Threat Group UNC3944 Abusing Azure Serial Console for Total VM Takeover

Discussion in 'News Aggregator' started by The Hacker News, 17 May 2023.

  1. A financially motivated cyber actor has been observed abusing Microsoft Azure Serial Console on virtual machines (VMs) to install third-party remote management tools within compromised environments. Google-owned Mandiant attributed the activity to a threat group it tracks under the name UNC3944, which is also known as Roasted 0ktapus and Scattered Spider. "This method of attack was unique in

    Continue reading...
     

Share This Page

Loading...