#ParsedReport
19-06-2022
BlackGuard Stealer Targets the Gaming Community
https://cyberint.com/blog/research/blackguard-stealer
Threats:
Blackguard_stealer (tags: vpn, stealer, malware)
Industry:
Entertainment
IOCs:
File: 2
Hash: 4
19-06-2022
BlackGuard Stealer Targets the Gaming Community
https://cyberint.com/blog/research/blackguard-stealer
Threats:
Blackguard_stealer (tags: vpn, stealer, malware)
Industry:
Entertainment
IOCs:
File: 2
Hash: 4
Cyberint
BlackGuard Stealer Targets the Gaming Community
The Cyberint Research Team recently discovered campaigns abusing gaming forums and Discord channels to distribute BlackGuard stealer.
#ParsedReport
20-06-2022
BRATA is evolving into an Advanced Persistent Threat
https://www.cleafy.com/cleafy-labs/brata-is-evolving-into-an-advanced-persistent-threat
Threats:
Brata (tags: fraud, keylogger, phishing, stealer, malware)
Anatsa
Sms_stealer (tags: malware, stealer)
Industry:
Financial
Geo:
Italy, Spain
IOCs:
File: 1
Hash: 2
IP: 2
20-06-2022
BRATA is evolving into an Advanced Persistent Threat
https://www.cleafy.com/cleafy-labs/brata-is-evolving-into-an-advanced-persistent-threat
Threats:
Brata (tags: fraud, keylogger, phishing, stealer, malware)
Anatsa
Sms_stealer (tags: malware, stealer)
Industry:
Financial
Geo:
Italy, Spain
IOCs:
File: 1
Hash: 2
IP: 2
Cleafy
BRATA is evolving into an APT | Cleafy Labs
The mobile banking malware BRATA keeps evolving into an APT. Read here the new Technical Report, which explains in detail how it monitors banks' account and how to prevent it.
Научил парсер выкусывать "мотивацию" из текста TI-отчета и вязать с группировкой :)
🔥3
#ParsedReport
21-06-2022
Bumblebee Being Distributed in Korea Through Email Hijacking
https://asec.ahnlab.com/en/35460
Threats:
Bumblebee (tags: dropper, trojan, malware, phishing)
Cobalt_strike
Dropper/win.dropperx-gen.c5154946
Geo:
Korea
IOCs:
File: 5
Path: 2
IP: 14
Hash: 5
21-06-2022
Bumblebee Being Distributed in Korea Through Email Hijacking
https://asec.ahnlab.com/en/35460
Threats:
Bumblebee (tags: dropper, trojan, malware, phishing)
Cobalt_strike
Dropper/win.dropperx-gen.c5154946
Geo:
Korea
IOCs:
File: 5
Path: 2
IP: 14
Hash: 5
ASEC BLOG
Bumblebee Being Distributed in Korea Through Email Hijacking - ASEC BLOG
The ASEC analysis team has recently discovered the active distribution of Bumblebee, a downloader type malware. It is distributed using phishing emails in ISO file, and this file contains a shortcut and malicious DLL file. There were also cases of malware…
#ParsedReport
20-06-2022
Client-side Magecart attacks still around, but more covert
https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert
Actors/Campaigns:
Magecart
IOCs:
Domain: 76
File: 1
IP: 49
Links:
20-06-2022
Client-side Magecart attacks still around, but more covert
https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert
Actors/Campaigns:
Magecart
IOCs:
Domain: 76
File: 1
IP: 49
Links:
https://gist.github.com/krautface/469fa925b494b7b436e1fd9346d36b60Malwarebytes
Client-side Magecart attacks still around, but more covert
This blog post was authored by Jérôme Segura We have seen and heard less buzz about ‘Magecart’ during the past several...
#ParsedReport
21-06-2022
APT ToddyCat
https://securelist.com/toddycat/106799
Actors/Campaigns:
Toddycat
Ice_fog
Threats:
Chinachopper
Samurai (tags: malware, trojan, backdoor, dropper)
Proxylogon_exploit
Cobalt_strike (tags: trojan)
Funnydream
Industry:
Government
Geo:
Indonesia, Taiwan, Russia, Slovakia, Iran, Malaysia, Vietnam, Afghanistan, Uzbekistan, Thailand, Kyrgyzstan, Vietnamese, Asia, Pakistan, China, India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 23
Path: 55
Registry: 1
Hash: 16
IP: 1
Domain: 1
Functions Names: 4
YARA: Found
21-06-2022
APT ToddyCat
https://securelist.com/toddycat/106799
Actors/Campaigns:
Toddycat
Ice_fog
Threats:
Chinachopper
Samurai (tags: malware, trojan, backdoor, dropper)
Proxylogon_exploit
Cobalt_strike (tags: trojan)
Funnydream
Industry:
Government
Geo:
Indonesia, Taiwan, Russia, Slovakia, Iran, Malaysia, Vietnam, Afghanistan, Uzbekistan, Thailand, Kyrgyzstan, Vietnamese, Asia, Pakistan, China, India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 23
Path: 55
Registry: 1
Hash: 16
IP: 1
Domain: 1
Functions Names: 4
YARA: Found
#ParsedReport
21-06-2022
Russias APT28 uses fear of nuclear war to spread Follina docs in Ukraine
https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine
Actors/Campaigns:
Fancy_bear (motivation: cyberespionage)
Threats:
Follina_vuln (tags: malware, stealer)
Industry:
Government
Geo:
Dubai, Russia, Ukraine, Russian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Path: 2
Domain: 2
IP: 1
Hash: 2
Url: 2
Functions Names: 1
21-06-2022
Russias APT28 uses fear of nuclear war to spread Follina docs in Ukraine
https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine
Actors/Campaigns:
Fancy_bear (motivation: cyberespionage)
Threats:
Follina_vuln (tags: malware, stealer)
Industry:
Government
Geo:
Dubai, Russia, Ukraine, Russian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Path: 2
Domain: 2
IP: 1
Hash: 2
Url: 2
Functions Names: 1
Malwarebytes
Russia’s APT28 uses fear of nuclear war to spread Follina docs in Ukraine
This blog post was authored by Hossein Jazi and Roberto Santos. In a recent campaign, APT28, an advanced persistent threat actor...
#ParsedReport
21-06-2022
King Fishers APT-Q-2 (Kimsuky) Many individual stories from the recent period onwards
https://mp-weixin-qq-com.translate.goog/s/JEQT3Lv1xoAe0nO7SkrgAA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
Threats:
Smokeloader_backdoor
Watering_hole_technique
Industry:
Government, Healthcare, Education
Geo:
Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 4
File: 2
Coin: 1
21-06-2022
King Fishers APT-Q-2 (Kimsuky) Many individual stories from the recent period onwards
https://mp-weixin-qq-com.translate.goog/s/JEQT3Lv1xoAe0nO7SkrgAA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
Threats:
Smokeloader_backdoor
Watering_hole_technique
Industry:
Government, Healthcare, Education
Geo:
Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 4
File: 2
Coin: 1
微信公众平台
钓鱼之王 — APT-Q-2(Kimsuky)近期以多个话题针对韩国的鱼叉攻击活动分析
近期,奇安信威胁情报中心红雨滴团队中捕获了Kimsuky组织多个鱼叉式钓鱼攻击样本。攻击者使用带恶意ole对象的hwp文件进行鱼叉攻击,当受害者点击执行诱饵文件之后,将会展示一个提示内容,诱导用户进行交互,以达到执行恶意载荷的目的。
#ParsedReport
21-06-2022
New IceXLoader 3.0 Developers Warm Up to Nim
https://www.fortinet.com/blog/threat-research/new-icexloader-3-0-developers-warm-up-to-nim
Threats:
Icexloader (tags: malware, ransomware, trojan, stealer, scan, phishing, rat, dropper, cryptomining)
Bazarnimrod
Bazarbackdoor
Trickbot
Ice_ix
Zeus
Xmr_miner
Dcrat_rat
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
Path: 1
File: 2
Hash: 8
Url: 12
Functions Names: 1
21-06-2022
New IceXLoader 3.0 Developers Warm Up to Nim
https://www.fortinet.com/blog/threat-research/new-icexloader-3-0-developers-warm-up-to-nim
Threats:
Icexloader (tags: malware, ransomware, trojan, stealer, scan, phishing, rat, dropper, cryptomining)
Bazarnimrod
Bazarbackdoor
Trickbot
Ice_ix
Zeus
Xmr_miner
Dcrat_rat
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
Path: 1
File: 2
Hash: 8
Url: 12
Functions Names: 1
Fortinet Blog
New IceXLoader 3.0 – Developers Warm Up to Nim
FortiGuard Labs discovered version 3.0 of IceXLoader, a new malware loader. Read our blog for the technical details of how it behaves and the potential malware that it can deliver in an infected sy…
#ParsedReport
21-06-2022
Matanbuchus: Malware-as-a-Service with Demonic Intentions
https://unit42.paloaltonetworks.com/matanbuchus-malware-as-a-service
Actors/Campaigns:
Belialdemon
Threats:
Triumph_loader
Industry:
Education, E-commerce
Geo:
Japanese, Austria, Belgium
IOCs:
File: 12
Url: 1
Hash: 3
Domain: 35
IP: 3
Path: 2
Functions Names: 2
21-06-2022
Matanbuchus: Malware-as-a-Service with Demonic Intentions
https://unit42.paloaltonetworks.com/matanbuchus-malware-as-a-service
Actors/Campaigns:
Belialdemon
Threats:
Triumph_loader
Industry:
Education, E-commerce
Geo:
Japanese, Austria, Belgium
IOCs:
File: 12
Url: 1
Hash: 3
Domain: 35
IP: 3
Path: 2
Functions Names: 2
Unit 42
Matanbuchus: Malware-as-a-Service with Demonic Intentions
Matanbuchus Loader is a new malware-as-a-service created by a threat actor who references demonic themes in software and usernames.
#ParsedReport
21-06-2022
Avos ransomware group expands with new attack arsenal
http://blog.talosintelligence.com/2022/06/avoslocker-new-arsenal.html
Actors/Campaigns:
Avos (motivation: financiallymotivated)
Threats:
Avoslocker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sliver_tool (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Lolbin
Darkcomet_rat
Mimikatz
Beacon
Geo:
Russian
CVEs:
CVE-2021-45105 [Vulners]
Vulners: Score: 4.3, CVSS: 5.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache log4j (<2.3.1, <2.12.3, le2.16.0)
- netapp cloud manager (-)
- debian debian linux (10.0, 11.0)
- sonicwall email security (le10.0.12)
- sonicwall network security manager (<3.0, <3.0)
have more...
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel audio development kit (-)
- intel computer vision annotation tool (-)
- intel datacenter manager (-)
- intel genomics kernel library (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2021-44832 [Vulners]
Vulners: Score: 6.0, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, 2.0, 2.0, <2.3.2, <2.12.4, <2.17.1)
IOCs:
File: 4
Path: 2
Url: 1
Hash: 14
IP: 2
Links:
21-06-2022
Avos ransomware group expands with new attack arsenal
http://blog.talosintelligence.com/2022/06/avoslocker-new-arsenal.html
Actors/Campaigns:
Avos (motivation: financiallymotivated)
Threats:
Avoslocker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sliver_tool (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Lolbin
Darkcomet_rat
Mimikatz
Beacon
Geo:
Russian
CVEs:
CVE-2021-45105 [Vulners]
Vulners: Score: 4.3, CVSS: 5.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache log4j (<2.3.1, <2.12.3, le2.16.0)
- netapp cloud manager (-)
- debian debian linux (10.0, 11.0)
- sonicwall email security (le10.0.12)
- sonicwall network security manager (<3.0, <3.0)
have more...
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel audio development kit (-)
- intel computer vision annotation tool (-)
- intel datacenter manager (-)
- intel genomics kernel library (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2021-44832 [Vulners]
Vulners: Score: 6.0, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, 2.0, 2.0, <2.3.2, <2.12.4, <2.17.1)
IOCs:
File: 4
Path: 2
Url: 1
Hash: 14
IP: 2
Links:
https://github.com/BishopFox/sliverCisco Talos Blog
Avos ransomware group expands with new attack arsenal
By Flavio Costa,
* In a recent customer engagement, we observed a month-long AvosLocker campaign.
* The attackers utilized several different tools, including Cobalt Strike, Sliver and multiple commercial network scanners.
* The initial ingress point in…
* In a recent customer engagement, we observed a month-long AvosLocker campaign.
* The attackers utilized several different tools, including Cobalt Strike, Sliver and multiple commercial network scanners.
* The initial ingress point in…
#ParsedReport
21-06-2022
MuddyWaters light first-stager targetting Middle East
https://lab52.io/blog/muddywaters-light-first-stager-targetting-middle-east
Actors/Campaigns:
Muddywater
Industry:
Energy, Government
Geo:
Kazakhstan, Syria, Sudan, Israel, Africa, Armenia, Bahrain, Turkey, Argentina, Iran, Pakistan
IOCs:
File: 10
Hash: 13
IP: 3
Functions Names: 2
21-06-2022
MuddyWaters light first-stager targetting Middle East
https://lab52.io/blog/muddywaters-light-first-stager-targetting-middle-east
Actors/Campaigns:
Muddywater
Industry:
Energy, Government
Geo:
Kazakhstan, Syria, Sudan, Israel, Africa, Armenia, Bahrain, Turkey, Argentina, Iran, Pakistan
IOCs:
File: 10
Hash: 13
IP: 3
Functions Names: 2
#technique
https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/06/dfscoerce-a-new-ntlm-relay-attack-can-take-control-over-a-windows-domain/
https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/06/dfscoerce-a-new-ntlm-relay-attack-can-take-control-over-a-windows-domain/
Malwarebytes
DFSCoerce, a new NTLM relay attack, can take control over a Windows domain
A researcher has posted a PoC for yet another NTLM relay attack method dubbed DFSCoerce. It is high time to retire NTLM.
