Update gozi_malware.yml

This commit is contained in:
Michael Haag
2024-07-24 14:39:35 -06:00
parent c35925b3a9
commit e600d8cd87
+3
View File
@@ -11,6 +11,9 @@ narrative: 'Gozi malware, first observed in 2006, has a complex lineage tracing
Post-infection activities may include credential theft, lateral movement, and the use of legitimate tools for persistence and remote access. Threat actors often leverage Gozi infections to conduct extensive reconnaissance, move laterally within networks, and potentially prepare for more severe attacks such as data exfiltration or ransomware deployment. /n
Detection strategies should focus on identifying suspicious ISO files, unusual process executions (especially involving renamed system utilities), registry modifications, and network communications associated with Gozi''s command and control infrastructure. Additionally, monitoring for post-exploitation activities such as credential dumping, lateral movement attempts, and the deployment of remote management tools can help in early detection and mitigation of Gozi-related threats.'
references:
- https://malpedia.caad.fkie.fraunhofer.de/details/win.gozi
- https://thedfirreport.com/2023/01/09/unwrapping-ursnifs-gifts/
tags:
category:
- Adversary Tactics