ATP next-gen protection exposes complex Astaroth attack

D

DelJo63

Microsoft itself has found a complex attack that uses only existing programs to cause malicious intent: the Astaroth Attack. Using its own 'ATP next-gen protection', this is what the attack looks like:


Astaroth, is injected into the Userinit process.

fig1a-astaroth-attack-chain.png

see the original article for more details.
 
Back