Threat actor has been targeting the aviation industry since at least 2018
Security Affairs
SEPTEMBER 18, 2021
Talos researchers believe that the group was able to remain under the radar using crypters that it bought on cybercrime forums. They abandon the C2 hostnames — which in this case are free DNS-based and they may change the crypter and initial vector, but they won’t stop their activity. Pierluigi Paganini.
Let's personalize your content