequence. Symbols indicate decision points and potential errors.