#ParsedReport
16-06-2022
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach
Actors/Campaigns:
Driftingcloud (tags: vpn, malware, backdoor, rat, dns)
Threats:
Behinder
Sliver_tool
Pupy_rat
Geo:
China, Chinese, Asia
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-1040 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sophos sfos (le18.5.3)
IOCs:
File: 5
Url: 1
Domain: 4
IP: 8
Functions Names: 3
YARA: Found
Links:
16-06-2022
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
https://www.volexity.com/blog/2022/06/15/driftingcloud-zero-day-sophos-firewall-exploitation-and-an-insidious-breach
Actors/Campaigns:
Driftingcloud (tags: vpn, malware, backdoor, rat, dns)
Threats:
Behinder
Sliver_tool
Pupy_rat
Geo:
China, Chinese, Asia
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-1040 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sophos sfos (le18.5.3)
IOCs:
File: 5
Url: 1
Domain: 4
IP: 8
Functions Names: 3
YARA: Found
Links:
https://github.com/gooogleapis/gooogleapishttps://github.com/Konloch/bytecode-viewerhttps://github.com/epinna/weevely3/blob/master/bd/agents/obfpost\_php.tplhttps://github.com/cassanof/pantegana/blob/master/Makefile#L12https://github.com/BishopFox/sliverhttps://github.com/cassanof/panteganahttps://github.com/volexity/threat-intel/blob/main/2022/2022-06-15%20DriftingCloud%20-%20Zero-Day%20Sophos%20Firewall%20Exploitation%20and%20an%20Insidious%20Breach/indicators/indicators.csvhttps://github.com/MountCloud/BehinderClientSource/blob/master/src/main/java/net/rebeyond/behinder/payload/java/SocksProxy.javahttps://github.com/berdav/CVE-2021-4034https://github.com/n1nj4sec/pupyhttps://github.com/volexity/threat-intel/blob/main/2022/2022-06-15%20DriftingCloud%20-%20Zero-Day%20Sophos%20Firewall%20Exploitation%20and%20an%20Insidious%20Breach/indicators/yara.yarVolexity
DriftingCloud: Zero-Day Sophos Firewall Exploitation and an Insidious Breach
Volexity frequently works with individuals and organizations heavily targeted by sophisticated, motivated, and well-equipped threat actors from around the world. Some of these individuals or organizations are attacked infrequently or […]
#ParsedReport
16-06-2022
Confluence exploits used to drop ransomware on vulnerable servers
https://news.sophos.com/en-us/2022/06/16/confluence-exploits-used-to-drop-ransomware-on-vulnerable-servers
Threats:
Cerber (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Cobalt_strike (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
IOCs:
File: 1
Links:
16-06-2022
Confluence exploits used to drop ransomware on vulnerable servers
https://news.sophos.com/en-us/2022/06/16/confluence-exploits-used-to-drop-ransomware-on-vulnerable-servers
Threats:
Cerber (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Cobalt_strike (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
IOCs:
File: 1
Links:
https://github.com/sophoslabs/IoCs/blob/master/CVE-2022-26134\_attacks.csvSophos News
Confluence exploits used to drop ransomware on vulnerable servers
Automated attacks are now widely exploiting the Atlassian vulnerability
#ParsedReport
16-06-2022
Panchans Mining Rig: New Golang Peer-to-Peer Botnet Says Hi!
https://www.akamai.com/blog/security/new-p2p-botnet-panchan
Threats:
Rig_tool (tags: botnet, malware, cryptomining)
Panchan_botnet
Cryptojacker
Xmrig_miner (tags: cryptomining)
Industry:
Financial, Telco, Education
Geo:
Asia, Japanese, Taiwan, Spain
TTPs:
Tactics: 1
Technics: 0
YARA: Found
Links:
16-06-2022
Panchans Mining Rig: New Golang Peer-to-Peer Botnet Says Hi!
https://www.akamai.com/blog/security/new-p2p-botnet-panchan
Threats:
Rig_tool (tags: botnet, malware, cryptomining)
Panchan_botnet
Cryptojacker
Xmrig_miner (tags: cryptomining)
Industry:
Financial, Telco, Education
Geo:
Asia, Japanese, Taiwan, Spain
TTPs:
Tactics: 1
Technics: 0
YARA: Found
Links:
https://github.com/akamai/akamai-security-research/tree/main/malware/panchanAkamai
Akamai Blog | Panchan’s Mining Rig: New Golang Peer-to-Peer Botnet Says “Hi!”
