Good read folks @SecurityBeard @r00tbsd @vanjasvajcer, I don't think DLL sideloading had been used before by BR bankers? cc @assolini
-
-
Replying to @bartblaze @TalosSecurity and
Possibly related: https://www.virusbulletin.com/conference/vb2017/abstracts/last-minute-paper-client-maximus-raises-bar … cc
@omeriko_91 reply 0 retweets 1 like -
Replying to @martijn_grooten @bartblaze and
Only by fact of attacking Brazil. We had no Powershell in ours. Java and Delphi *shudder* packed with Themida :(
1 reply 0 retweets 4 likes -
Replying to @SecurityBeard @martijn_grooten and
Delphi packed with Themida should autocorrect to Brazilian Banker (cc:
@assolini)1 reply 1 retweet 6 likes -
Replying to @juanandres_gs @SecurityBeard and1 reply 0 retweets 3 likes
-
Replying to @dimitribest @juanandres_gs and
No Themida. Just shit Delphi!
2 replies 0 retweets 2 likes -
Replying to @SecurityBeard @dimitribest and
Delphi is definitely (and unfortunately) making a comeback, so it seems.
1 reply 0 retweets 2 likes -
Replying to @bartblaze @SecurityBeard and
I bet Oracle is behind it. (Sorry.)
1 reply 0 retweets 4 likes -
-
Replying to @bartblaze @martijn_grooten and
You’re triggering my other (and often tweeted) nightmare.pic.twitter.com/RhopsWSuBg
1 reply 0 retweets 4 likes
Replying to @SecurityBeard @martijn_grooten and
Talking about a supply chain attack... :-)
8:08 AM - 2 Oct 2017
0 replies
0 retweets
0 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.