#ParsedReport
21-06-2022
Bumblebee Being Distributed in Korea Through Email Hijacking
https://asec.ahnlab.com/en/35460
Threats:
Bumblebee (tags: dropper, trojan, malware, phishing)
Cobalt_strike
Dropper/win.dropperx-gen.c5154946
Geo:
Korea
IOCs:
File: 5
Path: 2
IP: 14
Hash: 5
21-06-2022
Bumblebee Being Distributed in Korea Through Email Hijacking
https://asec.ahnlab.com/en/35460
Threats:
Bumblebee (tags: dropper, trojan, malware, phishing)
Cobalt_strike
Dropper/win.dropperx-gen.c5154946
Geo:
Korea
IOCs:
File: 5
Path: 2
IP: 14
Hash: 5
ASEC BLOG
Bumblebee Being Distributed in Korea Through Email Hijacking - ASEC BLOG
The ASEC analysis team has recently discovered the active distribution of Bumblebee, a downloader type malware. It is distributed using phishing emails in ISO file, and this file contains a shortcut and malicious DLL file. There were also cases of malware…
#ParsedReport
20-06-2022
Client-side Magecart attacks still around, but more covert
https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert
Actors/Campaigns:
Magecart
IOCs:
Domain: 76
File: 1
IP: 49
Links:
20-06-2022
Client-side Magecart attacks still around, but more covert
https://blog.malwarebytes.com/threat-intelligence/2022/06/client-side-magecart-attacks-still-around-but-more-covert
Actors/Campaigns:
Magecart
IOCs:
Domain: 76
File: 1
IP: 49
Links:
https://gist.github.com/krautface/469fa925b494b7b436e1fd9346d36b60Malwarebytes
Client-side Magecart attacks still around, but more covert
This blog post was authored by Jérôme Segura We have seen and heard less buzz about ‘Magecart’ during the past several...
#ParsedReport
21-06-2022
APT ToddyCat
https://securelist.com/toddycat/106799
Actors/Campaigns:
Toddycat
Ice_fog
Threats:
Chinachopper
Samurai (tags: malware, trojan, backdoor, dropper)
Proxylogon_exploit
Cobalt_strike (tags: trojan)
Funnydream
Industry:
Government
Geo:
Indonesia, Taiwan, Russia, Slovakia, Iran, Malaysia, Vietnam, Afghanistan, Uzbekistan, Thailand, Kyrgyzstan, Vietnamese, Asia, Pakistan, China, India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 23
Path: 55
Registry: 1
Hash: 16
IP: 1
Domain: 1
Functions Names: 4
YARA: Found
21-06-2022
APT ToddyCat
https://securelist.com/toddycat/106799
Actors/Campaigns:
Toddycat
Ice_fog
Threats:
Chinachopper
Samurai (tags: malware, trojan, backdoor, dropper)
Proxylogon_exploit
Cobalt_strike (tags: trojan)
Funnydream
Industry:
Government
Geo:
Indonesia, Taiwan, Russia, Slovakia, Iran, Malaysia, Vietnam, Afghanistan, Uzbekistan, Thailand, Kyrgyzstan, Vietnamese, Asia, Pakistan, China, India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 23
Path: 55
Registry: 1
Hash: 16
IP: 1
Domain: 1
Functions Names: 4
YARA: Found
#ParsedReport
21-06-2022
Russias APT28 uses fear of nuclear war to spread Follina docs in Ukraine
https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine
Actors/Campaigns:
Fancy_bear (motivation: cyberespionage)
Threats:
Follina_vuln (tags: malware, stealer)
Industry:
Government
Geo:
Dubai, Russia, Ukraine, Russian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Path: 2
Domain: 2
IP: 1
Hash: 2
Url: 2
Functions Names: 1
21-06-2022
Russias APT28 uses fear of nuclear war to spread Follina docs in Ukraine
https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine
Actors/Campaigns:
Fancy_bear (motivation: cyberespionage)
Threats:
Follina_vuln (tags: malware, stealer)
Industry:
Government
Geo:
Dubai, Russia, Ukraine, Russian
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Path: 2
Domain: 2
IP: 1
Hash: 2
Url: 2
Functions Names: 1
Malwarebytes
Russia’s APT28 uses fear of nuclear war to spread Follina docs in Ukraine
This blog post was authored by Hossein Jazi and Roberto Santos. In a recent campaign, APT28, an advanced persistent threat actor...
#ParsedReport
21-06-2022
King Fishers APT-Q-2 (Kimsuky) Many individual stories from the recent period onwards
https://mp-weixin-qq-com.translate.goog/s/JEQT3Lv1xoAe0nO7SkrgAA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
Threats:
Smokeloader_backdoor
Watering_hole_technique
Industry:
Government, Healthcare, Education
Geo:
Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 4
File: 2
Coin: 1
21-06-2022
King Fishers APT-Q-2 (Kimsuky) Many individual stories from the recent period onwards
https://mp-weixin-qq-com.translate.goog/s/JEQT3Lv1xoAe0nO7SkrgAA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Kimsuky
Threats:
Smokeloader_backdoor
Watering_hole_technique
Industry:
Government, Healthcare, Education
Geo:
Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 4
File: 2
Coin: 1
微信公众平台
钓鱼之王 — APT-Q-2(Kimsuky)近期以多个话题针对韩国的鱼叉攻击活动分析
近期,奇安信威胁情报中心红雨滴团队中捕获了Kimsuky组织多个鱼叉式钓鱼攻击样本。攻击者使用带恶意ole对象的hwp文件进行鱼叉攻击,当受害者点击执行诱饵文件之后,将会展示一个提示内容,诱导用户进行交互,以达到执行恶意载荷的目的。
#ParsedReport
21-06-2022
New IceXLoader 3.0 Developers Warm Up to Nim
https://www.fortinet.com/blog/threat-research/new-icexloader-3-0-developers-warm-up-to-nim
Threats:
Icexloader (tags: malware, ransomware, trojan, stealer, scan, phishing, rat, dropper, cryptomining)
Bazarnimrod
Bazarbackdoor
Trickbot
Ice_ix
Zeus
Xmr_miner
Dcrat_rat
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
Path: 1
File: 2
Hash: 8
Url: 12
Functions Names: 1
21-06-2022
New IceXLoader 3.0 Developers Warm Up to Nim
https://www.fortinet.com/blog/threat-research/new-icexloader-3-0-developers-warm-up-to-nim
Threats:
Icexloader (tags: malware, ransomware, trojan, stealer, scan, phishing, rat, dropper, cryptomining)
Bazarnimrod
Bazarbackdoor
Trickbot
Ice_ix
Zeus
Xmr_miner
Dcrat_rat
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
Path: 1
File: 2
Hash: 8
Url: 12
Functions Names: 1
Fortinet Blog
New IceXLoader 3.0 – Developers Warm Up to Nim
FortiGuard Labs discovered version 3.0 of IceXLoader, a new malware loader. Read our blog for the technical details of how it behaves and the potential malware that it can deliver in an infected sy…
#ParsedReport
21-06-2022
Matanbuchus: Malware-as-a-Service with Demonic Intentions
https://unit42.paloaltonetworks.com/matanbuchus-malware-as-a-service
Actors/Campaigns:
Belialdemon
Threats:
Triumph_loader
Industry:
Education, E-commerce
Geo:
Japanese, Austria, Belgium
IOCs:
File: 12
Url: 1
Hash: 3
Domain: 35
IP: 3
Path: 2
Functions Names: 2
21-06-2022
Matanbuchus: Malware-as-a-Service with Demonic Intentions
https://unit42.paloaltonetworks.com/matanbuchus-malware-as-a-service
Actors/Campaigns:
Belialdemon
Threats:
Triumph_loader
Industry:
Education, E-commerce
Geo:
Japanese, Austria, Belgium
IOCs:
File: 12
Url: 1
Hash: 3
Domain: 35
IP: 3
Path: 2
Functions Names: 2
Unit 42
Matanbuchus: Malware-as-a-Service with Demonic Intentions
Matanbuchus Loader is a new malware-as-a-service created by a threat actor who references demonic themes in software and usernames.
