SYMBOLCOMMON_NAMEaka. SYNONYMS
win.bh_a006 (Back to overview)

BH_A006


According to Volexity, a loader observed to be used with multiple malware families, among them LIGHTSPY.

References
2024-11-15VolexityCallum Roxan, Charlie Gardner, Paul Rascagnères
BrazenBamboo Weaponizes FortiClient Vulnerability to Steal VPN Credentials via DEEPDATA
lightSpy LIGHTSPY BH_A006 DEEPDATA DEEPPOST BrazenBamboo

There is no Yara-Signature yet.