article thumbnail

GhostWriter APT targets state entities of Ukraine with Cobalt Strike BeaconĀ 

Security Affairs

The phishing messages use a RAR-archive named “Saboteurs.rar”, which contains RAR-archive “Saboteurs 21.03.rar.” ” This second archive contains SFX-archive “Saboteurs filercs.rar,” experts reported that the file name contains the right-to-left override (RTLO) character to mask the real extension.