#ParsedReport
21-06-2022
Avos ransomware group expands with new attack arsenal
http://blog.talosintelligence.com/2022/06/avoslocker-new-arsenal.html
Actors/Campaigns:
Avos (motivation: financiallymotivated)
Threats:
Avoslocker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sliver_tool (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Lolbin
Darkcomet_rat
Mimikatz
Beacon
Geo:
Russian
CVEs:
CVE-2021-45105 [Vulners]
Vulners: Score: 4.3, CVSS: 5.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache log4j (<2.3.1, <2.12.3, le2.16.0)
- netapp cloud manager (-)
- debian debian linux (10.0, 11.0)
- sonicwall email security (le10.0.12)
- sonicwall network security manager (<3.0, <3.0)
have more...
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel audio development kit (-)
- intel computer vision annotation tool (-)
- intel datacenter manager (-)
- intel genomics kernel library (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2021-44832 [Vulners]
Vulners: Score: 6.0, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, 2.0, 2.0, <2.3.2, <2.12.4, <2.17.1)
IOCs:
File: 4
Path: 2
Url: 1
Hash: 14
IP: 2
Links:
21-06-2022
Avos ransomware group expands with new attack arsenal
http://blog.talosintelligence.com/2022/06/avoslocker-new-arsenal.html
Actors/Campaigns:
Avos (motivation: financiallymotivated)
Threats:
Avoslocker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Sliver_tool (tags: ransomware)
Log4shell_vuln (tags: ransomware)
Lolbin
Darkcomet_rat
Mimikatz
Beacon
Geo:
Russian
CVEs:
CVE-2021-45105 [Vulners]
Vulners: Score: 4.3, CVSS: 5.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache log4j (<2.3.1, <2.12.3, le2.16.0)
- netapp cloud manager (-)
- debian debian linux (10.0, 11.0)
- sonicwall email security (le10.0.12)
- sonicwall network security manager (<3.0, <3.0)
have more...
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel audio development kit (-)
- intel computer vision annotation tool (-)
- intel datacenter manager (-)
- intel genomics kernel library (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.0,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
CVE-2021-44832 [Vulners]
Vulners: Score: 6.0, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.6
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, 2.0, 2.0, <2.3.2, <2.12.4, <2.17.1)
IOCs:
File: 4
Path: 2
Url: 1
Hash: 14
IP: 2
Links:
https://github.com/BishopFox/sliverCisco Talos Blog
Avos ransomware group expands with new attack arsenal
By Flavio Costa,
* In a recent customer engagement, we observed a month-long AvosLocker campaign.
* The attackers utilized several different tools, including Cobalt Strike, Sliver and multiple commercial network scanners.
* The initial ingress point in…
* In a recent customer engagement, we observed a month-long AvosLocker campaign.
* The attackers utilized several different tools, including Cobalt Strike, Sliver and multiple commercial network scanners.
* The initial ingress point in…
#ParsedReport
21-06-2022
MuddyWaters light first-stager targetting Middle East
https://lab52.io/blog/muddywaters-light-first-stager-targetting-middle-east
Actors/Campaigns:
Muddywater
Industry:
Energy, Government
Geo:
Kazakhstan, Syria, Sudan, Israel, Africa, Armenia, Bahrain, Turkey, Argentina, Iran, Pakistan
IOCs:
File: 10
Hash: 13
IP: 3
Functions Names: 2
21-06-2022
MuddyWaters light first-stager targetting Middle East
https://lab52.io/blog/muddywaters-light-first-stager-targetting-middle-east
Actors/Campaigns:
Muddywater
Industry:
Energy, Government
Geo:
Kazakhstan, Syria, Sudan, Israel, Africa, Armenia, Bahrain, Turkey, Argentina, Iran, Pakistan
IOCs:
File: 10
Hash: 13
IP: 3
Functions Names: 2
#technique
https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/06/dfscoerce-a-new-ntlm-relay-attack-can-take-control-over-a-windows-domain/
https://blog.malwarebytes.com/exploits-and-vulnerabilities/2022/06/dfscoerce-a-new-ntlm-relay-attack-can-take-control-over-a-windows-domain/
Malwarebytes
DFSCoerce, a new NTLM relay attack, can take control over a Windows domain
A researcher has posted a PoC for yet another NTLM relay attack method dubbed DFSCoerce. It is high time to retire NTLM.