Akamai researchers have discovered a new P2P botnet targeting APJ. Read about it here.
#ParsedReport
16-06-2022
F5 Labs Investigates MaliBot
https://www.f5.com/labs/articles/threat-intelligence/f5-labs-investigates-malibot
Threats:
Malibot (tags: trojan, malware, rat, phishing, stealer, ransomware, dns)
Flubot
Sharkbot
Industry:
Government, Iot, Education, E-commerce, Financial
Geo:
African, Spanish, Italian, Russia, Spain, Italy
IOCs:
Url: 6
Hash: 4
IP: 1
File: 7
Domain: 2
Functions Names: 1
16-06-2022
F5 Labs Investigates MaliBot
https://www.f5.com/labs/articles/threat-intelligence/f5-labs-investigates-malibot
Threats:
Malibot (tags: trojan, malware, rat, phishing, stealer, ransomware, dns)
Flubot
Sharkbot
Industry:
Government, Iot, Education, E-commerce, Financial
Geo:
African, Spanish, Italian, Russia, Spain, Italy
IOCs:
Url: 6
Hash: 4
IP: 1
File: 7
Domain: 2
Functions Names: 1
F5
F5 Labs Investigates MaliBot
We found a novel malware strain that is targeting financial sites in Italy and Spain... so far.
👍1
#ParsedReport
17-06-2022
Malicious HWP Files with BAT Scripts Being Distributed Actively (North Korea/National Defense/Broadcasting)
https://asec.ahnlab.com/en/35405
Actors/Campaigns:
Kimsuky (tags: malware)
Geo:
Korea, Asia
IOCs:
File: 11
Hash: 13
17-06-2022
Malicious HWP Files with BAT Scripts Being Distributed Actively (North Korea/National Defense/Broadcasting)
https://asec.ahnlab.com/en/35405
Actors/Campaigns:
Kimsuky (tags: malware)
Geo:
Korea, Asia
IOCs:
File: 11
Hash: 13
ASEC BLOG
Malicious HWP Files with BAT Scripts Being Distributed Actively (North Korea/National Defense/Broadcasting) - ASEC BLOG
The ASEC analysis team has discovered the active distribution of APT files that are exploiting a feature of HWP files (OLE object insertion) recently. After the case introduced in the post “Malicious HWP File Disguised as Press Release of 20th Presidential…
#ParsedReport
17-06-2022
ASEC Weekly Malware Statistics (June 6th, 2022 June 12th, 2022)
https://asec.ahnlab.com/en/35424
Threats:
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Agent_tesla (tags: malware)
Formbook (tags: malware)
Lokibot_stealer (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)
Industry:
Transport, Financial
Geo:
Usa
IOCs:
Domain: 2
IP: 2
Email: 2
File: 30
Url: 43
17-06-2022
ASEC Weekly Malware Statistics (June 6th, 2022 June 12th, 2022)
https://asec.ahnlab.com/en/35424
Threats:
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Agent_tesla (tags: malware)
Formbook (tags: malware)
Lokibot_stealer (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)
Industry:
Transport, Financial
Geo:
Usa
IOCs:
Domain: 2
IP: 2
Email: 2
File: 30
Url: 43
ASEC
ASEC Weekly Malware Statistics (June 6th, 2022 - June 12th, 2022) - ASEC
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from June 6th, 2022 (Monday) to June 12th, 2022 (Sunday). For the main category, banking malware…
#ParsedReport
17-06-2022
Cerber2021 Ransomware Back in Action. Sophisticated Ransomware targeting Windows and Linux Users
https://blog.cyble.com/2022/06/17/cerber2021-ransomware-back-in-action
Threats:
