The MOONSHINE Exploit Kit and the DarkNimbus Backdoor in the DNS Spotlight
While it may not be the first time the Earth Minotaur attackers used the MOONSHINE exploit kit to trail after targets, upping its capabilities with the addition of DarkNimbus delivery may be a novel tactic.1
Fellow threat researchers already identified 53 indicators of compromise (IoCs) related to the latest Earth Minotaur attack.2
The WhoisXML API research team dove deep into the threat aided by our comprehensive DNS intelligence and uncovered additional artifacts comprising: