For this week's TTP Tuesday we are releasing a new APT38 themed chain to demonstrate embedding malware in a container file to subvert Mark-of-the-Web trust controls. This technique can be used to achieve macro execution even when downloading files from an untrusted zone such as the Internet.
This chain starts by installing PackMyPayload, then creates an ISO image, hosts it for download, and once unpacked and executed on the target machine queues a TTP for the embedded agent.
Video Timeline:
00:00 Prelude Intro
00:07 Intel Intro
02:47 Further Chain Info
05:15 Chain Demo