#ParsedReport
21-06-2022
Rise of LNK (Shortcut files) Malware
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/rise-of-lnk-shortcut-files-malware
Threats:
Emotet (tags: malware)
Qakbot (tags: malware)
Icedid (tags: malware)
Bazarbackdoor (tags: malware)
Findpos
Hancitor
Ficker_stealer
Dexter
IOCs:
File: 8
Path: 2
Url: 9
Hash: 3
21-06-2022
Rise of LNK (Shortcut files) Malware
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/rise-of-lnk-shortcut-files-malware
Threats:
Emotet (tags: malware)
Qakbot (tags: malware)
Icedid (tags: malware)
Bazarbackdoor (tags: malware)
Findpos
Hancitor
Ficker_stealer
Dexter
IOCs:
File: 8
Path: 2
Url: 9
Hash: 3
McAfee Blog
Rise of LNK (Shortcut files) Malware | McAfee Blog
An LNK file is a Windows Shortcut that serves as a pointer to open a file, folder, or application. LNK files are based on the Shell Link binary file format, which holds information used to access another data object. McAfee Labs has seen a rise in malware…
#ParsedReport
22-06-2022
Chinese actor takes aim, armed with Nim Language and Bizarro AES. Executive Summary
https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes
Actors/Campaigns:
Pirate_panda
Ta428
Threats:
Bizarro (tags: proxy, trojan, scan, malware, rat, backdoor, ransomware)
Yahoyah (tags: scan, backdoor, malware)
Zebrocy
Trickbot
Process_doppelganging_technique
Industry:
Financial
Geo:
Philippines, Taiwan, China, Chinese
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 32
IP: 24
Domain: 2
Functions Names: 1
Links:
22-06-2022
Chinese actor takes aim, armed with Nim Language and Bizarro AES. Executive Summary
https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes
Actors/Campaigns:
Pirate_panda
Ta428
Threats:
Bizarro (tags: proxy, trojan, scan, malware, rat, backdoor, ransomware)
Yahoyah (tags: scan, backdoor, malware)
Zebrocy
Trickbot
Process_doppelganging_technique
Industry:
Financial
Geo:
Philippines, Taiwan, China, Chinese
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 32
IP: 24
Domain: 2
Functions Names: 1
Links:
https://github.com/polymorf/findcrypt-yaraCheck Point Research
Chinese actor takes aim, armed with Nim Language and Bizarro AES - Check Point Research
Executive Summary In this article, Check Point Research shares findings on a group / activity cluster with ties to Tropic Trooper: The infection chain includes a previously undescribed loader (dubbed “Nimbda”) written in Nim language. This loader was observed…
#ParsedReport
22-06-2022
CALISTO continues its credential harvesting campaign
https://blog.sekoia.io/calisto-continues-its-credential-harvesting-campaign
Actors/Campaigns:
Calisto
Coldriver
Fancy_bear
Threats:
Hades
Industry:
Ngo
Geo:
Ukrainian, Russian
IOCs:
Domain: 24
Links:
22-06-2022
CALISTO continues its credential harvesting campaign
https://blog.sekoia.io/calisto-continues-its-credential-harvesting-campaign
Actors/Campaigns:
Calisto
Coldriver
Fancy_bear
Threats:
Hades
Industry:
Ngo
Geo:
Ukrainian, Russian
IOCs:
Domain: 24
Links:
https://github.com/kgretzky/evilginx2Sekoia.io Blog
CALISTO continues its credential harvesting campaign
March 30, 2022, Google TAG published several IOCs related to CALISTO - a Russia-nexus threat actor. Discover our analysis.
