Threat Group – Xillen Killers
Threat Type – Information stealer and loader operating under a Malware as a Service model
Exploited Vulnerabilities – Social engineering and opportunistic scanning for unpatched versions of Cisco AnyConnect, OpenVPN, FortiClient and Pulse Secure in order to access cached credentials
Malware Used – Xillen Stealer version five using a