#ParsedReport
09-06-2022
Killnet: The Hactivist Group That Started A Global Cyber War
https://www.digitalshadows.com/blog-and-research/killnet-the-hactivist-group-that-started-a-global-cyber-war
Actors/Campaigns:
Killnet (tags: botnet, ddos, rat)
It_army
Ddosgung
Sakurajima
Kratos
Zarya
Threats:
Phoenix_keylogger
Mirai
Dns_amplification_technique
Industry:
Financial, Government
Geo:
Russian, Russia, Ukraine, Lithuania, Poland, Romanian, Estonia, Latvia, Italian, Germany, German, Italy, Romania
Functions Names: 1
09-06-2022
Killnet: The Hactivist Group That Started A Global Cyber War
https://www.digitalshadows.com/blog-and-research/killnet-the-hactivist-group-that-started-a-global-cyber-war
Actors/Campaigns:
Killnet (tags: botnet, ddos, rat)
It_army
Ddosgung
Sakurajima
Kratos
Zarya
Threats:
Phoenix_keylogger
Mirai
Dns_amplification_technique
Industry:
Financial, Government
Geo:
Russian, Russia, Ukraine, Lithuania, Poland, Romanian, Estonia, Latvia, Italian, Germany, German, Italy, Romania
Functions Names: 1
Digital Shadows
Killnet: The Hactivist Group That Started A Global Cyber War
We have observed an explosion in the number of distributed denial-of-service (DDoS), defacement, and data-leakage attack
#ParsedReport
09-06-2022
LockBit 2.0: How This RaaS Operates and How to Protect Against It
https://unit42.paloaltonetworks.com/lockbit-2-ransomware
Actors/Campaigns:
Darkside
Threats:
Lockbit (tags: stealer, rat, malware, spyware, ddos, ransomware, vpn, dns, scan, proxy, phishing)
Babuk
Revil
Conti
Blackcat
Avaddon
Suncrypt
Blackbyte
Cobalt_strike
Metasploit_tool
Proxyshell_vuln
Psexec_tool
Wevtutil_tool
Mimikatz
Minidump_tool
Grabchrome_tool
Grabrff_tool
Netscan_tool
Adfind_tool
Pchunter_tool
Beacon
Megasync_tool
Stealbit
Industry:
Healthcare, Education, Retail, Financial
Geo:
Latam, Russian, Japan, Japac, Germany, Apac, Italy, America, Emea
CVEs:
CVE-2021-20028 [Vulners]
Vulners: Score: 7.5, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- sonicwall sma 210 firmware (<9.0.0.10)
- sonicwall sma 410 firmware (<9.0.0.10)
- sonicwall sma 500v firmware (<9.0.0.10)
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
CVE-2020-0787 [Vulners]
Vulners: Score: 7.2, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, 1709, 1803, 1809, 1903, 1909)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2008 (-, r2, r2)
have more...
CVE-2021-34473 [Vulners]
Vulners: Score: 10.0, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
TTPs:
Tactics: 10
Technics: 27
09-06-2022
LockBit 2.0: How This RaaS Operates and How to Protect Against It
https://unit42.paloaltonetworks.com/lockbit-2-ransomware
Actors/Campaigns:
Darkside
Threats:
Lockbit (tags: stealer, rat, malware, spyware, ddos, ransomware, vpn, dns, scan, proxy, phishing)
Babuk
Revil
Conti
Blackcat
Avaddon
Suncrypt
Blackbyte
Cobalt_strike
Metasploit_tool
Proxyshell_vuln
Psexec_tool
Wevtutil_tool
Mimikatz
Minidump_tool
Grabchrome_tool
Grabrff_tool
Netscan_tool
Adfind_tool
Pchunter_tool
Beacon
Megasync_tool
Stealbit
Industry:
Healthcare, Education, Retail, Financial
Geo:
Latam, Russian, Japan, Japac, Germany, Apac, Italy, America, Emea
CVEs:
CVE-2021-20028 [Vulners]
Vulners: Score: 7.5, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Unavailable
Soft:
- sonicwall sma 210 firmware (<9.0.0.10)
- sonicwall sma 410 firmware (<9.0.0.10)
- sonicwall sma 500v firmware (<9.0.0.10)
CVE-2021-34523 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
CVE-2020-0787 [Vulners]
Vulners: Score: 7.2, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, 1709, 1803, 1809, 1903, 1909)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2008 (-, r2, r2)
have more...
CVE-2021-34473 [Vulners]
Vulners: Score: 10.0, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
TTPs:
Tactics: 10
Technics: 27
Unit 42
LockBit 2.0: How This RaaS Operates and How to Protect Against It
LockBit 2.0 has so far been this year's most active ransomware gang on double-extortion leak sites. Learn about their tactics.
#ParsedReport
09-06-2022
Andariel Group, active only in Korea, for the past two years
https://www-ahnlab-com.translate.goog/kr/site/securityinfo/secunews/secuNewsView.do?seq=31890&menu_dist=2&cmd=scrap&_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Lazarus (tags: malware, phishing, ransomware, keylogger)
Threats:
Gh0st_rat
Rifdoor
Phandoor
Tiger_downloader
Watering_hole_technique
Nukesped_rat
Tiger_rat
Geo:
Korea
IOCs:
File: 10
Functions Names: 1
09-06-2022
Andariel Group, active only in Korea, for the past two years
https://www-ahnlab-com.translate.goog/kr/site/securityinfo/secunews/secuNewsView.do?seq=31890&menu_dist=2&cmd=scrap&_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Lazarus (tags: malware, phishing, ransomware, keylogger)
Threats:
Gh0st_rat
Rifdoor
Phandoor
Tiger_downloader
Watering_hole_technique
Nukesped_rat
Tiger_rat
Geo:
Korea
IOCs:
File: 10
Functions Names: 1
www-ahnlab-com.translate.goog
보안 이슈 | AhnLab
안랩이 최신 IT 및 보안 이슈를 알기 쉽게 풀어드립니다.
#ParsedReport
09-06-2022
eSentire Threat Intelligence Malware Analysis: Purple Fox
https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-purple-fox
Threats:
Purplefox (tags: malware, rat, rootkit, proxy, dns, scan, phishing)
Rig_tool (tags: malware)
Lolbin
Hot_potato_technique
Tater_exploit
Geo:
Chinese, Africa, Apac, America, Emea
CVEs:
CVE-2018-8120 [Vulners]
Vulners: Score: 7.2, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -, r2)
- microsoft windows 7 (-)
CVE-2021-1675 [Vulners]
Vulners: Score: 9.3, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 20h2, 21h1, 1809, 1909, 2004)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
have more...
CVE-2015-1701 [Vulners]
Vulners: Score: 7.2, CVSS: 7.1,
Vulners: Exploitation: True
X-Force: Risk: 6.8
X-Force: Patch: Official fix
Soft:
- microsoft windows vista (*)
- microsoft windows 2003 server (*)
- microsoft windows server 2008 (-)
- microsoft windows 7 (le-, le-)
CVE-2020-0674 [Vulners]
Vulners: Score: 7.6, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Workaround
Soft:
- microsoft internet explorer (9, 10, 11)
CVE-2019-0808 [Vulners]
Vulners: Score: 7.2, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows 7 (sp1)
- microsoft windows server 2008 (r2, r2, -)
IOCs:
File: 10
Registry: 4
Path: 21
IP: 39
Domain: 1
Hash: 6
Url: 1
YARA: Found
Links:
09-06-2022
eSentire Threat Intelligence Malware Analysis: Purple Fox
https://www.esentire.com/blog/esentire-threat-intelligence-malware-analysis-purple-fox
Threats:
Purplefox (tags: malware, rat, rootkit, proxy, dns, scan, phishing)
Rig_tool (tags: malware)
Lolbin
Hot_potato_technique
Tater_exploit
Geo:
Chinese, Africa, Apac, America, Emea
CVEs:
CVE-2018-8120 [Vulners]
Vulners: Score: 7.2, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -, r2)
- microsoft windows 7 (-)
CVE-2021-1675 [Vulners]
Vulners: Score: 9.3, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 20h2, 21h1, 1809, 1909, 2004)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
have more...
