TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Indian threat actor Patchwork APT caught in its own web

140 pointsby akshaybhalotiaover 3 years ago

7 comments

vlovich123over 3 years ago
Wait. How does the malware author injecting themselves with their own malware lead to Malwarebytes getting screenshots of the attackers machine? Did they somehow breach the APT’s network or hijack the malware? Is there some context I’m missing behind this blog post?
评论 #29888005 未加载
评论 #29887884 未加载
archi42over 3 years ago
Strictly speaking, they&#x27;re wrong about the keyboard layout. &quot;ENG\nIN&quot; means something like &quot;English (India)&quot; - the layout selector only shows the currently active layout (if more than one layout is configured). The other layouts are only shown when clicking on it and might be anything.<p>Also, when defining a custom keyboard layout you have relative freedom in picking the name and language&#x2F;region it&#x27;s classified as. So that &quot;ENG\nIN&quot; could be anything.<p>Source: I have two layouts installed. The default regional keyboard layout so co-workers using my machine don&#x27;t go insane (shown as &quot;DEU \nDE&quot; [=Language\nRegion]), and for myself a customized variant of the US layout. I can&#x27;t recall the exact reason why I configured it as it is (maybe to avoid installing the &quot;ENG&quot; language pack?), but that custom US layout shows as plain &quot;DEU&quot; (no second line).
hsbauauvhabzbover 3 years ago
The logic in the php snippet which captures IP addresses is not correct. Any user is able to add an x-forwarded-for header to mask their real IP from the logs.<p>I wouldn’t be surprised if the log file can have additional entries spoofed with new lines also ;)
评论 #29890048 未加载
ChrisMarshallNYover 3 years ago
Yeesh. OLE objects.<p>I thought it was a bad idea, back then, and I think most folks were of the same mind. I’m actually shocked that OLE is still a thing.
amriksohataover 3 years ago
How do they even know it&#x27;s Indian? What footprint is used
评论 #29889216 未加载
评论 #29891756 未加载
评论 #29889019 未加载
评论 #29889194 未加载
评论 #29889112 未加载
mijoharasover 3 years ago
Can someone tell me what APT stands for in this context? it doesn&#x27;t appear to be defined in the linked article.
评论 #29891471 未加载
rl3over 3 years ago
&gt;<i>That file contains an exploit (Microsoft Equation Editor) which is meant to compromise the victim’s computer and execute the final payload (RAT).</i><p>When your attempt to copy the <i>Equation Group</i> is a little too literal.