Exposing the Deception: Russian EFF Impersonators Behind Stealc & Pyramid C2
Open directories often expose more than just files--they provide a window into how malicious campaigns operate. In this case, we identified a threat actor impersonating the Electronic Frontier Foundation (EFF) to target the online gaming community. The exposed directory contained decoy documents alongside the malware used in this operation: Steal and Pyramid C2.Further analysis linked 11 additional servers to the campaign through shared SSH keys, indicating a broad network footprint. Code commen...
Read more at hunt.io