CVE-2015-1701 [Vulners]
Vulners: Score: 7.2, CVSS: 7.1,
Vulners: Exploitation: True
X-Force: Risk: 6.8
X-Force: Patch: Official fix
Soft:
- microsoft windows vista (*)
- microsoft windows 2003 server (*)
- microsoft windows server 2008 (-)
- microsoft windows 7 (le-, le-)
CVE-2020-0674 [Vulners]
Vulners: Score: 7.6, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Workaround
Soft:
- microsoft internet explorer (9, 10, 11)
CVE-2019-0808 [Vulners]
Vulners: Score: 7.2, CVSS: 6.2,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows 7 (sp1)
- microsoft windows server 2008 (r2, r2, -)
IOCs:
File: 10
Registry: 4
Path: 21
IP: 39
Domain: 1
Hash: 6
Url: 1
YARA: Found
Links:
https://github.com/Kevin-Robertson/Taterhttps://github.com/k8gege/K8toolseSentire
eSentire Threat Intelligence Malware Analysis: Purple Fox
Dive deeper into the technical details gathered during eSentire’s Threat Response Unit (TRU) team’s research and threat analysis of the Purple Fox malware.
#ParsedReport
10-06-2022
Lyceum .NET DNSBackdoor. Key Features of this attack:
https://www.zscaler.com/blogs/security-research/lyceum-net-dns-backdoor
Actors/Campaigns:
Siamesekitten (tags: dns, backdoor, malware)
Threats:
Dnsbackdoor (tags: dns, backdoor, malware)
Industry:
Energy, Telco
Geo:
Iran, Iranian
TTPs:
Tactics: 1
Technics: 7
IOCs:
File: 5
Url: 5
Hash: 2
Domain: 1
IP: 2
Functions Names: 6
10-06-2022
Lyceum .NET DNSBackdoor. Key Features of this attack:
https://www.zscaler.com/blogs/security-research/lyceum-net-dns-backdoor
Actors/Campaigns:
Siamesekitten (tags: dns, backdoor, malware)
Threats:
Dnsbackdoor (tags: dns, backdoor, malware)
Industry:
Energy, Telco
Geo:
Iran, Iranian
TTPs:
Tactics: 1
Technics: 7
IOCs:
File: 5
Url: 5
Hash: 2
Domain: 1
IP: 2
Functions Names: 6
Zscaler
Lyceum .NET DNS Backdoor | Zscaler
The Lyceum APT group is targeting Middle East organizations with DNS hijacking attack using a new .NET-based malware.
#ParsedReport
10-06-2022
Bumblebee Loader Linked to Conti and Used In Quantum Locker Attacks
https://www.kroll.com/en/insights/publications/cyber/bumblebee-loader-linked-conti-used-in-quantum-locker-attacks
Actors/Campaigns:
Exotic_lily
Ta578
Ta579
Threats:
Quantum_locker (tags: spam, phishing, trojan, malware, ransomware)
Bumblebee (tags: spam, phishing, trojan, malware, ransomware)
Conti (tags: spam, phishing, trojan, malware, ransomware)
Cobalt_strike
Emotet
Icedid
Ryuk
Gozi
Meterpreter_tool
Sliver_tool
Bazarbackdoor
Industry:
Healthcare
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
Links:
10-06-2022
Bumblebee Loader Linked to Conti and Used In Quantum Locker Attacks
https://www.kroll.com/en/insights/publications/cyber/bumblebee-loader-linked-conti-used-in-quantum-locker-attacks
Actors/Campaigns:
Exotic_lily
Ta578
Ta579
Threats:
Quantum_locker (tags: spam, phishing, trojan, malware, ransomware)
Bumblebee (tags: spam, phishing, trojan, malware, ransomware)
Conti (tags: spam, phishing, trojan, malware, ransomware)
Cobalt_strike
Emotet
Icedid
Ryuk
Gozi
Meterpreter_tool
Sliver_tool
Bazarbackdoor
Industry:
Healthcare
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.1,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
Links:
https://github.com/LordNoteworthy/al-khaser/tree/06d4a89e9ecc3e49e4d2df67fe0b2d6faf04166eKroll
Bumblebee Loader Linked to Conti and Used In Quantum Locker Attacks | Kroll
Kroll has recently observed a new malware strain called “Bumblebee” operating as a loader, delivered via phishing email, in order to deploy additional payloads for use in ransomware operations. Read more.