#ParsedReport
22-06-2022
From the Front Lines \| 3 New and Emerging Ransomware Threats Striking Businesses in 2022
https://www.sentinelone.com/blog/from-the-front-lines-3-new-and-emerging-ransomware-threats-striking-businesses-in-2022
Actors/Campaigns:
Lapsus
Mindware
Threats:
Zeon (tags: ransomware)
Helloxd (tags: ransomware, malware, rat)
Babuk (tags: ransomware, malware)
Conti (tags: ransomware)
Lockbit (tags: ransomware)
Blackcat (tags: ransomware)
Microbackdoor (tags: ransomware)
Sfile (tags: ransomware)
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
IP: 1
Hash: 22
Links:
22-06-2022
From the Front Lines \| 3 New and Emerging Ransomware Threats Striking Businesses in 2022
https://www.sentinelone.com/blog/from-the-front-lines-3-new-and-emerging-ransomware-threats-striking-businesses-in-2022
Actors/Campaigns:
Lapsus
Mindware
Threats:
Zeon (tags: ransomware)
Helloxd (tags: ransomware, malware, rat)
Babuk (tags: ransomware, malware)
Conti (tags: ransomware)
Lockbit (tags: ransomware)
Blackcat (tags: ransomware)
Microbackdoor (tags: ransomware)
Sfile (tags: ransomware)
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 8
IP: 1
Hash: 22
Links:
https://github.com/vbdaga/Rabbit-Cipherhttps://github.com/dashingsoft/pyarmorSentinelOne
From the Front Lines | 3 New and Emerging Ransomware Threats Striking Businesses in 2022
Crimeware continues to evolve at pace with threat actors both iterating on old source code and creating new ransomware families. Stay informed, stay safe.
#ParsedReport
22-06-2022
Improvised Modus Operandi for Targeting Indian Banking Customers via SMS Forwarding Malware
https://cloudsek.com/threatintelligence/improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware/?utm_source=rss&utm_medium=rss&utm_campaign=improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware
Industry:
Financial
Geo:
Indian, India
TTPs:
Tactics: 2
Technics: 0
IOCs:
Domain: 5
File: 2
IP: 1
Hash: 1
Url: 3
Functions Names: 3
22-06-2022
Improvised Modus Operandi for Targeting Indian Banking Customers via SMS Forwarding Malware
https://cloudsek.com/threatintelligence/improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware/?utm_source=rss&utm_medium=rss&utm_campaign=improvised-modus-operandi-for-targeting-indian-banking-customers-via-sms-forwarding-malware
Industry:
Financial
Geo:
Indian, India
TTPs:
Tactics: 2
Technics: 0
IOCs:
Domain: 5
File: 2
IP: 1
Hash: 1
Url: 3
Functions Names: 3
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
Improvised Modus Operandi for Targeting Indian Banking Customers via SMS Forwarding Malware - CloudSEK
CloudSEK team has uncovered a banking trojan (SMS Forwarding Malware, with improvised modus operandi, where the threat actor or a group of threat actors host a simple fake online complaint portal having the domains and target Indian banking customers.
#ParsedReport
22-06-2022
Cybercriminals Exploit Reverse Tunnel Services and URL Shorteners to Launch Large-Scale Phishing Campaigns
https://cloudsek.com/threatintelligence/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/?utm_source=rss&utm_medium=rss&utm_campaign=cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns
Industry:
Financial
Geo:
Indian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Domain: 3
Url: 6
22-06-2022
Cybercriminals Exploit Reverse Tunnel Services and URL Shorteners to Launch Large-Scale Phishing Campaigns
https://cloudsek.com/threatintelligence/cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns/?utm_source=rss&utm_medium=rss&utm_campaign=cybercriminals-exploit-reverse-tunnel-services-and-url-shorteners-to-launch-large-scale-phishing-campaigns
Industry:
Financial
Geo:
Indian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Domain: 3
Url: 6
#ParsedReport
22-06-2022
Quantum Software: LNK file-based builders growing in popularity. Possibly associated with Lazarus APT group
https://blog.cyble.com/2022/06/22/quantum-software-lnk-file-based-builders-growing-in-popularity
Actors/Campaigns:
Lazarus
Kimsuky
Threats:
Emotet
Bumblebee
Qakbot
Icedid
Lolbin
Dogwalk_vuln
TTPs:
Tactics: 3
Technics: 5
IOCs:
File: 2
Path: 1
Url: 1
Hash: 2
22-06-2022
Quantum Software: LNK file-based builders growing in popularity. Possibly associated with Lazarus APT group
https://blog.cyble.com/2022/06/22/quantum-software-lnk-file-based-builders-growing-in-popularity
Actors/Campaigns:
Lazarus
Kimsuky
Threats:
Emotet
Bumblebee
Qakbot
Icedid
Lolbin
Dogwalk_vuln
TTPs:
Tactics: 3
Technics: 5
IOCs:
File: 2
Path: 1
Url: 1
Hash: 2
Cyble
Quantum Software: LNK File Builders Gain Popularity
Cyble analyzes Quantum Software, a .lnk -based builder with possible links to the Lazarus APT Group.
