#ParsedReport
28-06-2022
New Info-stealer Disguised as Crack Being Distributed
https://asec.ahnlab.com/en/35981
Threats:
Cryptbot_stealer
Redline_stealer
Vidar_stealer
Recordbreaker_stealer
Raccoon_stealer
Clipbanker
Infostealer/win.recordstealer.r498039
Infostealer/win.recordstealer.r500009
Infostealer/win.passstealer.r496906
Geo:
Russian
IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
28-06-2022
New Info-stealer Disguised as Crack Being Distributed
https://asec.ahnlab.com/en/35981
Threats:
Cryptbot_stealer
Redline_stealer
Vidar_stealer
Recordbreaker_stealer
Raccoon_stealer
Clipbanker
Infostealer/win.recordstealer.r498039
Infostealer/win.recordstealer.r500009
Infostealer/win.passstealer.r496906
Geo:
Russian
IOCs:
Url: 9
Coin: 9
Hash: 230
Domain: 26
ASEC
New Info-stealer Disguised as Crack Being Distributed - ASEC
New Info-stealer Disguised as Crack Being Distributed ASEC
#ParsedReport
28-06-2022
ASEC Weekly Malware Statistics (June 13th, 2022 June 19th, 2022)
https://asec.ahnlab.com/en/35859
Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Lokibot_stealer (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Smokeloader (tags: malware)
Industry:
Transport, Financial
IOCs:
Domain: 18
Email: 3
File: 21
Url: 22
28-06-2022
ASEC Weekly Malware Statistics (June 13th, 2022 June 19th, 2022)
https://asec.ahnlab.com/en/35859
Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Lokibot_stealer (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Smokeloader (tags: malware)
Industry:
Transport, Financial
IOCs:
Domain: 18
Email: 3
File: 21
Url: 22
ASEC BLOG
ASEC Weekly Malware Statistics (June 13th, 2022 - June 19th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from June 13th, 2022 (Monday) to June 19th, 2022 (Sunday). For the main category, info-stealer…
#ParsedReport
28-06-2022
ZuoRAT Hijacks SOHO Routers to Silently Stalk Networks
https://blog.lumen.com/zuorat-hijacks-soho-routers-to-silently-stalk-networks/?utm_source=rss&utm_medium=rss&utm_campaign=zuorat-hijacks-soho-routers-to-silently-stalk-networks
Threats:
Zuo_rat
Cobalt_strike
Emotet
Konni
Mirai
Geo:
Chinese, Canada, China, American, Russian, America, Taiwan
CVEs:
CVE-2020-26879 [Vulners]
Vulners: Score: 10.0, CVSS: 2.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- commscope ruckus vriot (le1.5.1.0.21)
CVE-2020-26878 [Vulners]
Vulners: Score: 9.0, CVSS: 6.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- commscope ruckus vriot (le1.5.1.0.21)
IOCs:
Domain: 4
Url: 7
IP: 8
File: 4
Path: 2
Functions Names: 1
Links:
28-06-2022
ZuoRAT Hijacks SOHO Routers to Silently Stalk Networks
https://blog.lumen.com/zuorat-hijacks-soho-routers-to-silently-stalk-networks/?utm_source=rss&utm_medium=rss&utm_campaign=zuorat-hijacks-soho-routers-to-silently-stalk-networks
Threats:
Zuo_rat
Cobalt_strike
Emotet
Konni
Mirai
Geo:
Chinese, Canada, China, American, Russian, America, Taiwan
CVEs:
CVE-2020-26879 [Vulners]
Vulners: Score: 10.0, CVSS: 2.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- commscope ruckus vriot (le1.5.1.0.21)
CVE-2020-26878 [Vulners]
Vulners: Score: 9.0, CVSS: 6.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- commscope ruckus vriot (le1.5.1.0.21)
IOCs:
Domain: 4
Url: 7
IP: 8
File: 4
Path: 2
Functions Names: 1
Links:
https://github.com/jgamblin/Mirai-Source-Code
https://github.com/beyefendi/exploit/blob/main/ruckus151021.py
https://github.com/SolomonSklash/COM-Hijacking
https://github.com/blacklotuslabs/IOCs/blob/main/ZuoRAT\_IoCs.txtLumen Blog
ZuoRAT hijacks SOHO routers to silently stalk networks
Infected SOHO routers can compromise sensitive data. Discover the tactics used by threat actors to exploit home office networks.
