QuestionQ2

Threat Actor Attribution Techniques

An analyst receives a report stating that the infection chain starts with a phishing email containing a malicious download link. When the victim downloads the malicious RAR file, the archive requires a specific password for extraction, revealing a fake PDF executable malware file and an image printing file. After the malware is decrypted and the fake PDF executable is run, the embedded LummaC2 or Rhadamanthys information stealer executes automatically, collects the victim’s credentials and data, and sends them to the C2 server.

Which conclusion should the analyst make about the threat actor?

Explanation

The activity is a multi-stage intrusion: a phishing link delivers a password-protected archive and disguised executable, which helps bypass security inspection before executing an information stealer. The payload collects credentials and data and transmits them to a command-and-control server, establishing sensitive-information exfiltration as the operation’s primary objective. MITRE ATT&CK identifies malicious-link phishing as a method for delivering malware, including Lumma Stealer.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!