Cerberimposter (tags: ransomware, malware, rat)
Cerber (tags: ransomware)
Gandcrab (tags: ransomware)
Samsam (tags: ransomware)
Blackrouter (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2021-22205 [Vulners]
Vulners: Score: 7.5, CVSS: 5.6,
Vulners: Exploitation: True
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- gitlab (<13.8.8, <13.8.8, <13.9.6, <13.9.6, <13.10.3, <13.10.3)
CVE-2021-26084 [Vulners]
Vulners: Score: 7.5, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence server (<7.12.5, <7.4.11, <7.11.6, <6.13.23)
- atlassian confluence data center (<7.12.5, <7.11.6, <7.4.11, <6.13.23)
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 4
Technics: 6
IOCs:
Url: 1
Hash: 3
Functions Names: 1
Links:
17-06-2022
Cerber2021 Ransomware Back in Action. Sophisticated Ransomware targeting Windows and Linux Users
https://blog.cyble.com/2022/06/17/cerber2021-ransomware-back-in-action
Threats:
Cerberimposter (tags: ransomware, malware, rat)
Cerber (tags: ransomware)
Gandcrab (tags: ransomware)
Samsam (tags: ransomware)
Blackrouter (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2021-22205 [Vulners]
Vulners: Score: 7.5, CVSS: 5.6,
Vulners: Exploitation: True
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- gitlab (<13.8.8, <13.8.8, <13.9.6, <13.9.6, <13.10.3, <13.10.3)
CVE-2021-26084 [Vulners]
Vulners: Score: 7.5, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence server (<7.12.5, <7.4.11, <7.11.6, <6.13.23)
- atlassian confluence data center (<7.12.5, <7.11.6, <7.4.11, <6.13.23)
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 4
Technics: 6
IOCs:
Url: 1
Hash: 3
Functions Names: 1
Links:
https://github.com/weidai11/cryptoppCyble
Cerber2021 Ransomware Back in Action
Cyble Research Labs analyzes Cerber2021 Ransomware - a potential rebrand of the popular Cerber Ransomware family.
#ParsedReport
17-06-2022
Lookout Uncovers Android Spyware Deployed in Kazakhstan
https://www.lookout.com/blog/hermit-spyware-discovery
Actors/Campaigns:
Memento (tags: rat)
Threats:
Hermit (tags: malware, spyware, rat, phishing)
Chrysaor
Finfisher
Industry:
Government, Telco, Financial
Geo:
Syria, Pakistan, Bangladesh, Chinese, Syrian, Berlin, Turkmenistan, Chile, Italy, Italian, German, Mongolia, Turkey, Kazakhstans, Kazakhstan, Myanmar, Vietnam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 1
IP: 10
Domain: 17
Hash: 8
17-06-2022
Lookout Uncovers Android Spyware Deployed in Kazakhstan
https://www.lookout.com/blog/hermit-spyware-discovery
Actors/Campaigns:
Memento (tags: rat)
Threats:
Hermit (tags: malware, spyware, rat, phishing)
Chrysaor
Finfisher
Industry:
Government, Telco, Financial
Geo:
Syria, Pakistan, Bangladesh, Chinese, Syrian, Berlin, Turkmenistan, Chile, Italy, Italian, German, Mongolia, Turkey, Kazakhstans, Kazakhstan, Myanmar, Vietnam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 1
IP: 10
Domain: 17
Hash: 8
Lookout
Lookout Uncovers Hermit Spyware Deployed in Kazakhstan | Threat Intel
Lookout researchers have uncovered enterprise-grade Android surveillanceware used by the government of Kazakhstan within its borders.
