IceBreaker Malware

General News

Summary

A threatening attack campaign, dubbed IceBreaker targets the gaming and gambling sectors and has been active since at least September 2022. The actors claim to have account registration issues and then encourage the agent to open a screenshot image hosted on Dropbox. The LNK payload is configured to fetch and execute an MSI package carrying a Node.js implant on the victims machine. The Threatening Capabilities of the IceBreaker Malware The corrupted JavaScript file can be used by the threat actors to gain access to a victims computer. If the VBS downloader is executed by the victim instead, it will deploy a different payload named Houdini - a VBS-based Remote Access Trojan (RAT) that has been around since 2013.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M