#ParsedReport
21-06-2022
Rise of LNK (Shortcut files) Malware
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/rise-of-lnk-shortcut-files-malware
Threats:
Emotet (tags: malware)
Qakbot (tags: malware)
Icedid (tags: malware)
Bazarbackdoor (tags: malware)
Findpos
Hancitor
Ficker_stealer
Dexter
IOCs:
File: 8
Path: 2
Url: 9
Hash: 3
21-06-2022
Rise of LNK (Shortcut files) Malware
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/rise-of-lnk-shortcut-files-malware
Threats:
Emotet (tags: malware)
Qakbot (tags: malware)
Icedid (tags: malware)
Bazarbackdoor (tags: malware)
Findpos
Hancitor
Ficker_stealer
Dexter
IOCs:
File: 8
Path: 2
Url: 9
Hash: 3
McAfee Blog
Rise of LNK (Shortcut files) Malware | McAfee Blog
An LNK file is a Windows Shortcut that serves as a pointer to open a file, folder, or application. LNK files are based on the Shell Link binary file format, which holds information used to access another data object. McAfee Labs has seen a rise in malware…
#ParsedReport
22-06-2022
Chinese actor takes aim, armed with Nim Language and Bizarro AES. Executive Summary
https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes
Actors/Campaigns:
Pirate_panda
Ta428
Threats:
Bizarro (tags: proxy, trojan, scan, malware, rat, backdoor, ransomware)
Yahoyah (tags: scan, backdoor, malware)
Zebrocy
Trickbot
Process_doppelganging_technique
Industry:
Financial
Geo:
Philippines, Taiwan, China, Chinese
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 32
IP: 24
Domain: 2
Functions Names: 1
Links:
22-06-2022
Chinese actor takes aim, armed with Nim Language and Bizarro AES. Executive Summary
https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes
Actors/Campaigns:
Pirate_panda
Ta428
Threats:
Bizarro (tags: proxy, trojan, scan, malware, rat, backdoor, ransomware)
Yahoyah (tags: scan, backdoor, malware)
Zebrocy
Trickbot
Process_doppelganging_technique
Industry:
Financial
Geo:
Philippines, Taiwan, China, Chinese
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 32
IP: 24
Domain: 2
Functions Names: 1
Links:
https://github.com/polymorf/findcrypt-yaraCheck Point Research
Chinese actor takes aim, armed with Nim Language and Bizarro AES - Check Point Research
Executive Summary In this article, Check Point Research shares findings on a group / activity cluster with ties to Tropic Trooper: The infection chain includes a previously undescribed loader (dubbed “Nimbda”) written in Nim language. This loader was observed…
#ParsedReport
22-06-2022
CALISTO continues its credential harvesting campaign
https://blog.sekoia.io/calisto-continues-its-credential-harvesting-campaign
Actors/Campaigns:
Calisto
Coldriver
Fancy_bear
Threats:
Hades
Industry:
Ngo
Geo:
Ukrainian, Russian
IOCs:
Domain: 24
Links:
22-06-2022
CALISTO continues its credential harvesting campaign
https://blog.sekoia.io/calisto-continues-its-credential-harvesting-campaign
Actors/Campaigns:
Calisto
Coldriver
Fancy_bear
Threats:
Hades
Industry:
Ngo
Geo:
Ukrainian, Russian
IOCs:
Domain: 24
Links:
https://github.com/kgretzky/evilginx2Sekoia.io Blog
CALISTO continues its credential harvesting campaign
March 30, 2022, Google TAG published several IOCs related to CALISTO - a Russia-nexus threat actor. Discover our analysis.
