3 ms·
> Base64 is never-before seen? Maybe they're referring to using a prominent website as a C&C server? Wait... no, they've seen that before when they reported, i
by dabber 3y ago
> Base64 is never-before seen?
Maybe they're referring to using a prominent website as a C&C server? Wait... no, they've seen that before when they reported, in 2017, on a:
> "backdoor Trojan used comments posted to Britney Spears's official Instagram account to locate the control server that sends instructions and offloads stolen data to and from infected computers." [0]
So they must be talking about the novel use of an image in the staged delivery? Oh... nevermind, that can't be it either because their reporting on VPNFilter in 2018 mentioned:
> "stage 1 relies on a sophisticated mechanism to locate servers where stage 2 and stage 3 payloads were available. The primary method involved downloading images stored on Photobucket.com and extracting an IP address from six integer values used for GPS latitude and longitude stored in the EXIF field of the image." [1]
So yeah, I guess Ars hasn't seen Base64 before it was embedded on their site.
[0] https://arstechnica.com/information-technology/2017/06/russian-hackers-turn-to-britney-spears-for-help-concealing-espionage-malware/ https://arstechnica.com/information-technology/2017/06/russi...
[1] https://arstechnica.com/information-technology/2018/06/vpnfilter-malware-infecting-50000-devices-is-worse-than-we-thought/ https://arstechnica.com/information-technology/2018/06/vpnfi...