Cybersecurity experts have identified a series of targeted cyber attacks on financial organizations in Africa since July 2023, involving tools like PoshC2 and Chisel to gain and maintain access. The threat actors operate as initial access brokers, disguising their malware with legitimate application signatures and stealing credentials to expand their reach. #CL-CRI-1014 #PoshC2 #MeshCentralAgent
Keypoints
- The attacks primarily target financial institutions across Africa using publicly available hacking tools.
- The threat actors mask malicious tools by spoofing signatures of legitimate software like Microsoft Teams and VMware Tools.
- Once inside a network, the attackers deploy multiple tools such as MeshCentral Agent and Classroom Spy to control infected machines.
- Palo Alto Networks observed the use of scheduled tasks, services, and shortcut files to persist malware on infected systems.
- The emergence of the Dire Wolf ransomware group highlights ongoing threats to global financial and tech sectors with sophisticated capabilities.
Read More: https://thehackernews.com/2025/06/cyber-criminals-exploit-open-source.html