Good day everyone, I hope all is well!
The Check Point Software Technologies Ltd research team took an in-depth look at the #SYSJOKER backdoor and discovered multiple variants as well. Sysjoker is written in Rust and has been used in cyber attacks against Israeli organizations during the Israeli-Hamas war. It also has been designed to target #Windows, #Linux, and #MacOS. I hope you enjoy the article and Happy Hunting!
ISRAEL-HAMAS WAR SPOTLIGHT: SHAKING THE RUST OFF SYSJOKER
https://research.checkpoint.com/2023/israel-hamas-war-spotlight-shaking-the-rust-off-sysjoker/
Notable MITRE ATT&CK TTPs:
TA0002 - Execution
T1059.003 - Command and Scripting Interpreter: PowerShell
TA0003 - Persistence
T1547.001 - Boot or Logon AutoStart Execution: Registry Run Keys/ Startup Folder
TA0011 - Command and Control
T1102.002 - Web Service: Bidirectional Communication
#CyberSecurity #ITSecurity #InfoSec #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday