A new threat actor is targeting Microsoft Windows web servers, suggesting that users should patch .NET deserialisation vulnerabilities and look for suspicious activity on web-facing Microsoft Internet Information Services servers, according to cybersecurity technology and services provider Sygnia.
Tel Aviv-based Sygnia recently issued a report stating that researchers found “an advanced memory-resident attack commonly associated with nation-state actors.”
The hacker, which Sygnia is calling “Praying Mantis” or “TG1021,” uses “a variety of deserialisation exploits targeting Windows IIS servers and vulnerabilities targeting web applications” and “a completely volatile and custom malware framework tailor-made for IIS servers.”
IIS (Internet Information Services) is a web server on the Microsoft .NET platform on the Windows operating system.
Chinese Military Hackers Launch Tripple Cyberattack on Major Telecom Carriers
softpedia.com - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from softpedia.com Daily Mail and Mail on Sunday newspapers.
Iranian APT Lures Defense Contractor in Catfishing-Malware Scam
threatpost.com - get the latest breaking news, showbiz & celebrity photos, sport news & rumours, viral videos and top stories from threatpost.com Daily Mail and Mail on Sunday newspapers.