FBI Warns Software Supply Chain Corporations about ongoing attacks against them 03-30-2020, 05:35 PM
#1
FBI alerts US private sectors about attacks aimed at their supply chain software providers. The FBI has sent a security alert to the US private sector about an ongoing hacking campaign; FBI says hackers are attempting to infect companies with the Kwampirs RAT. The alert did not identify the targeted software providers, nor any other victims.
![[Image: FBI.jpg]](https://i.ibb.co/5KcVCT4/FBI.jpg)
This RAT use "CreateProcessAsUserW" for the creation of second instance of a genuine process, under rundll32 with credentials of current logged in user, for example, you can see in the above pic Genuine Process - "wmiapsrv.exe" and tempered process is "wmipvsre.exe"
![[Image: FBI.jpg]](https://i.ibb.co/5KcVCT4/FBI.jpg)
This RAT use "CreateProcessAsUserW" for the creation of second instance of a genuine process, under rundll32 with credentials of current logged in user, for example, you can see in the above pic Genuine Process - "wmiapsrv.exe" and tempered process is "wmipvsre.exe"
(This post was last modified: 03-30-2020, 05:57 PM by SaMoo7.)
SaMoo7 was Here
![[Image: nicelane.gif]](https://cdn.discordapp.com/attachments/543434045741072385/556098401880637440/nicelane.gif)
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)