#ParsedReport
10-06-2022
Smilodon Credit Card Skimming Malware Shifts to WordPress
https://blog.sucuri.net/2022/06/smilodon-credit-card-skimming-malware-shifts-to-wordpress.html
Actors/Campaigns:
Magecart (tags: malware)
Threats:
Megalodon (tags: malware, rat, backdoor)
Industry:
E-commerce, Financial
IOCs:
Domain: 3
Functions Names: 1
10-06-2022
Smilodon Credit Card Skimming Malware Shifts to WordPress
https://blog.sucuri.net/2022/06/smilodon-credit-card-skimming-malware-shifts-to-wordpress.html
Actors/Campaigns:
Magecart (tags: malware)
Threats:
Megalodon (tags: malware, rat, backdoor)
Industry:
E-commerce, Financial
IOCs:
Domain: 3
Functions Names: 1
Sucuri Blog
Smilodon Credit Card Skimming Malware Shifts to WordPress
WordPress’ massive market share has come with an unsurprising side effect: As more and more site admins turn to popular plugins like WooCommerce to turn…
#ParsedReport
10-06-2022
BAT (//)
https://asec-ahnlab-com.translate.goog/ko/35189/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
IOCs:
File: 6
Hash: 13
10-06-2022
BAT (//)
https://asec-ahnlab-com.translate.goog/ko/35189/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
IOCs:
File: 6
Hash: 13
ASEC BLOG
활발하게 유포 중인 BAT 스크립트 포함한 악성 한글문서 (북한/국방/방송) - ASEC BLOG
ASEC 분석팀은 한글 문서의 정상 기능(OLE 개체 연결 삽입)을 악용하는 APT 문서가 최근 활발하게 유포 중임을 확인하였다. 지난 3월 3일 소개한 “20대 대통령선거 선상투표 보도자료 가장한 악성 한글문서 유포” 사례 이후로 공격자는 국방, 대북, 방송 관계자들을 대상으로 지속적으로 악성 한글 문서를 유포하고있다. 악성 한글 문서의 동작 방식은 한글 문서 안에 삽입된 OLE 개체(배치파일)가 실행되고, 이후 파워쉘을 통해 쉘코드를 정상 프로세스에…
#ParsedReport
10-06-2022
Back From the Dead, Emotet Returns in 2022
https://www.deepinstinct.com/blog/emotet-malware-returns-in-2022
Actors/Campaigns:
Wizard_spider (tags: malware)
Threats:
Emotet (tags: malware, botnet, rat, phishing, trojan, ransomware)
Conti
Ryuk
Trickbot (tags: malware)
Qakbot
Chaos (tags: phishing, malware)
Industry:
Financial
Geo:
Japanese, Netherlands
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 8.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
10-06-2022
Back From the Dead, Emotet Returns in 2022
https://www.deepinstinct.com/blog/emotet-malware-returns-in-2022
Actors/Campaigns:
Wizard_spider (tags: malware)
Threats:
Emotet (tags: malware, botnet, rat, phishing, trojan, ransomware)
Conti
Ryuk
Trickbot (tags: malware)
Qakbot
Chaos (tags: phishing, malware)
Industry:
Financial
Geo:
Japanese, Netherlands
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 8.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
Deep Instinct
Emotet Malware Returns in 2022 | Deep Instinct
Emotet malware has returned with a vengeance in 2022. How dangerous are new emotet variants? Learn more about the newest Emotet threats & how Deep Instinct can help.