#ParsedReport
22-06-2022
Distribution of LockBit ransomware through email impersonating copyright
https://asec-ahnlab-com.translate.goog/ko/35481/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Lockbit (tags: phishing, malware, ransomware)
Malware/mdp.systemmanipulation.m1751 (tags: ransomware)
IOCs:
File: 14
Hash: 2
22-06-2022
Distribution of LockBit ransomware through email impersonating copyright
https://asec-ahnlab-com.translate.goog/ko/35481/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Lockbit (tags: phishing, malware, ransomware)
Malware/mdp.systemmanipulation.m1751 (tags: ransomware)
IOCs:
File: 14
Hash: 2
ASEC BLOG
저작권 사칭 메일을 통한 LockBit 랜섬웨어 유포 - ASEC BLOG
ASEC 분석팀은 이전에 소개한 방식과 동일한 저작권법 위반의 내용으로 사칭한 피싱 메일을 통해 LockBit 랜섬웨어가 다시 유포되고 있음을 확인하였다. 지난 2월 유포되었던 피싱 메일(아래 링크 참고) 본문과 유사한 내용으로 작성되었으며 기존처럼 첨부된 파일명에 압축 파일의 비밀번호를 포함하여 유포하였다. 지원서 및 저작권 관련 메일로 LockBit 랜섬웨어 유포 중 [그림 2]와 같이 피싱 메일에 첨부된 압축 파일 내부에 추가 압축 파일이 존재하는…
#ParsedReport
22-06-2022
New information stealing malware, crack disguise is being distributed
https://asec-ahnlab-com.translate.goog/ko/35549/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Cryptbot_stealer (tags: malware)
Redline_stealer (tags: malware)
Vidar_stealer (tags: malware)
Raccoon_stealer (tags: malware)
Recordbreaker_stealer (tags: malware)
Exodus (tags: malware)
Clipbanker (tags: malware)
Infostealer/win.recordstealer.r498039 (tags: malware)
Infostealer/win.recordstealer.r500009 (tags: malware)
Infostealer/win.passstealer.r496906 (tags: malware)
IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
22-06-2022
New information stealing malware, crack disguise is being distributed
https://asec-ahnlab-com.translate.goog/ko/35549/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Cryptbot_stealer (tags: malware)
Redline_stealer (tags: malware)
Vidar_stealer (tags: malware)
Raccoon_stealer (tags: malware)
Recordbreaker_stealer (tags: malware)
Exodus (tags: malware)
Clipbanker (tags: malware)
Infostealer/win.recordstealer.r498039 (tags: malware)
Infostealer/win.recordstealer.r500009 (tags: malware)
Infostealer/win.passstealer.r496906 (tags: malware)
IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
ASEC BLOG
신종 정보탈취 악성코드, 크랙 위장 유포 중 - ASEC BLOG
ASEC 분석팀은 S/W 크랙 및 인스톨러로 위장하여 유포되는 다양한 악성코드를 소개한 바 있다. CryptBot, RedLine, Vidar 악성코드가 대표적이다. 최근 단일 악성코드 형태의 RedLine 악성코드가 자취를 감추고(드로퍼 유형으로는 유포 중) 신종 정보 탈취 악성코드가 활발히 유포 중이다. 5월 20일 경부터 본격적으로 유포되기 시작하였으며, 해외에서는 해당 악성코드를 “Recordbreaker Stealer”로 분류하고 있으며, Raccoon…
#ParsedReport
23-06-2022
Windows MSDT Zero-day Vulnerability DogWalk Detected by V3
https://asec.ahnlab.com/en/35681
Threats:
Dogwalk_vuln (tags: malware)
Follina_vuln
IOCs:
File: 1
Path: 1
23-06-2022
Windows MSDT Zero-day Vulnerability DogWalk Detected by V3
https://asec.ahnlab.com/en/35681
Threats:
Dogwalk_vuln (tags: malware)
Follina_vuln
IOCs:
File: 1
Path: 1
ASEC BLOG
Windows MSDT Zero-day Vulnerability 'DogWalk' Detected by V3 - ASEC BLOG
On June 8th, a new Windows Zero-day vulnerability named DogWalk was revealed by Hacker News (thehackernews.com). Similar to that of Follina vulnerability that targeted MS Office document files, this is a vulnerability that occurs from MSDT (Microsoft Support…
#ParsedReport
23-06-2022
Spyware vendor targets users in Italy and Kazakhstan
https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan
Threats:
Lightspeed_vuln
Sockpuppet_vuln
Timewaste_vuln
Avecesare_vuln
Clicked_vuln
Industry:
Telco, Government
Geo:
Italy, Kazakhstan
CVEs:
CVE-2020-9907 [Vulners]
Vulners: Score: 9.3, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<13.6)
- apple iphone os (<13.6)
- apple tvos (<13.4.8)
CVE-2021-30883 [Vulners]
Vulners: Score: 9.3, CVSS: 3.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<14.8.1, 15.0, 15.0.1)
- apple iphone os (<14.8.1, 15.0, 15.0.1)
- apple macos (<11.6.1, 12.0)
- apple tvos (<15.1)
- apple watchos (<8.1)
have more...
