Hacker News new | ask | show | jobs
by SurceBeats 235 days ago
The sophistication here (SVG > CHM > fileless execution > dual payload) suggests access to commercial malware toolkits rather than bespoke APT development.
1 comments

And, it might be taking longer to discover because it's hard to notice with SVG.