Wednesday, March 13, 2013

The Dingo and the Baby

FireEye has been tracking an APT campaign for a while and we have noticed that this attack is currently active and targeting companies.

Image source: Article
In this case, the campaign uses the name of the company it targets in the CnC domain name.

What does this have to do with dingoes and babies? The title comes from a string that we saw in all of the malware, called LetsGo/Merong, and its variants.

Do you know where the dingo is?

No comments: