Nuget Malicious Banking Credential Attack Targets Cloud Secrets
TL;DR. A malicious NuGet package, tied to the Sicoob banking platform, is stealing banking credentials and harvesting cloud secrets. - The attack leverages tactics like typosquatting and dependency confusion to distribute fake packages. - It specifically targets developers through public repositories to compromise supply chains. - Attackers use obfuscated PowerShell scripts to exfiltrate sensitive data to C2 servers.
- Malicious NuGet package named 'sicoob' steals banking credentials.
- Attackers employ typosquatting and dependency confusion for distribution.
- The campaign targets developer environments and cloud secrets.
- Data exfiltration is managed via obfuscated PowerShell scripts to C2 servers.