#ParsedReport
10-06-2022
SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center SANS Site Network Current Site SANS Internet Storm Center Other SANS Sites Help Graduate Degree Programs Security Training Security Certification Security Awareness Training Penetration Testing Industrial Control Systems Cyber Defense Foundations DFIR Software Security Government OnSite Training InfoSec Handlers Diary Blog
https://isc.sans.edu/diary/rss/28728
Actors/Campaigns:
Ta570 (tags: spam, malware)
Threats:
Qakbot (tags: spam, malware)
Follina_vuln (tags: spam, malware)
Industry:
Government
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 59
Hash: 49
Path: 1
Url: 4
10-06-2022
SANS ISC: InfoSec Handlers Diary Blog - SANS Internet Storm Center SANS Site Network Current Site SANS Internet Storm Center Other SANS Sites Help Graduate Degree Programs Security Training Security Certification Security Awareness Training Penetration Testing Industrial Control Systems Cyber Defense Foundations DFIR Software Security Government OnSite Training InfoSec Handlers Diary Blog
https://isc.sans.edu/diary/rss/28728
Actors/Campaigns:
Ta570 (tags: spam, malware)
Threats:
Qakbot (tags: spam, malware)
Follina_vuln (tags: spam, malware)
Industry:
Government
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 59
Hash: 49
Path: 1
Url: 4
SANS Internet Storm Center
InfoSec Handlers Diary Blog - SANS Internet Storm Center
Internet Storm Center Diary 2022-09-13, Author: Johannes Ullrich
#ParsedReport
10-06-2022
Phishing Campaigns featuring Ursnif Trojan on the Rise
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/phishing-campaigns-featuring-ursnif-trojan/?&web_view=true
Threats:
Gozi (tags: spam, rat, trojan, phishing, malware)
Dexter
Emotet
Hancitor
Ficker_stealer
TTPs:
Tactics: 3
Technics: 4
IOCs:
File: 4
Url: 1
Hash: 2
Functions Names: 2
10-06-2022
Phishing Campaigns featuring Ursnif Trojan on the Rise
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/phishing-campaigns-featuring-ursnif-trojan/?&web_view=true
Threats:
Gozi (tags: spam, rat, trojan, phishing, malware)
Dexter
Emotet
Hancitor
Ficker_stealer
TTPs:
Tactics: 3
Technics: 4
IOCs:
File: 4
Url: 1
Hash: 2
Functions Names: 2
McAfee Blog
Phishing Campaigns featuring Ursnif Trojan on the Rise | McAfee Blog
Authored by Jyothi Naveen and Kiran Raj McAfee Labs have been observing a spike in phishing campaigns that utilize Microsoft office macro capabilities.
#ParsedReport
10-06-2022
Instagram credentials Stealers: Free Followers or Free Likes
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/instagram-credentials-stealers-free-followers-or-free-likes
Threats:
Dexter
Emotet
Hancitor
Ficker_stealer
Geo:
Turkey, Portuguese
IOCs:
Hash: 2
10-06-2022
Instagram credentials Stealers: Free Followers or Free Likes
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/instagram-credentials-stealers-free-followers-or-free-likes
Threats:
Dexter
Emotet
Hancitor
Ficker_stealer
Geo:
Turkey, Portuguese
IOCs:
Hash: 2
McAfee Blog
Instagram credentials Stealers: Free Followers or Free Likes | McAfee Blog
Authored by Dexter Shin Instagram has become a platform with over a billion monthly active users. Many of Instagram's users are looking to increase their
#ParsedReport
10-06-2022
Instagram credentials Stealer: Disguised as Mod App
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/instagram-credentials-stealer-disguised-as-mod-app
Threats:
Dexter (tags: stealer)
Emotet
Hancitor
Ficker_stealer
IOCs:
Email: 1
Hash: 1
10-06-2022
Instagram credentials Stealer: Disguised as Mod App
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/instagram-credentials-stealer-disguised-as-mod-app
Threats:
Dexter (tags: stealer)
Emotet
Hancitor
Ficker_stealer
IOCs:
Email: 1
Hash: 1
McAfee Blog
Instagram credentials Stealer: Disguised as Mod App | McAfee Blog
Authored by Dexter Shin McAfee’s Mobile Research Team introduced a new Android malware targeting Instagram users who want to increase their followers or
#ParsedReport
10-06-2022
Yashma Ransomware Report
https://www.cyfirma.com/outofband/yashma-ransomware-report
Threats:
Yashma (tags: ddos, malware, ransomware, spam, phishing, rat)
Chaos (tags: ransomware)
Geo:
Turkey, Azerbaijan
TTPs:
Tactics: 6
Technics: 12
IOCs:
File: 2
Hash: 1
10-06-2022
Yashma Ransomware Report
https://www.cyfirma.com/outofband/yashma-ransomware-report
Threats:
Yashma (tags: ddos, malware, ransomware, spam, phishing, rat)
Chaos (tags: ransomware)
Geo:
Turkey, Azerbaijan
TTPs:
Tactics: 6
Technics: 12
IOCs:
File: 2
Hash: 1
CYFIRMA
Yashma Ransomware Report - CYFIRMA
Yashma Ransomware Report Executive Summary: Yashma is a new ransomware seen in the wild since May 2022. This ransomware is...
