惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - Franky
MyScale Blog
MyScale Blog
A
About on SuperTechFans
博客园_首页
B
Blog RSS Feed
Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Vercel News
Vercel News
C
Check Point Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
I
InfoQ
罗磊的独立博客

Intel 471 Blog

TeamPCP Supply Chain Attacks Turning Geopolitical Tension into Actionable Intelligence CVE-2025-68613: Zerobot botnet exploits critical vulnerability impacting n8n AI orchestration platform Introducing Cyber Threat Exposure Bundle: A Unified Approach to External Risk CVE-2026-20127: Critical Cisco SD-WAN vulnerability exploited in wild Handala Threat Group OpenClaw: A viral AI assistant and a magnet for infostealer malware and ClickFix trickery Israeli, US strikes against Iran triggers a surge in hacktivist activity CVE-2026-1731: Finding a critical RCE in an age of AI-driven vulnerability research Born to bypass MFA: Taking down Tycoon 2FA The UK Cyber Security Resilience Bill How AI and the human advantage beat tomorrow’s threats Winter Olympics 2026: Hacktivism Surges Ahead of Protests and Suspected Sabotage How Threat Hunting and “Good” Metrics Help The Business Likely fake ransomware operator 0APT causes panic — Our analysis Hunting APTs: from state policy to TTPs CrazyHunter Ransomware DevMan Ransomware Introducing HUNTER Tuning: a New Tool for Driving Behavioral Threat Hunt Detections Battling check fraud in the U.S. Gootloader Malware Update Shai-Hulud Worm 2.0 New FvncBot Android banking trojan targets Poland White Paper Preview: Black "Fraud Day” and Beyond — The Key Cyber Threats Facing the Retail Sector this Holiday Season Threat hunting case study: Detecting IAB activity Using deception to extract cyber threat intelligence Lynx Ransomware Qilin Ransomware Group ClickFix: Tricking users into installing infostealers Cybercrime Takedowns: Trust, Partnerships and Focus
Suspicious rundll32 Execution
Intel 471 · 2021-06-01 · via Intel 471 Blog

THREAT DESCRIPTION

In May 2021, Microsoft and Volexity reported sophisticated phishing campaigns affecting government organizations. Microsoft attributed the attack to Nobelium (UNC2452). Nobelium utilized several new malwares and tools to carry out their attack. In the first stages of setting up a foothold on a target system, Nobelium utilized EnvyScout and BoomBox. EnvyScout is a malicious dropper capable of de-obfuscating and writing a malicious ISO file to disk. The intent of the ISO file is to coax a target user into mounting it and clicking on the contained LNK file. BoomBox is a downloader which collects system information, sends it to a DropBox account for parsing and ingestion by Nobelium, and downloads additional tools, such as NativeZone.

ANALYST NOTES

This technique was observed being utilized by Nobelium in May 2021. The attack chain observed was a lure to get a user to open an "IMG" or "ISO" file containing a LNK file. The LNK was disguised as a folder and would execute a hidden binary (BoomBox) within the IMG file. From this point rundll32.exe would be utilized several times to execute various DLL files, and execute specific code blocks within one or more additionally downloaded DLL files. The targeted technique was utilized to upload system information to DropBox for the adversary's analysis and parsing, as well as download a loader called NativeZone. This is typically a CobaltStrike BEACON and Loader. Analysts can review activity before the trigger of this rule, looking for several rundll32.exe commands, IMG or ISO file being loaded, saved or opened by explorer.exe. Aside from the reported Nobelium activity, analysts can look for general rundll32.exe proxy execution. LNK files are commonly utilized in phishing and can often mimic similar activity to the intended activity in this package. However, instead of looking for a mounted ISO file, analysts can look for additional rundll32.exe executions and LNK files opened from Outlook's temporary directories.

Get the Free Hunt Packages!

Check Out Other Emerging Threats >