A new strand of malware uses Word files with macros to download a PowerShell script from GitHub. This PowerShell script further downloads a legitimate image file from image hosting service Imgur to decodeĀ a Cobalt Strike script. […]
Home>Secure Hunter Blog>Anti-Malware News>GitHub-hosted malware calculates Cobalt Strike payload from Imgur pic