#technique
PACMAN is a new attack technique demonstrated against Apple M1 processor chipsets that could be used to hack macOS systems.
https://securityaffairs.co/wordpress/132154/hacking/pacman-attack-apple-m1-cpus.html
PACMAN is a new attack technique demonstrated against Apple M1 processor chipsets that could be used to hack macOS systems.
https://securityaffairs.co/wordpress/132154/hacking/pacman-attack-apple-m1-cpus.html
Security Affairs
PACMAN, a new attack technique against Apple M1 CPUs
PACMAN is a new attack technique demonstrated against Apple M1 processor chipsets that could be used to hack macOS systems.
#ParsedReport
12-06-2022
Confluence servers hacked to deploy AvosLocker, Cerber2021 ransomware
https://www.bleepingcomputer.com/news/security/confluence-servers-hacked-to-deploy-avoslocker-cerber2021-ransomware
Threats:
Avoslocker (tags: scan, ransomware, cryptomining, malware, botnet, rat)
Cerberimposter (tags: ransomware, botnet, cryptomining, malware, scan, rat)
Cerber (tags: ransomware)
Geo:
Australia
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: Unknown, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
CVE-2021-26084 [Vulners]
Vulners: Score: 7.5, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence server (<7.12.5, <7.4.11, <7.11.6, <6.13.23)
- atlassian confluence data center (<7.12.5, <7.11.6, <7.4.11, <6.13.23)
12-06-2022
Confluence servers hacked to deploy AvosLocker, Cerber2021 ransomware
https://www.bleepingcomputer.com/news/security/confluence-servers-hacked-to-deploy-avoslocker-cerber2021-ransomware
Threats:
Avoslocker (tags: scan, ransomware, cryptomining, malware, botnet, rat)
Cerberimposter (tags: ransomware, botnet, cryptomining, malware, scan, rat)
Cerber (tags: ransomware)
Geo:
Australia
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: Unknown, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
CVE-2021-26084 [Vulners]
Vulners: Score: 7.5, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence server (<7.12.5, <7.4.11, <7.11.6, <6.13.23)
- atlassian confluence data center (<7.12.5, <7.11.6, <7.4.11, <6.13.23)
BleepingComputer
Confluence servers hacked to deploy AvosLocker, Cerber2021 ransomware
Ransomware gangs are now targeting a recently patched and actively exploited remote code execution (RCE) vulnerability affecting Atlassian Confluence Server and Data Center instances for initial access to corporate networks.
#ParsedReport
12-06-2022
Exposing HelloXD Ransomware and x4k
https://unit42.paloaltonetworks.com/helloxd-ransomware
Actors/Campaigns:
Lapsus (tags: ransomware)
Threats:
Helloxd (tags: malware, backdoor, ddos, dns, ransomware, rat)
Babuk (tags: ransomware)
Microbackdoor (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Lockbit (tags: malware, ransomware)
Industry:
Financial
Geo:
Apac, Emea, Japan, America, Russia, Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
IP: 7
File: 3
Hash: 59
Email: 1
Domain: 56
Links:
12-06-2022
Exposing HelloXD Ransomware and x4k
https://unit42.paloaltonetworks.com/helloxd-ransomware
Actors/Campaigns:
Lapsus (tags: ransomware)
Threats:
Helloxd (tags: malware, backdoor, ddos, dns, ransomware, rat)
Babuk (tags: ransomware)
Microbackdoor (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Lockbit (tags: malware, ransomware)
Industry:
Financial
Geo:
Apac, Emea, Japan, America, Russia, Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
IP: 7
File: 3
Hash: 59
Email: 1
Domain: 56
Links:
https://github.com/l4ckyguyhttps://github.com/byt3bl33d3r/OffensiveNim/blob/master/src/self\_delete\_bin.nimhttps://github.com/l4cky-controlhttps://github.com/x4kmehttps://github.com/vbdaga/Rabbit-CipherUnit 42
Exposing HelloXD Ransomware and x4k
HelloXD is a ransomware family in its initial stages – but already seeking to impact organizations. We analyze samples and hunt for attribution.
