article thumbnail

TA505 is expanding its operations

Security Affairs

The threat group is also known for its recent attack campaign against Bank and Retail business sectors, but the latest evidence indicates a potential expansion of its criminal operation to other industries too. Files contained in “wprgxyeqd79.exe” The “-p” parameter, indeed, specify the password of the archive to be extracted.

IT 70