<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Posts on Mal-Eats</title><link>https://mal-eats.net/en/posts/</link><description>Recent content in Posts on Mal-Eats</description><generator>Hugo</generator><language>en</language><lastBuildDate>Tue, 11 May 2021 12:08:02 +0900</lastBuildDate><atom:link href="https://mal-eats.net/en/posts/index.xml" rel="self" type="application/rss+xml"/><item><title>Campo, a New Attack Campaign Targeting Japan</title><link>https://mal-eats.net/en/2021/05/11/campo_new_attack_campaign_targeting_japan/</link><pubDate>Tue, 11 May 2021 08:23:26 +0900</pubDate><guid>https://mal-eats.net/en/2021/05/11/campo_new_attack_campaign_targeting_japan/</guid><description>&lt;p&gt;Since around March 2021, campaigns in Japan using an infrastructure called campo/openfield have been observed. This campaign has the potential to deliver subsequent malware depending on the infected organization, and some cases eventually could result in ransomware incidents overseas.&lt;/p&gt;&#10;&lt;p&gt;We keep tracking this attack campaign, and it started to be observed at least around October 2020 as far as we are aware. We anticipate that attackers will continue to be active in the future, and we are concerned that this could lead to serious impacts including ransomware encryption in the worst case. Therefore, in order to prepare for such threats, we will share in this blog the characteristics of campaigns for Japan and how to check for malware execution traces based on our research.&lt;/p&gt;</description></item></channel></rss>