#ParsedReport
17-06-2022
Raccoon Stealer is Back with a New Version. Executive Summary
https://medium.com/s2wblog/raccoon-stealer-is-back-with-a-new-version-5f436e04b20d
Threats:
Raccoon_stealer (tags: cryptomining, malware, stealer, rat)
Redline_stealer
Fakecrack
Exodus
Vidar_stealer
Kpot_stealer
Geo:
Korean
IOCs:
Hash: 47
Domain: 1
File: 13
Coin: 3
Path: 5
IP: 1
Functions Names: 1
17-06-2022
Raccoon Stealer is Back with a New Version. Executive Summary
https://medium.com/s2wblog/raccoon-stealer-is-back-with-a-new-version-5f436e04b20d
Threats:
Raccoon_stealer (tags: cryptomining, malware, stealer, rat)
Redline_stealer
Fakecrack
Exodus
Vidar_stealer
Kpot_stealer
Geo:
Korean
IOCs:
Hash: 47
Domain: 1
File: 13
Coin: 3
Path: 5
IP: 1
Functions Names: 1
Medium
Raccoon Stealer is Back with a New Version
Author: S2W TALON
#ParsedReport
17-06-2022
'Dark Elephant': A Decade of Cyber Attacks
https://mp-weixin-qq-com.translate.goog/s/mC5D8kFaQA-cIcw2rlTgeA?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
Actors/Campaigns:
Darkelephant
Modified_elephant
Threats:
Harpoon
Netwire_rat
Darkcomet_rat
Parallax_rat
Geo:
India, China, Pakistan
CVEs:
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
IOCs:
File: 14
17-06-2022
'Dark Elephant': A Decade of Cyber Attacks
https://mp-weixin-qq-com.translate.goog/s/mC5D8kFaQA-cIcw2rlTgeA?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
Actors/Campaigns:
Darkelephant
Modified_elephant
Threats:
Harpoon
Netwire_rat
Darkcomet_rat
Parallax_rat
Geo:
India, China, Pakistan
CVEs:
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
IOCs:
File: 14
微信公众平台
“暗象”组织:潜藏十年的网络攻击
安天披露印度“暗象”组织针对我国及南亚国家的网络窃密活动。
#ParsedReport
17-06-2022
Sophisticated Phishing Toolkit Dubbed NakedPages for Sale on Cybercrime Forums
https://cloudsek.com/threatintelligence/sophisticated-phishing-toolkit-dubbed-nakedpages-for-sale-on-cybercrime-forums
Threats:
Nakedpages_tool
Industry:
E-commerce
Geo:
India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
17-06-2022
Sophisticated Phishing Toolkit Dubbed NakedPages for Sale on Cybercrime Forums
https://cloudsek.com/threatintelligence/sophisticated-phishing-toolkit-dubbed-nakedpages-for-sale-on-cybercrime-forums
Threats:
Nakedpages_tool
Industry:
E-commerce
Geo:
India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Cloudsek
Sophisticated Phishing Toolkit Dubbed “NakedPages” for Sale on Cybercrime Forums | Threat Intelligence | CloudSEK
XVigil discovered a threat actor advertising a “battle-tested” reverse proxy/PHP phishing app called “NakedPages”, on a cybercrime forum.
#ParsedReport
17-06-2022
Latin American Governments Targeted By Ransomware
https://www.recordedfuture.com/latin-american-governments-targeted-by-ransomware
Actors/Campaigns:
Zirochka
Wazawaka
Threats:
Conti (tags: ransomware)
Blackcat (tags: ransomware)
Lockbit (tags: ransomware)
Blackbyte (tags: ransomware)
Industry:
Government, Ics, Healthcare, Education, E-commerce, Financial
Geo:
Latam, Brazilian, Colombia, Russian, Peru, Mexico, Ukraine, Russia, Panama, Brazil, Ecuador, Chile, America, Argentina, Uruguay, American
TTPs:
IOCs:
Domain: 10
YARA: Found
17-06-2022
Latin American Governments Targeted By Ransomware
https://www.recordedfuture.com/latin-american-governments-targeted-by-ransomware
Actors/Campaigns:
Zirochka
Wazawaka
Threats:
Conti (tags: ransomware)
Blackcat (tags: ransomware)
Lockbit (tags: ransomware)
Blackbyte (tags: ransomware)
Industry:
Government, Ics, Healthcare, Education, E-commerce, Financial
Geo:
Latam, Brazilian, Colombia, Russian, Peru, Mexico, Ukraine, Russia, Panama, Brazil, Ecuador, Chile, America, Argentina, Uruguay, American
TTPs:
IOCs:
Domain: 10
YARA: Found
Recordedfuture
Latin American Governments Targeted By Ransomware
Recent ransomware attacks against Latin American governments suggest a change of policy within Russian-speaking threat groups, and they will likely continue to target these government entities – and critical infrastructure within Latin America’s private sector…
#ParsedReport
17-06-2022
CoinEgg Scam Campaign Steals Victims Cryptocurrency and Data
