"The aim of phishing is normally to get full access to the machines and this attack is no different. However, because FIN4 doesn't actually drop malware onto victims machines, instead mimics normal user behaviours, it will make this type of activity incredibly hard to detect.
- Alex Marsden, MWR InfoSecurity
- Talking Point
- Posted On