IceBreaker Malware
Summary
A threatening attack campaign, dubbed IceBreaker targets the gaming and gambling sectors and has been active since at least September 2022. The actors claim to have account registration issues and then encourage the agent to open a screenshot image hosted on Dropbox. The LNK payload is configured to fetch and execute an MSI package carrying a Node.js implant on the victims machine. The Threatening Capabilities of the IceBreaker Malware The corrupted JavaScript file can be used by the threat actors to gain access to a victims computer. If the VBS downloader is executed by the victim instead, it will deploy a different payload named Houdini - a VBS-based Remote Access Trojan (RAT) that has been around since 2013.
Classifications
industries
Entertainment
applications
Customer Service & Support
AskAI Classifications
Labels
Cybersecurity Software
Anti-Malware Software
SaaS Security
Linked Companies
EnigmaSoft
$1M to $5M