This one is kinda interesting. Uses a .ISO file (Defender and possibly others allowlist by default, but Win10 opens natively), inside there's a .exe which is too large for Defender to scan. C2 is via Apple's push infrastructure. https://www.virustotal.com/gui/file/83f99f42880fcbbbe6e810aa8bc498a4318e27fcfb86301c4bd305be9379234e/detection … https://twitter.com/bcrypt/status/1420471176137113601 …
-
-
ArechClient was a hoot!
-
I guess i have to get out from under the rock more. I have not seen this.
End of conversation
New conversation -
-
-
Holy shit
Thanks. Twitter will use this to make your timeline better. UndoUndo
-
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.
there’s additional domains to block (they also theme around many other apps) in the thread from