• Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • Categories
    Category
    {{ postCtrl.tags }}
    • {{ category.tag_type }}

      • {{tag.tag_name}}
      • View more
  • News
  • Tutorials
  • Forums
  • Tags
  • Users
Tutorial News Comments FAQ Related Articles

FIN7 still to be found via Astra tools even after arrests

{{postValue.id}}

A recent discovery by the researchers has brought to light the fact that FIN7, despite several arrests last year, still continues to show signs of life, continues to show signs of life.

It was found out to be a new attack panel (Astra) in campaigns that Flashpoint analysts have called Astra. Also, it was found to be in two new malware samples that were used in 2018.

The members of the group (Carbanak gang) behind FIN7 were arrested last year, January and August 2018. They started the attacks from 2015 targeting over 100 companies across the US, Europe, and Australia. Hospitality, restaurant, and gaming industries were mostly the victims of their attacks.

The fact that Astra is detected by the researchers suggests the fact that FIN7 is resilient in its quest to steal payment card and financial data from hacked devices from around the world. Researchers describe Astra as a script management stem, written in PHP, used to push attack scripts to infected computers.

Flashpoint identified the two previously unseen malware families associated with the Astra campaign activity as SQLat and DNSbot. SQLRat drops files and executes SQL scripts on infected host systems by not leaving behind any artifacts like a malware usually does, a trait that was not observed in the previous FIN7 attacks. DNSbot, on the other heand, is a multi-protocol backdoor through which attackers can push data between compromised machines via either DNS traffic or encrypted channels like HTTPS or SSL.

The Astra was found to be used in sensitive situations, thus avoiding its exposure in the previous months.

Tags:
markdjokovic
Author: 

Comments ( 0 )

No comments available

Add a comment
{{postCtrl.cmtErrMsg}}

Frequently asked questions ( 0 )

No questions available

Back To Top!
Rank
User
Points

Top Contributers

userNamenaveelansari
135850

Top Contributers

userNameayanbhatti
92510

Top Contributers

userNamehamzaahmed
32150

Top Contributers

1
userNamelinuxhelp
31040

Top Contributers

userNamemuhammadali
24500
Can you help David Lopez Guillen ?
Ayuda urgente instale SSL para servidor Opensuse y ahora no funciona tengo servicio web

hola segui este tutorial para tener un certificado ssl y ahora no se ve mi app en la red, espero alguien pueda ayudarme, tengo M9oodle en3.5 en un servidor open suse y ahora no funciona por favor ayuda.

https://www.linuxhelp.com/how-to-create-ssl-certificate-in-opensuse

Networking
  • Routing
  • trunk
  • Netmask
  • Packet Capture
  • domain
  • HTTP Proxy
Server Setup
  • NFS
  • KVM
  • Memory
  • Sendmail
  • WebDAV
  • LXC
Shell Commands
  • Cloud commander
  • Command line archive tools
  • last command
  • Shell
  • terminal
  • Throttle
Desktop Application
  • Linux app
  • Pithos
  • Retrospect
  • Scribe
  • TortoiseHg
  • 4Images
Monitoring Tool
  • Monit
  • Apache Server Monitoring
  • EtherApe 
  • Arpwatch Tool
  • Auditd
  • Barman
Web Application
  • Nutch
  • Amazon VPC
  • FarmWarDeployer
  • Rukovoditel
  • Mirror site
  • Chef
Contact Us | Terms of Use| Privacy Policy| Disclaimer
© 2025 LinuxHelp.com All rights reserved. Linux™ is the registered trademark of Linus Torvalds. This site is not affiliated with linus torvalds in any way.