Japanese cybersecurity provider Trend Micro has uncovered a new malicious campaign targeting female political leaders and attendees of the Women Political Leaders (WPL) Summit held in Brussels in June 2023.
The treat actors, Void Rabisu, started deploying a new version of its RomCom backdoor – which Trend Micro tracks as RomCom 4.0 and Microsoft as Peapod – in early August 2023, Trend Micro reported in a malware analysis published on October 13.
The backdoor payload was hidden in a malicious copy of the official website of the WPL Summit, which aims to improve gender equality in politics.
“While the ‘Videos & photos’ link of the legitimate domain redirects visitors to a Google Drive folder containing photographs from the event, the wplsummit[.]com fake website directed visitors to a OneDrive folder containing two compressed files and an executable called Unpublished Pictures 1-20230802T122531-002-sfx.exe. The latter file appears to be a piece of malware,” reads the Trend Micro report.
No tags.