SoupDealer Malware Bypasses Every Sandbox, AV's and EDR/XDR in Real-World Incidents

https://cybersecuritynews.com/soupdealer-malware-bypasses-every-sandbox/

34 points · 9 comments · view on lemmy.world

9 Comments

frongt@lemmy.zip · 14 pts · 1y (1 reply)

In live incidents, SoupDealer bypassed host‐based antivirus checks by confirming no security products were active before proceeding.

That's a pretty narrow victim demographic. Windows has Defender enabled out of the box. I don't see any investigation on the C2 connection, either, so I'm left wondering who the attacked and intended targets are.

Hirom@beehaw.org · 2 pts · 1y

And it downloads Tor to connect to C2. So it's a machine with Internet access AND without security mesures.

So it might be a target with poor IT. A windows machine shouldn't be left without AV, especially if it has Internet access.

sad_detective_man@leminal.space · 5 pts · 1y (4 replies)

Why would somebody only target machines in Turkey?

ButtermilkBiscuit@feddit.nl · 5 pts · 1y (2 replies)

Greece has entered the chat

sad_detective_man@leminal.space · 5 pts · 1y (1 reply)

oh wait. yeah, look I'm not a smart man

lurch@sh.itjust.works · 5 pts · 1y

I'm a smart man and I think your question still stands. Why shouldn't they get along like normal people. (Intentionally no question mark.)

hakki@floss.social · 1 pts · 1y

@sad_detective_man @cm0002 Turkey is also somehow a border of the NATO - that can also be a key

salacious_coaster@infosec.pub · 4 pts · 1y

Yikes 😬

SendMePhotos@lemmy.world · 2 pts · 1y