#ParsedReport
17-06-2022
Cerber2021 Ransomware Back in Action. Sophisticated Ransomware targeting Windows and Linux Users
https://blog.cyble.com/2022/06/17/cerber2021-ransomware-back-in-action
Threats:
Cerberimposter (tags: ransomware, malware, rat)
Cerber (tags: ransomware)
Gandcrab (tags: ransomware)
Samsam (tags: ransomware)
Blackrouter (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2021-22205 [Vulners]
Vulners: Score: 7.5, CVSS: 5.6,
Vulners: Exploitation: True
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- gitlab (<13.8.8, <13.8.8, <13.9.6, <13.9.6, <13.10.3, <13.10.3)
CVE-2021-26084 [Vulners]
Vulners: Score: 7.5, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence server (<7.12.5, <7.4.11, <7.11.6, <6.13.23)
- atlassian confluence data center (<7.12.5, <7.11.6, <7.4.11, <6.13.23)
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 4
Technics: 6
IOCs:
Url: 1
Hash: 3
Functions Names: 1
Links:
17-06-2022
Cerber2021 Ransomware Back in Action. Sophisticated Ransomware targeting Windows and Linux Users
https://blog.cyble.com/2022/06/17/cerber2021-ransomware-back-in-action
Threats:
Cerberimposter (tags: ransomware, malware, rat)
Cerber (tags: ransomware)
Gandcrab (tags: ransomware)
Samsam (tags: ransomware)
Blackrouter (tags: ransomware)
Industry:
Financial
CVEs:
CVE-2021-22205 [Vulners]
Vulners: Score: 7.5, CVSS: 5.6,
Vulners: Exploitation: True
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- gitlab (<13.8.8, <13.8.8, <13.9.6, <13.9.6, <13.10.3, <13.10.3)
CVE-2021-26084 [Vulners]
Vulners: Score: 7.5, CVSS: 7.3,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence server (<7.12.5, <7.4.11, <7.11.6, <6.13.23)
- atlassian confluence data center (<7.12.5, <7.11.6, <7.4.11, <6.13.23)
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 4
Technics: 6
IOCs:
Url: 1
Hash: 3
Functions Names: 1
Links:
https://github.com/weidai11/cryptoppCyble
Cerber2021 Ransomware Back in Action
Cyble Research Labs analyzes Cerber2021 Ransomware - a potential rebrand of the popular Cerber Ransomware family.
#ParsedReport
17-06-2022
Lookout Uncovers Android Spyware Deployed in Kazakhstan
https://www.lookout.com/blog/hermit-spyware-discovery
Actors/Campaigns:
Memento (tags: rat)
Threats:
Hermit (tags: malware, spyware, rat, phishing)
Chrysaor
Finfisher
Industry:
Government, Telco, Financial
Geo:
Syria, Pakistan, Bangladesh, Chinese, Syrian, Berlin, Turkmenistan, Chile, Italy, Italian, German, Mongolia, Turkey, Kazakhstans, Kazakhstan, Myanmar, Vietnam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 1
IP: 10
Domain: 17
Hash: 8
17-06-2022
Lookout Uncovers Android Spyware Deployed in Kazakhstan
https://www.lookout.com/blog/hermit-spyware-discovery
Actors/Campaigns:
Memento (tags: rat)
Threats:
Hermit (tags: malware, spyware, rat, phishing)
Chrysaor
Finfisher
Industry:
Government, Telco, Financial
Geo:
Syria, Pakistan, Bangladesh, Chinese, Syrian, Berlin, Turkmenistan, Chile, Italy, Italian, German, Mongolia, Turkey, Kazakhstans, Kazakhstan, Myanmar, Vietnam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 1
IP: 10
Domain: 17
Hash: 8
Lookout
Lookout Uncovers Hermit Spyware Deployed in Kazakhstan | Threat Intel
Lookout researchers have uncovered enterprise-grade Android surveillanceware used by the government of Kazakhstan within its borders.
#ParsedReport
17-06-2022
Raccoon Stealer is Back with a New Version. Executive Summary
https://medium.com/s2wblog/raccoon-stealer-is-back-with-a-new-version-5f436e04b20d
Threats:
Raccoon_stealer (tags: cryptomining, malware, stealer, rat)
Redline_stealer
Fakecrack
Exodus
Vidar_stealer
Kpot_stealer
Geo:
Korean
IOCs:
Hash: 47
Domain: 1
File: 13
Coin: 3
Path: 5
IP: 1
Functions Names: 1
17-06-2022
Raccoon Stealer is Back with a New Version. Executive Summary
https://medium.com/s2wblog/raccoon-stealer-is-back-with-a-new-version-5f436e04b20d
Threats:
Raccoon_stealer (tags: cryptomining, malware, stealer, rat)
Redline_stealer
Fakecrack
Exodus
Vidar_stealer
Kpot_stealer
Geo:
Korean
IOCs:
Hash: 47
Domain: 1
File: 13
Coin: 3
Path: 5
IP: 1
Functions Names: 1
Medium
Raccoon Stealer is Back with a New Version
Author: S2W TALON
#ParsedReport
17-06-2022
'Dark Elephant': A Decade of Cyber Attacks
https://mp-weixin-qq-com.translate.goog/s/mC5D8kFaQA-cIcw2rlTgeA?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
Actors/Campaigns:
Darkelephant
Modified_elephant
Threats:
Harpoon
Netwire_rat
Darkcomet_rat
Parallax_rat
Geo:
India, China, Pakistan
CVEs:
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
IOCs:
File: 14
17-06-2022
'Dark Elephant': A Decade of Cyber Attacks
https://mp-weixin-qq-com.translate.goog/s/mC5D8kFaQA-cIcw2rlTgeA?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en
Actors/Campaigns:
Darkelephant
Modified_elephant
Threats:
Harpoon
Netwire_rat
Darkcomet_rat
Parallax_rat
Geo:
India, China, Pakistan
CVEs:
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
IOCs:
File: 14
微信公众平台
“暗象”组织:潜藏十年的网络攻击
安天披露印度“暗象”组织针对我国及南亚国家的网络窃密活动。
#ParsedReport
17-06-2022
Sophisticated Phishing Toolkit Dubbed NakedPages for Sale on Cybercrime Forums
https://cloudsek.com/threatintelligence/sophisticated-phishing-toolkit-dubbed-nakedpages-for-sale-on-cybercrime-forums
Threats:
Nakedpages_tool
Industry:
E-commerce
Geo:
India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
17-06-2022
Sophisticated Phishing Toolkit Dubbed NakedPages for Sale on Cybercrime Forums
https://cloudsek.com/threatintelligence/sophisticated-phishing-toolkit-dubbed-nakedpages-for-sale-on-cybercrime-forums
Threats:
Nakedpages_tool
Industry:
E-commerce
Geo:
India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Cloudsek
Sophisticated Phishing Toolkit Dubbed “NakedPages” for Sale on Cybercrime Forums | Threat Intelligence | CloudSEK
XVigil discovered a threat actor advertising a “battle-tested” reverse proxy/PHP phishing app called “NakedPages”, on a cybercrime forum.
#ParsedReport
17-06-2022
Latin American Governments Targeted By Ransomware
https://www.recordedfuture.com/latin-american-governments-targeted-by-ransomware
Actors/Campaigns:
Zirochka
Wazawaka
Threats:
Conti (tags: ransomware)
Blackcat (tags: ransomware)
Lockbit (tags: ransomware)
Blackbyte (tags: ransomware)
Industry:
Government, Ics, Healthcare, Education, E-commerce, Financial
Geo:
Latam, Brazilian, Colombia, Russian, Peru, Mexico, Ukraine, Russia, Panama, Brazil, Ecuador, Chile, America, Argentina, Uruguay, American
TTPs:
IOCs:
Domain: 10
YARA: Found
17-06-2022
Latin American Governments Targeted By Ransomware
https://www.recordedfuture.com/latin-american-governments-targeted-by-ransomware
Actors/Campaigns:
Zirochka
Wazawaka
Threats:
Conti (tags: ransomware)
Blackcat (tags: ransomware)
Lockbit (tags: ransomware)
Blackbyte (tags: ransomware)
Industry:
Government, Ics, Healthcare, Education, E-commerce, Financial
Geo:
Latam, Brazilian, Colombia, Russian, Peru, Mexico, Ukraine, Russia, Panama, Brazil, Ecuador, Chile, America, Argentina, Uruguay, American
TTPs:
IOCs:
Domain: 10
YARA: Found
Recordedfuture
Latin American Governments Targeted By Ransomware
Recent ransomware attacks against Latin American governments suggest a change of policy within Russian-speaking threat groups, and they will likely continue to target these government entities – and critical infrastructure within Latin America’s private sector…
#ParsedReport
17-06-2022
CoinEgg Scam Campaign Steals Victims Cryptocurrency and Data
https://cloudsek.com/threatintelligence/coinegg-scam-campaign-steals-victims-cryptocurrency-and-data/?utm_source=rss&utm_medium=rss&utm_campaign=coinegg-scam-campaign-steals-victims-cryptocurrency-and-data
Industry:
Financial
Geo:
Australia, France
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
Domain: 2
IP: 2
17-06-2022
CoinEgg Scam Campaign Steals Victims Cryptocurrency and Data
https://cloudsek.com/threatintelligence/coinegg-scam-campaign-steals-victims-cryptocurrency-and-data/?utm_source=rss&utm_medium=rss&utm_campaign=coinegg-scam-campaign-steals-victims-cryptocurrency-and-data
Industry:
Financial
Geo:
Australia, France
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 6
Domain: 2
IP: 2
Cloudsek
CoinEgg Scam Campaign Steals Victims’ Cryptocurrency and Data | Threat Intelligence | CloudSEK
CloudSEK researchers’ investigation discovered that the CoinEgg Scam/cryptocurrency scam was conducted by threat actors. We discovered an on-going malicious scheme involving multiple payment gateway domains and Android-based applications, used to lure unsuspecting…
#ParsedReport
17-06-2022
Anatomy of a Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-ransomware-attack
Threats:
Lockbit
Psexec_tool
Tightvnc_tool
Log4shell_vuln
Mimikatz
Passthehash_technique
TTPs:
Tactics: 12
Technics: 24
IOCs:
Domain: 1
IP: 8
17-06-2022
Anatomy of a Ransomware Attack
https://www.varonis.com/blog/anatomy-of-a-ransomware-attack
Threats:
Lockbit
Psexec_tool
Tightvnc_tool
Log4shell_vuln
Mimikatz
Passthehash_technique
TTPs:
Tactics: 12
Technics: 24
IOCs:
Domain: 1
IP: 8
Varonis
Anatomy of a LockBit Ransomware Attack
A detailed case study of the exact techniques and methods that threat actors used in a real-life ransomware attack.
👍1
#ParsedReport
17-06-2022
Resurgence of Voicemail-themed Phishing Attacks Targeting Key Industry Verticals in US.
https://www.zscaler.com/blogs/security-research/resurgence-voicemail-themed-phishing-attacks-targeting-key-industry
Industry:
Transport, Healthcare
Geo:
Japan
IOCs:
Hash: 1
File: 2
Domain: 10
17-06-2022
Resurgence of Voicemail-themed Phishing Attacks Targeting Key Industry Verticals in US.
https://www.zscaler.com/blogs/security-research/resurgence-voicemail-themed-phishing-attacks-targeting-key-industry
Industry:
Transport, Healthcare
Geo:
Japan
IOCs:
Hash: 1
File: 2
Domain: 10
Zscaler
Voicemail Phishing Continues to Target Key US Industries
Voicemail-themed credential phishing campaign targets key industry verticals in US to steal Office365 and Outlook credentials. Read more.
#ParsedReport
19-06-2022
BlackGuard Stealer Targets the Gaming Community
https://cyberint.com/blog/research/blackguard-stealer
Threats:
Blackguard_stealer (tags: vpn, stealer, malware)
Industry:
Entertainment
IOCs:
File: 2
Hash: 4
19-06-2022
BlackGuard Stealer Targets the Gaming Community
https://cyberint.com/blog/research/blackguard-stealer
Threats:
Blackguard_stealer (tags: vpn, stealer, malware)
Industry:
Entertainment
IOCs:
File: 2
Hash: 4
Cyberint
BlackGuard Stealer Targets the Gaming Community
The Cyberint Research Team recently discovered campaigns abusing gaming forums and Discord channels to distribute BlackGuard stealer.
#ParsedReport
20-06-2022
BRATA is evolving into an Advanced Persistent Threat
https://www.cleafy.com/cleafy-labs/brata-is-evolving-into-an-advanced-persistent-threat
Threats:
Brata (tags: fraud, keylogger, phishing, stealer, malware)
Anatsa
Sms_stealer (tags: malware, stealer)
Industry:
Financial
Geo:
Italy, Spain
IOCs:
File: 1
Hash: 2
IP: 2
20-06-2022
BRATA is evolving into an Advanced Persistent Threat
https://www.cleafy.com/cleafy-labs/brata-is-evolving-into-an-advanced-persistent-threat
Threats:
Brata (tags: fraud, keylogger, phishing, stealer, malware)
Anatsa
Sms_stealer (tags: malware, stealer)
Industry:
Financial
Geo:
Italy, Spain
IOCs:
File: 1
Hash: 2
IP: 2
Cleafy
BRATA is evolving into an APT | Cleafy Labs
The mobile banking malware BRATA keeps evolving into an APT. Read here the new Technical Report, which explains in detail how it monitors banks' account and how to prevent it.
Научил парсер выкусывать "мотивацию" из текста TI-отчета и вязать с группировкой :)
🔥3
#ParsedReport
21-06-2022
Bumblebee Being Distributed in Korea Through Email Hijacking
https://asec.ahnlab.com/en/35460
Threats:
Bumblebee (tags: dropper, trojan, malware, phishing)
Cobalt_strike
Dropper/win.dropperx-gen.c5154946
Geo:
Korea
IOCs:
File: 5
Path: 2
IP: 14
Hash: 5
21-06-2022
Bumblebee Being Distributed in Korea Through Email Hijacking
https://asec.ahnlab.com/en/35460
Threats:
Bumblebee (tags: dropper, trojan, malware, phishing)
Cobalt_strike
Dropper/win.dropperx-gen.c5154946
Geo:
Korea
IOCs:
File: 5
Path: 2
IP: 14
Hash: 5
ASEC BLOG
Bumblebee Being Distributed in Korea Through Email Hijacking - ASEC BLOG
The ASEC analysis team has recently discovered the active distribution of Bumblebee, a downloader type malware. It is distributed using phishing emails in ISO file, and this file contains a shortcut and malicious DLL file. There were also cases of malware…
#ParsedReport
20-06-2022
Client-side Magecart attacks still around, but more covert
https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert
Actors/Campaigns:
Magecart
IOCs:
Domain: 76
File: 1
IP: 49
Links:
20-06-2022
Client-side Magecart attacks still around, but more covert
https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert
Actors/Campaigns:
Magecart
IOCs:
Domain: 76
File: 1
IP: 49
Links:
https://gist.github.com/krautface/469fa925b494b7b436e1fd9346d36b60Malwarebytes
Client-side Magecart attacks still around, but more covert
This blog post was authored by Jérôme Segura We have seen and heard less buzz about ‘Magecart’ during the past several...
#ParsedReport
21-06-2022
APT ToddyCat
https://securelist.com/toddycat/106799
Actors/Campaigns:
Toddycat
Ice_fog
Threats:
Chinachopper
Samurai (tags: malware, trojan, backdoor, dropper)
Proxylogon_exploit
Cobalt_strike (tags: trojan)
Funnydream
Industry:
Government
Geo:
Indonesia, Taiwan, Russia, Slovakia, Iran, Malaysia, Vietnam, Afghanistan, Uzbekistan, Thailand, Kyrgyzstan, Vietnamese, Asia, Pakistan, China, India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 23
Path: 55
Registry: 1
Hash: 16
IP: 1
Domain: 1
Functions Names: 4
YARA: Found
21-06-2022
APT ToddyCat
https://securelist.com/toddycat/106799
Actors/Campaigns:
Toddycat
Ice_fog
Threats:
Chinachopper
Samurai (tags: malware, trojan, backdoor, dropper)
Proxylogon_exploit
Cobalt_strike (tags: trojan)
Funnydream
Industry:
Government
Geo:
Indonesia, Taiwan, Russia, Slovakia, Iran, Malaysia, Vietnam, Afghanistan, Uzbekistan, Thailand, Kyrgyzstan, Vietnamese, Asia, Pakistan, China, India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 23
Path: 55
Registry: 1
Hash: 16
IP: 1
Domain: 1
Functions Names: 4
YARA: Found
#ParsedReport
21-06-2022
Russias APT28 uses fear of nuclear war to spread Follina docs in Ukraine
https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine
Actors/Campaigns:
Fancy_bear (motivation: cyberespionage)
Threats:
Follina_vuln (tags: malware, stealer)
Industry:
Government
Geo:
Dubai, Russia, Ukraine, Russian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Path: 2
Domain: 2
IP: 1
Hash: 2
Url: 2
Functions Names: 1
21-06-2022
Russias APT28 uses fear of nuclear war to spread Follina docs in Ukraine
https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine
Actors/Campaigns:
Fancy_bear (motivation: cyberespionage)
Threats:
Follina_vuln (tags: malware, stealer)
Industry:
Government
Geo:
Dubai, Russia, Ukraine, Russian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Path: 2
Domain: 2
IP: 1
Hash: 2
Url: 2
Functions Names: 1
Malwarebytes
Russia’s APT28 uses fear of nuclear war to spread Follina docs in Ukraine
This blog post was authored by Hossein Jazi and Roberto Santos. In a recent campaign, APT28, an advanced persistent threat actor...
#ParsedReport
21-06-2022
King Fishers APT-Q-2 (Kimsuky) Many individual stories from the recent period onwards
https://mp-weixin-qq-com.translate.goog/s/JEQT3Lv1xoAe0nO7SkrgAA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
Threats:
Smokeloader_backdoor
Watering_hole_technique
Industry:
Government, Healthcare, Education
Geo:
Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 4
File: 2
Coin: 1
21-06-2022
King Fishers APT-Q-2 (Kimsuky) Many individual stories from the recent period onwards
https://mp-weixin-qq-com.translate.goog/s/JEQT3Lv1xoAe0nO7SkrgAA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
Threats:
Smokeloader_backdoor
Watering_hole_technique
Industry:
Government, Healthcare, Education
Geo:
Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 4
File: 2
Coin: 1
微信公众平台
钓鱼之王 — APT-Q-2(Kimsuky)近期以多个话题针对韩国的鱼叉攻击活动分析
近期,奇安信威胁情报中心红雨滴团队中捕获了Kimsuky组织多个鱼叉式钓鱼攻击样本。攻击者使用带恶意ole对象的hwp文件进行鱼叉攻击,当受害者点击执行诱饵文件之后,将会展示一个提示内容,诱导用户进行交互,以达到执行恶意载荷的目的。