216.73.216.6

Water Makara Uses Obfuscated JavaScript in Spear Phishing Campaign Targeting Brazil With Astaroth Malware

· Published 15/10/2024 08:51 · Modified 15/10/2024 10:15

Export JSON

Essential information

Published
15/10/2024 08:51
Modified
15/10/2024 10:15
Tags
2024-10-15 astaroth banking malware brazil domain generation algorithm lnk files obfuscated javascript spear-phishing tax documents
Related entities
1 intrusion sets (apt), 2 malware, 4 others

Description

Water Makara, a threat actor group, is targeting enterprises in with a spear phishing campaign using the . The attackers employ to bypass security defenses, often impersonating official to trick users. The campaign primarily affects manufacturing companies, retail firms, and government agencies. The attack chain involves malicious ZIP files containing that execute JavaScript commands, establishing connections to a C&C server. The malware uses domain generation algorithms and various file extensions to spread. This campaign highlights the importance of user awareness, security training, and robust cybersecurity measures to mitigate such threats.

External references