#ParsedReport
22-06-2022
From the Front Lines \| 3 New and Emerging Ransomware Threats Striking Businesses in 2022
https://www.sentinelone.com/blog/from-the-front-lines-3-new-and-emerging-ransomware-threats-striking-businesses-in-2022
Actors/Campaigns:
Lapsus
Mindware
Threats:
Zeon (tags: ransomware)
Helloxd (tags: ransomware, malware, rat)
Babuk (tags: ransomware, malware)
Conti (tags: ransomware)
Lockbit (tags: ransomware)
Blackcat (tags: ransomware)
Microbackdoor (tags: ransomware)
Sfile (tags: ransomware)
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
IP: 1
Hash: 22
Links:
22-06-2022
From the Front Lines \| 3 New and Emerging Ransomware Threats Striking Businesses in 2022
https://www.sentinelone.com/blog/from-the-front-lines-3-new-and-emerging-ransomware-threats-striking-businesses-in-2022
Actors/Campaigns:
Lapsus
Mindware
Threats:
Zeon (tags: ransomware)
Helloxd (tags: ransomware, malware, rat)
Babuk (tags: ransomware, malware)
Conti (tags: ransomware)
Lockbit (tags: ransomware)
Blackcat (tags: ransomware)
Microbackdoor (tags: ransomware)
Sfile (tags: ransomware)
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
IP: 1
Hash: 22
Links:
https://github.com/vbdaga/Rabbit-Cipherhttps://github.com/dashingsoft/pyarmorSentinelOne
From the Front Lines | 3 New and Emerging Ransomware Threats Striking Businesses in 2022
Crimeware continues to evolve at pace with threat actors both iterating on old source code and creating new ransomware families. Stay informed, stay safe.
#ParsedReport
22-06-2022
Improvised Modus Operandi for Targeting Indian Banking Customers via SMS Forwarding Malware
https://cloudsek.com/threatintelligence/improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware/?utm_source=rss&utm_medium=rss&utm_campaign=improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware
Industry:
Financial
Geo:
Indian, India
TTPs:
Tactics: 2
Technics: 0
IOCs:
Domain: 5
File: 2
IP: 1
Hash: 1
Url: 3
Functions Names: 3
22-06-2022
Improvised Modus Operandi for Targeting Indian Banking Customers via SMS Forwarding Malware
https://cloudsek.com/threatintelligence/improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware/?utm_source=rss&utm_medium=rss&utm_campaign=improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware
Industry:
Financial
Geo:
Indian, India
TTPs:
Tactics: 2
Technics: 0
IOCs:
Domain: 5
File: 2
IP: 1
Hash: 1
Url: 3
Functions Names: 3
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
Improvised Modus Operandi for Targeting Indian Banking Customers via SMS Forwarding Malware - CloudSEK
CloudSEK team has uncovered a banking trojan (SMS Forwarding Malware, with improvised modus operandi, where the threat actor or a group of threat actors host a simple fake online complaint portal having the domains and target Indian banking customers.
#ParsedReport
22-06-2022
Cybercriminals Exploit Reverse Tunnel Services and URL Shorteners to Launch Large-Scale Phishing Campaigns
https://cloudsek.com/threatintelligence/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/?utm_source=rss&utm_medium=rss&utm_campaign=cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns
Industry:
Financial
Geo:
Indian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Domain: 3
Url: 6
22-06-2022
Cybercriminals Exploit Reverse Tunnel Services and URL Shorteners to Launch Large-Scale Phishing Campaigns
https://cloudsek.com/threatintelligence/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/?utm_source=rss&utm_medium=rss&utm_campaign=cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns
Industry:
Financial
Geo:
Indian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Domain: 3
Url: 6
#ParsedReport
22-06-2022
Quantum Software: LNK file-based builders growing in popularity. Possibly associated with Lazarus APT group
https://blog.cyble.com/2022/06/22/quantum-software-lnk-file-based-builders-growing-in-popularity
Actors/Campaigns:
Lazarus
Kimsuky
Threats:
Emotet
Bumblebee
Qakbot
Icedid
Lolbin
Dogwalk_vuln
TTPs:
Tactics: 3
Technics: 5
IOCs:
File: 2
Path: 1
Url: 1
Hash: 2
22-06-2022
Quantum Software: LNK file-based builders growing in popularity. Possibly associated with Lazarus APT group
https://blog.cyble.com/2022/06/22/quantum-software-lnk-file-based-builders-growing-in-popularity
Actors/Campaigns:
Lazarus
Kimsuky
Threats:
Emotet
Bumblebee
Qakbot
Icedid
Lolbin
Dogwalk_vuln
TTPs:
Tactics: 3
Technics: 5
IOCs:
File: 2
Path: 1
Url: 1
Hash: 2
Cyble
Quantum Software: LNK File Builders Gain Popularity
Cyble analyzes Quantum Software, a .lnk -based builder with possible links to the Lazarus APT Group.