Go back to previous topic
Forum nameGeneral Discussion
Topic subjectThey took over the domain used for the C2 server.
Topic URLhttp://board.okayplayer.com/okp.php?az=show_topic&forum=4&topic_id=13417477&mesg_id=13417516
13417516, They took over the domain used for the C2 server.
Posted by nonaime, Mon Dec-21-20 10:43 AM
So yes, they can tell if someone is infected, but just because folks are phoning home doesn't mean that there is/was interest in them.

Once FireEye blew the whistle on the campaign, it would be foolish for anyone to continue whatever they were doing.

We probably won't hear directly anything on the Fed side...but anyone else who saw their systems rummaged through will most likely say something...especially publicly traded companies. They have to disclose stuff like this (FireEye immediately released an 8-K).