Onusman_2022-10-31_update.zip -
The file is associated with a specific campaign involving the Onusman (also known as OnuSman or OnuSman-Stealer) malware . This particular update surfaced around late October 2022, primarily targeting Windows environments to exfiltrate sensitive data. Executive Summary
Outbound traffic to api.telegram.org or specific suspicious IP addresses associated with "Onusman" hosting. Onusman_2022-10-31_update.zip
Disconnect the affected machine from the network immediately. The file is associated with a specific campaign