#ParsedReport
12-06-2022
Smilodon Credit Card Skimming Malware Shifts to WordPress
https://blog.sucuri.net/2022/06/smilodon-credit-card-skimming-malware-shifts-to-wordpress.html
Actors/Campaigns:
Magecart (tags: malware)
Threats:
Megalodon (tags: rat, backdoor, malware)
Industry:
E-commerce, Financial
IOCs:
Domain: 3
Functions Names: 1
12-06-2022
Smilodon Credit Card Skimming Malware Shifts to WordPress
https://blog.sucuri.net/2022/06/smilodon-credit-card-skimming-malware-shifts-to-wordpress.html
Actors/Campaigns:
Magecart (tags: malware)
Threats:
Megalodon (tags: rat, backdoor, malware)
Industry:
E-commerce, Financial
IOCs:
Domain: 3
Functions Names: 1
Sucuri Blog
Smilodon Credit Card Skimming Malware Shifts to WordPress
WordPress’ massive market share has come with an unsurprising side effect: As more and more site admins turn to popular plugins like WooCommerce to turn…
#ParsedReport
13-06-2022
Hydra Android Malware Distributed Via Play Store. Fake Document Manager App Downloading Hydra Banking Trojan
https://blog.cyble.com/2022/06/13/hydra-android-malware-distributed-via-play-store
Threats:
Hydra (tags: malware, trojan, phishing, proxy)
Industry:
Financial
Geo:
Colombia
TTPs:
Tactics: 6
Technics: 2
IOCs:
Url: 6
File: 2
Hash: 2
13-06-2022
Hydra Android Malware Distributed Via Play Store. Fake Document Manager App Downloading Hydra Banking Trojan
https://blog.cyble.com/2022/06/13/hydra-android-malware-distributed-via-play-store
Threats:
Hydra (tags: malware, trojan, phishing, proxy)
Industry:
Financial
Geo:
Colombia
TTPs:
Tactics: 6
Technics: 2
IOCs:
Url: 6
File: 2
Hash: 2
Cyble
Cyble - Fake Document Manager App Downloading Hydra Banking Trojan
Cyble analyzes a resurfaced version of Hydra malware distributed via a fake Document Manager app on the Play Store.
#ParsedReport
13-06-2022
Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Key points
https://www.zscaler.com/blogs/security-research/technical-analysis-purecrypter
Threats:
Purecrypter (tags: ransomware, malware, stealer, rat)
Binder
Agent_tesla
Arkei_stealer
Asyncrat_rat
Azorult
Dcrat_rat
Nanocore_rat
Redline_stealer
Remcos_rat
Snake_keylogger
Avemaria_rat
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 57
File: 13
Url: 17
Registry: 4
Path: 1
Functions Names: 4
13-06-2022
Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers. Key points
https://www.zscaler.com/blogs/security-research/technical-analysis-purecrypter
Threats:
Purecrypter (tags: ransomware, malware, stealer, rat)
Binder
Agent_tesla
Arkei_stealer
Asyncrat_rat
Azorult
Dcrat_rat
Nanocore_rat
Redline_stealer
Remcos_rat
Snake_keylogger
Avemaria_rat
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 57
File: 13
Url: 17
Registry: 4
Path: 1
Functions Names: 4
Zscaler
Technical Analysis of PureCrypter | Zscaler Blog
Technical Analysis of PureCrypter: A Fully-Functional Loader Distributing Remote Access Trojans and Information Stealers