New ‘Domino’ Malware Linked to FIN7 Group, Ex-Conti Members

Distribution campaigns for a recently identified backdoor have revealed a partnership between former members of the Conti ransomware group and developers for the FIN7 advanced persistent threat (APT), IBM reports. Dubbed ‘Domino’, the backdoor has been active since at least October 2022 and is capable of gathering basic system information, sending data to its command-and-control (C&C) server, and executing a loader to deploy the final payload on the compromised systems.

Read full article on SecurityWeek

 


Date:

Categorie(s):

Tag(s):