14/07/2022
Other methods adopted by the group include code obfuscation, introducing new layers in the attack chain from initial compromise to ex*****on, and using multiple URLs as well as unknown file extensions (e.g., .OCX, .ooccxx, .dat, or .gyp) to deliver the payload.