CVE-2020-3837 [Vulners]
Vulners: Score: 9.3, CVSS: 5.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<13.3.1)
- apple iphone os (<13.3.1)
- apple mac os x (<10.15.3)
- apple tvos (<13.3.1)
- apple watchos (<6.1.2)
have more...
CVE-2018-4344 [Vulners]
Vulners: Score: 9.3, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.4
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.0)
- apple mac os x (<10.14)
- apple tvos (<12)
- apple watchos (<5.0)
CVE-2021-30983 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<15.2)
- apple iphone os (<15.2)
CVE-2019-8605 [Vulners]
Vulners: Score: 9.3, CVSS: 5.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.3)
- apple mac os x (<10.14.5)
- apple tvos (<12.3)
- apple watchos (<5.2.1)
IOCs:
Domain: 18
Hash: 9
IP: 4
23-06-2022
Spyware vendor targets users in Italy and Kazakhstan
https://blog.google/threat-analysis-group/italian-spyware-vendor-targets-users-in-italy-and-kazakhstan
Threats:
Lightspeed_vuln
Sockpuppet_vuln
Timewaste_vuln
Avecesare_vuln
Clicked_vuln
Industry:
Telco, Government
Geo:
Italy, Kazakhstan
CVEs:
CVE-2020-9907 [Vulners]
Vulners: Score: 9.3, CVSS: 4.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<13.6)
- apple iphone os (<13.6)
- apple tvos (<13.4.8)
CVE-2021-30883 [Vulners]
Vulners: Score: 9.3, CVSS: 3.1,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipad os (<14.8.1, 15.0, 15.0.1)
- apple iphone os (<14.8.1, 15.0, 15.0.1)
- apple macos (<11.6.1, 12.0)
- apple tvos (<15.1)
- apple watchos (<8.1)
have more...
CVE-2020-3837 [Vulners]
Vulners: Score: 9.3, CVSS: 5.8,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<13.3.1)
- apple iphone os (<13.3.1)
- apple mac os x (<10.15.3)
- apple tvos (<13.3.1)
- apple watchos (<6.1.2)
have more...
CVE-2018-4344 [Vulners]
Vulners: Score: 9.3, CVSS: 4.4,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.4
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.0)
- apple mac os x (<10.14)
- apple tvos (<12)
- apple watchos (<5.0)
CVE-2021-30983 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple ipados (<15.2)
- apple iphone os (<15.2)
CVE-2019-8605 [Vulners]
Vulners: Score: 9.3, CVSS: 5.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- apple iphone os (<12.3)
- apple mac os x (<10.14.5)
- apple tvos (<12.3)
- apple watchos (<5.2.1)
IOCs:
Domain: 18
Hash: 9
IP: 4
Google
Spyware vendor targets users in Italy and Kazakhstan
Today, alongside Google’s Project Zero, we are detailing capabilities provided by RCS Labs, an Italian vendor that uses a combination of tactics, including atypical drive-by downloads as initial infection vectors to target mobile users on both iOS and Android.