33
SoupDealer Malware Bypasses Every Sandbox, AV's and EDR/XDR in Real-World Incidents
(cybersecuritynews.com)
An umbrella community for all things cybersecurity / infosec. News, research, questions, are all welcome!
Enjoy!
That's a pretty narrow victim demographic. Windows has Defender enabled out of the box. I don't see any investigation on the C2 connection, either, so I'm left wondering who the attacked and intended targets are.
And it downloads Tor to connect to C2. So it's a machine with Internet access AND without security mesures.
So it might be a target with poor IT. A windows machine shouldn't be left without AV, especially if it has Internet access.