Summary
Affected platforms
The following platforms are known to be affected:
Threat details
At the time of publication, it is unclear how Felipe is delivered. When delivered Felipe will enumerate the affected system to determine if it has already been infected, before creating a hidden folder on the Desktop. It will then install four payloads to disable security services, maintain persistence and extract information.
Felipe uses process memory dumps to obtain raw user data, it then applies an algorithm to this data to identify payment card information as well as verify it is legitimate. This information is then sent to a command and control server using an Triple Data Encryption Standard (3DES) algorithm.
Remediation steps
| Type | Step |
|---|---|
|
To prevent and detect an infection, ensure that:
|
Last edited: 14 February 2020 2:47 pm