Taurus Loader
Description
(Proofpoint) We use this name to describe a tool used to create malicious documents. We believe Taurus builder was purchased on underground crime forums. Notably, documents created with this builder use the CMSTP bypass.
Names
Name |
---|
Taurus Loader |
Taurus Builder |
Taurus Builder Kit |
Category
Malware
Type
- Botnet
- Downloader
Information
- https://www.proofpoint.com/us/threat-insight/post/fake-jobs-campaigns-delivering-moreeggs-backdoor-fake-job-offers
- https://medium.com/@quoscient/golden-chickens-uncovering-a-malware-as-a-service-maas-provider-and-two-new-threat-actors-using-61cf0cb87648
- https://quointelligence.eu/2018/11/golden-chickens-uncovering-a-malware-as-a-service-maas-provider-and-two-new-threat-actors-using/
Other Information
Uuid
447eedbe-c9b3-4021-9062-dae0fbf10473
Last Card Change
2020-07-10