Updated on 2022-10-31
The Cranefly hacker group was spotted leveraging Microsoft IIS to deploy a previously undocumented dropper, named Danfuan, on security tools such as load balancers and SANS arrays. Read more: Espionage Hackers Use Microsoft IIS to Plant Malware
Overview: Cranefly
Broadcom’s Symantec team published a report last week on a recent trick used by the Cranefly APT, which uses the logs of IIS servers to send commands to infected servers. Read more: Cranefly: Threat Actor Uses Previously Unseen Techniques and Tools in Stealthy Campaign