You are viewing a single comment's thread.

view the rest of the comments →

pisslam ago

my recommendation is to run firefox or brave in firejail with apparmor. if you set up firejail with the overlay function, nothing is written to the disk and the program has no idea it has been jailed.

senpaithatignoresyou ago

This was on multiple corporate networks: on unix AND linux machines.

We think FIN7 made it, because the new diagnostic tools think it was installed around April-May, around the same time they where fucking with chipotle and other companies.

dunrambai ago

Sounds like kovter and not fin7. Hashes, details, persistence mechanisms?

senpaithatignoresyou ago

From what i understand, in one instance it was running powershell scripts that it read off of a text file.

It also had scripts that worked on other operating systems in other text files as well.