TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Indian threat actor Patchwork APT caught in its own web

140 点作者 akshaybhalotia超过 3 年前

7 条评论

vlovich123超过 3 年前
Wait. How does the malware author injecting themselves with their own malware lead to Malwarebytes getting screenshots of the attackers machine? Did they somehow breach the APT’s network or hijack the malware? Is there some context I’m missing behind this blog post?
评论 #29888005 未加载
评论 #29887884 未加载
archi42超过 3 年前
Strictly speaking, they&#x27;re wrong about the keyboard layout. &quot;ENG\nIN&quot; means something like &quot;English (India)&quot; - the layout selector only shows the currently active layout (if more than one layout is configured). The other layouts are only shown when clicking on it and might be anything.<p>Also, when defining a custom keyboard layout you have relative freedom in picking the name and language&#x2F;region it&#x27;s classified as. So that &quot;ENG\nIN&quot; could be anything.<p>Source: I have two layouts installed. The default regional keyboard layout so co-workers using my machine don&#x27;t go insane (shown as &quot;DEU \nDE&quot; [=Language\nRegion]), and for myself a customized variant of the US layout. I can&#x27;t recall the exact reason why I configured it as it is (maybe to avoid installing the &quot;ENG&quot; language pack?), but that custom US layout shows as plain &quot;DEU&quot; (no second line).
hsbauauvhabzb超过 3 年前
The logic in the php snippet which captures IP addresses is not correct. Any user is able to add an x-forwarded-for header to mask their real IP from the logs.<p>I wouldn’t be surprised if the log file can have additional entries spoofed with new lines also ;)
评论 #29890048 未加载
ChrisMarshallNY超过 3 年前
Yeesh. OLE objects.<p>I thought it was a bad idea, back then, and I think most folks were of the same mind. I’m actually shocked that OLE is still a thing.
amriksohata超过 3 年前
How do they even know it&#x27;s Indian? What footprint is used
评论 #29889216 未加载
评论 #29891756 未加载
评论 #29889019 未加载
评论 #29889194 未加载
评论 #29889112 未加载
mijoharas超过 3 年前
Can someone tell me what APT stands for in this context? it doesn&#x27;t appear to be defined in the linked article.
评论 #29891471 未加载
rl3超过 3 年前
&gt;<i>That file contains an exploit (Microsoft Equation Editor) which is meant to compromise the victim’s computer and execute the final payload (RAT).</i><p>When your attempt to copy the <i>Equation Group</i> is a little too literal.