• Categories
    Category
  • Categories
    Category
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
News Comments FAQ Related Articles

FIN7 still to be found via Astra tools even after arrests

5361

A recent discovery by the researchers has brought to light the fact that FIN7, despite several arrests last year, still continues to show signs of life, continues to show signs of life.

It was found out to be a new attack panel (Astra) in campaigns that Flashpoint analysts have called Astra. Also, it was found to be in two new malware samples that were used in 2018.

The members of the group (Carbanak gang) behind FIN7 were arrested last year, January and August 2018. They started the attacks from 2015 targeting over 100 companies across the US, Europe, and Australia. Hospitality, restaurant, and gaming industries were mostly the victims of their attacks.

The fact that Astra is detected by the researchers suggests the fact that FIN7 is resilient in its quest to steal payment card and financial data from hacked devices from around the world. Researchers describe Astra as a script management stem, written in PHP, used to push attack scripts to infected computers.

Flashpoint identified the two previously unseen malware families associated with the Astra campaign activity as SQLat and DNSbot. SQLRat drops files and executes SQL scripts on infected host systems by not leaving behind any artifacts like a malware usually does, a trait that was not observed in the previous FIN7 attacks. DNSbot, on the other heand, is a multi-protocol backdoor through which attackers can push data between compromised machines via either DNS traffic or encrypted channels like HTTPS or SSL.

The Astra was found to be used in sensitive situations, thus avoiding its exposure in the previous months.

Tags:
markdjokovic
Author: 

Comments ( 0 )

No comments available

Add a comment

Frequently asked questions ( 0 )

No questions available

Related News in FIN7 still to be found via Astra tools even after arrests

Related News in FIN7 still to be found via Astra tools even after arrests

URL Attacks and The Ways to Stay Away from Them!
URL Attacks and The Ways to Stay Away from Them!
Mar 19, 2019
FIN7 still to be found via Astra tools even after arrests
FIN7 still to be found via Astra tools even after arrests
Mar 26, 2019
Streaming List of GPS Locations Exposed From Saudi Telecom Provider
Streaming List of GPS Locations Exposed From Saudi Telecom Provider
Dec 17, 2019
A Sneaky Ransomware That Seems Benificial. But Deceptive.
A Sneaky Ransomware That Seems Benificial. But Deceptive.
Apr 5, 2019
Pressing Cybersecurity issue in healthcare and how to mitigate it!
Pressing Cybersecurity issue in healthcare and how to mitigate it!
Mar 18, 2019
DMSniff POS Malware Thrives via DGA
DMSniff POS Malware Thrives via DGA
Mar 18, 2019
Gnosticplayers’ is back with breached data sale on the Dark Web
Gnosticplayers’ is back with breached data sale on the Dark Web
Mar 21, 2019
Popular SSH client PuTTY had serious key exchange vulnerability
Popular SSH client PuTTY had serious key exchange vulnerability
Mar 22, 2019
Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help legeek ?
Installation of the call center module

hello

I wish to install a call center in virtual with issabel, I downloaded the latest version of it , but I don' t arrive to install the call center module in issabel. please help me

thanks!

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.