• frongt@lemmy.zip
    link
    fedilink
    arrow-up
    14
    ·
    2 days ago

    In live incidents, SoupDealer bypassed host‐based antivirus checks by confirming no security products were active before proceeding.

    That’s a pretty narrow victim demographic. Windows has Defender enabled out of the box. I don’t see any investigation on the C2 connection, either, so I’m left wondering who the attacked and intended targets are.

    • Hirom@beehaw.org
      link
      fedilink
      arrow-up
      2
      ·
      1 day ago

      And it downloads Tor to connect to C2. So it’s a machine with Internet access AND without security mesures.

      So it might be a target with poor IT. A windows machine shouldn’t be left without AV, especially if it has Internet access.