Cybersecurity researchers have discovered new attacks targeting various Israeli entities with publicly available frameworks such as Donut and Sliver.

According to a report by HarfangLab, these attacks appear to be highly targeted, leveraging specific infrastructure and custom WordPress websites as a malicious payload delivery mechanism. However, they affect a variety of entities in unrelated industries and rely on known open source malware.
HarfangLab is tracking activity under the name “Supposed Grasshopper.” It is a reference to a server controlled by the attackers (“auth.economy-gov-il[.]com/SUPPOSED_GRASSHOPPER.bin”), to which a first-stage downloader connects.
See also: New Unfurling Hemlock floods systems with malware
This downloader, written in Nim, is used to download the second-stage malware from the staging server. It is delivered via a virtual hard disk (VHD) file, which is likely distributed via custom WordPress sites, as part of a drive-by download scheme.
The second-stage payload, retrieved from the server, is Donut, a shellcode generation framework, which serves as a pipeline for the development of Sliver, a Cobalt Strike alternative.
Researchers observed that the attackers also attempted to infiltrate infrastructure and deploy a realistic WordPress website to deliver payloads.
The ultimate goal of the Donut and Sliver frameworks campaign is currently unknown, although HarfangLab said it could be related to a legitimate penetration testing. However, if this is the case, it raises questions about the transparency and impersonation of Israeli government agencies.
See also: Mac users exposed to info-stealer malware via Google Ads
What measures can be taken to protect against these attacks?
training . and awareness Employees need to be aware of the latest techniques used by attackers and know how to recognize suspicious activity.
Regularly updating and upgrading systems and security software can also prevent many attacks. Attackers often exploit known security vulnerabilities that have been fixed in newer versions.

Implementing layered security (defense in depth) can provide additional protection. This includes the use of firewalls, antivirus, intrusion detection systems (IDS), and other security tools that work together to detect and prevent attacks.
See also: Why is Temu considered “dangerous malware”?
Regularly conducting security audits and penetration testing can help identify vulnerabilities before they are exploited by attackers. Organizations can then fix the issues identified during these audits.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Using strong and unique passwords for every system and app is also essential. Additionally, implementing multi-factor authentication (MFA) can add an extra layer of security.
Finally, collaborating with specialized security consultants and participating in cybersecurity information sharing communities can provide valuable information (e.g., on Donut and Sliver frameworks) and help develop better defense strategies.
Source: thehackernews.com
