Palo Alto Networks: Custom Backdoor ‘SockDetour’ Targets Defense Companies
Palo Alto Networks has found that threat actors have been using a custom backdoor called SockDetour to target U.S. defense contractors. The company said Thursday SockDetour functions as a backup backdoor in the event that the first backdoor is removed and is hard to detect because it “operates filelessly and socketlessly on compromised Windows servers.” […] More