https://cloudsek.com/threatintelligence/coinegg-scam-campaign-steals-victims-cryptocurrency-and-data/?utm_source=rss&utm_medium=rss&utm_campaign=coinegg-scam-campaign-steals-victims-cryptocurrency-and-data
Industry:
Financial
Geo:
Australia, France
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
Domain: 2
IP: 2
17-06-2022
CoinEgg Scam Campaign Steals Victims Cryptocurrency and Data
https://cloudsek.com/threatintelligence/coinegg-scam-campaign-steals-victims-cryptocurrency-and-data/?utm_source=rss&utm_medium=rss&utm_campaign=coinegg-scam-campaign-steals-victims-cryptocurrency-and-data
Industry:
Financial
Geo:
Australia, France
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
Domain: 2
IP: 2
Cloudsek
CoinEgg Scam Campaign Steals Victims’ Cryptocurrency and Data | Threat Intelligence | CloudSEK
CloudSEK researchers’ investigation discovered that the CoinEgg Scam/cryptocurrency scam was conducted by threat actors. We discovered an on-going malicious scheme involving multiple payment gateway domains and Android-based applications, used to lure unsuspecting…
#ParsedReport
17-06-2022
Anatomy of a Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-ransomware-attack
Threats:
Lockbit
Psexec_tool
Tightvnc_tool
Log4shell_vuln
Mimikatz
Passthehash_technique
TTPs:
Tactics: 12
Technics: 24
IOCs:
Domain: 1
IP: 8
17-06-2022
Anatomy of a Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-ransomware-attack
Threats:
Lockbit
Psexec_tool
Tightvnc_tool
Log4shell_vuln
Mimikatz
Passthehash_technique
TTPs:
Tactics: 12
Technics: 24
IOCs:
Domain: 1
IP: 8
Varonis
Anatomy of a LockBit Ransomware Attack
A detailed case study of the exact techniques and methods that threat actors used in a real-life ransomware attack.
👍1
#ParsedReport
17-06-2022
Resurgence of Voicemail-themed Phishing Attacks Targeting Key Industry Verticals in US.
https://www.zscaler.com/blogs/security-research/resurgence-voicemail-themed-phishing-attacks-targeting-key-industry
Industry:
Transport, Healthcare
Geo:
Japan
IOCs:
Hash: 1
File: 2
Domain: 10
17-06-2022
Resurgence of Voicemail-themed Phishing Attacks Targeting Key Industry Verticals in US.
https://www.zscaler.com/blogs/security-research/resurgence-voicemail-themed-phishing-attacks-targeting-key-industry
Industry:
Transport, Healthcare
Geo:
Japan
IOCs:
Hash: 1
File: 2
Domain: 10
Zscaler
Voicemail Phishing Continues to Target Key US Industries
Voicemail-themed credential phishing campaign targets key industry verticals in US to steal Office365 and Outlook credentials. Read more.
#ParsedReport
19-06-2022
BlackGuard Stealer Targets the Gaming Community
https://cyberint.com/blog/research/blackguard-stealer
Threats:
Blackguard_stealer (tags: vpn, stealer, malware)
Industry:
Entertainment
IOCs:
File: 2
Hash: 4
19-06-2022
BlackGuard Stealer Targets the Gaming Community
https://cyberint.com/blog/research/blackguard-stealer
Threats:
Blackguard_stealer (tags: vpn, stealer, malware)
Industry:
Entertainment
IOCs:
File: 2
Hash: 4
Cyberint
BlackGuard Stealer Targets the Gaming Community
The Cyberint Research Team recently discovered campaigns abusing gaming forums and Discord channels to distribute BlackGuard stealer.
#ParsedReport
20-06-2022
BRATA is evolving into an Advanced Persistent Threat
https://www.cleafy.com/cleafy-labs/brata-is-evolving-into-an-advanced-persistent-threat
Threats:
Brata (tags: fraud, keylogger, phishing, stealer, malware)
Anatsa
Sms_stealer (tags: malware, stealer)
Industry:
Financial
Geo:
Italy, Spain
IOCs:
File: 1
Hash: 2
IP: 2
20-06-2022
BRATA is evolving into an Advanced Persistent Threat
https://www.cleafy.com/cleafy-labs/brata-is-evolving-into-an-advanced-persistent-threat
Threats:
Brata (tags: fraud, keylogger, phishing, stealer, malware)
Anatsa
Sms_stealer (tags: malware, stealer)
Industry:
Financial
Geo:
Italy, Spain
IOCs:
File: 1
Hash: 2
IP: 2
Cleafy
BRATA is evolving into an APT | Cleafy Labs
The mobile banking malware BRATA keeps evolving into an APT. Read here the new Technical Report, which explains in detail how it monitors banks' account and how to prevent it.