ICYMI: China-based APT group #LuoYu now targets the commonly used Windows auto-update feature to compromise victims’ machines. Get the technical analysis on #WinDealer, usage of man-on-the-side attack method, #YARArule, #IoCs & more. #ThreatThursday
Auto-updaters can help close the door on known attacks and security vulnerabilities by allowing software vendors to patch their own wares automatically. But recently, threat actors from the LuoYu group have been turning this commonly used feature into a weapon to compromise victims’ machines.
ICYMI: China-based APT group #LuoYu now targets the commonly used Windows auto-update feature to compromise victims’ machines. Get the technical analysis on #WinDealer, usage of man-on-the-side attack method, #YARArule, #IoCs & more. #ThreatThursday