RnD Research Lab

Cyber Security => IT News => Topic started by: ixsky on

Title: New 'HrServ.dll' Web Shell Detected in APT Attack Targeting Afghan Government
Post by: ixsky on
New 'HrServ.dll' Web Shell Detected in APT Attack Targeting Afghan Government

An unspecified government entity in Afghanistan was targeted by a previously undocumented web shell called HrServ in what's suspected to be an advanced persistent threat (APT) attack.
The web shell, a dynamic-link library (DLL) named "hrserv.dll," exhibits "sophisticated features such as custom encoding methods for client communication and in-memory execution," Kaspersky security researcher Mert

Source: New 'HrServ.dll' Web Shell Detected in APT Attack Targeting Afghan Government (https://thehackernews.com/2023/11/new-hrservdll-web-shell-detected-in-apt.html)