4 ms·
The malicious version had items in place that would cause it to not activate if certain anti-malware software is present or other environmental conditions were
by intern4tional 6y ago
The malicious version had items in place that would cause it to not activate if certain anti-malware software is present or other environmental conditions were not met (like not joined to an active directory). This reduces the number from 18k to something less (still probably huge) but 18k is the max if perfect conditions are present.
As for why the attackers did not proceed, resourcing probably had nothing to do with it and more along the lines of many of those customers were not interesting. Proceeding to load further malware stages in those uninteresting customers increases the chance of getting detected and given that the attacker was targeting long term persistent access to highly valuable targets, the attacker by design more likely simply left targets without valuable information alone.
- OminousWeapons 6y agoIt's probably both. Additional exploitation of targets was typically required to reach data of interest, and at a certain point you do get resource constrained having to deal with a high number of targets. It takes time to exploit them, it takes time to ingest and parse the discovered data, and even basic things like managing all the resulting shells takes time. Based on this, as you say there were likely a high number of targets who probably were not worth the time to exploit, especially when every exploitation action increases the risk of detection and cessation of the op.