#ParsedReport
28-06-2022
Attacks on industrial control systems using ShadowPad
https://ics-cert.kaspersky.com/publications/reports/2022/06/27/attacks-on-industrial-control-systems-using-shadowpad
Actors/Campaigns:
Hafnium
Red_delta
Threats:
Shadowpad (tags: proxy, rat, malware, backdoor)
Cobalt_strike
Plugx_rat (tags: backdoor)
Dll_hijacking_technique
Procdump_tool
Mimikatz
Nextnet_tool
Chinachopper
Industry:
Logistic, Telco, Transport, Ics
Geo:
Malaysia, Afghanistan, Pakistan, Chinese, China
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
TTPs:
Tactics: 7
Technics: 22
IOCs:
File: 15
Path: 1
Domain: 12
Hash: 24
Url: 9
IP: 2
YARA: Found
28-06-2022
Attacks on industrial control systems using ShadowPad
https://ics-cert.kaspersky.com/publications/reports/2022/06/27/attacks-on-industrial-control-systems-using-shadowpad
Actors/Campaigns:
Hafnium
Red_delta
Threats:
Shadowpad (tags: proxy, rat, malware, backdoor)
Cobalt_strike
Plugx_rat (tags: backdoor)
Dll_hijacking_technique
Procdump_tool
Mimikatz
Nextnet_tool
Chinachopper
Industry:
Logistic, Telco, Transport, Ics
Geo:
Malaysia, Afghanistan, Pakistan, Chinese, China
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 6.4,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
TTPs:
Tactics: 7
Technics: 22
IOCs:
File: 15
Path: 1
Domain: 12
Hash: 24
Url: 9
IP: 2
YARA: Found
#ParsedReport
28-06-2022
Revive: from spyware to Android banking trojan
https://www.cleafy.com/cleafy-labs/revive-from-spyware-to-android-banking-trojan
Threats:
Revive_rat (tags: spyware, trojan, keylogger, rat, fraud, malware, phishing)
Anatsa (tags: trojan, spyware)
Sharkbot
Teardroid
Oscorp
Industry:
Financial
Geo:
Francesco, Spanish
IOCs:
File: 1
Hash: 2
IP: 1
Domain: 2
Links:
28-06-2022
Revive: from spyware to Android banking trojan
https://www.cleafy.com/cleafy-labs/revive-from-spyware-to-android-banking-trojan
Threats:
Revive_rat (tags: spyware, trojan, keylogger, rat, fraud, malware, phishing)
Anatsa (tags: trojan, spyware)
Sharkbot
Teardroid
Oscorp
Industry:
Financial
Geo:
Francesco, Spanish
IOCs:
File: 1
Hash: 2
IP: 1
Domain: 2
Links:
https://github.com/ScRiPt1337/Teardroidv4\_apihttps://github.com/ScRiPt1337/Teardroid-phpratCleafy
Revive: from spyware to android banking trojan | Cleafy Labs
A new banking trojan targeting Europe has been discovered by Cleafy's Threat Intelligence Team. We dubbed it Revive and it is an evolution of simple spyware into a banking trojan, with the key capability of conducting Account Takeover attacks: here's the…
#ParsedReport
28-06-2022
Emotet: Still Abusing Microsoft Office Macros
https://www.netskope.com/blog/emotet-still-abusing-microsoft-office-macros
Threats:
Emotet (tags: ransomware, phishing, fraud, malware)
Goodwill
Jasmin
Follina_vuln
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 6
YARA: Found
Links:
28-06-2022
Emotet: Still Abusing Microsoft Office Macros
https://www.netskope.com/blog/emotet-still-abusing-microsoft-office-macros
Threats:
Emotet (tags: ransomware, phishing, fraud, malware)
Goodwill
Jasmin
Follina_vuln
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 6
YARA: Found
Links:
https://github.com/mrexodia/dumpulatorhttps://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Emotet/2022-06-24https://github.com/netskopeoss/NetskopeThreatLabsIOCs/blob/main/Emotet/2022-06-24/script/extract\_xls\_urls.pyNetskope
Emotet: Still Abusing Microsoft Office Macros
Summary In April 2022, Netskope Threat Labs analyzed an Emotet campaign that was using LNK files instead of Microsoft Office documents, likely as a
#ParsedReport
28-06-2022
Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/bumblebee-loader-cybercrime
Actors/Campaigns:
Wizard_spider
Threats:
Bumblebee (tags: backdoor, phishing, cryptomining, malware, rat, ransomware, trojan)
Conti (tags: malware, ransomware)
Mountlocker (tags: malware, ransomware)
Trickbot (tags: malware, ransomware)
Bazarbackdoor (tags: malware, ransomware)
Quantum_locker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Metasploit_tool (tags: ransomware)
Adfind_tool (tags: phishing, rat, malware, ransomware)
Meterpreter_tool
Screenconnect_tool
Atera_tool
Avaddon
Ragnarlocker
Mimikatz
Lazagne
Netscan_tool
Ligolo
Procdump_tool
Diavol
Powersploit
Ryuk
Avoslocker
Empire_loader
Geo:
Canada
CVEs:
CVE-2021-34527 [Vulners]
Vulners: Score: 9.0, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 20h2, 21h1, 1809, 1909, 2004)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-, 20h2, 2004)
have more...
IOCs:
File: 16
IP: 6
Path: 2
Hash: 43
Domain: 1
Url: 6
28-06-2022
Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/bumblebee-loader-cybercrime
Actors/Campaigns:
Wizard_spider
Threats:
Bumblebee (tags: backdoor, phishing, cryptomining, malware, rat, ransomware, trojan)
Conti (tags: malware, ransomware)
Mountlocker (tags: malware, ransomware)
Trickbot (tags: malware, ransomware)
Bazarbackdoor (tags: malware, ransomware)
Quantum_locker (tags: ransomware)
Cobalt_strike (tags: ransomware)
Metasploit_tool (tags: ransomware)
Adfind_tool (tags: phishing, rat, malware, ransomware)
Meterpreter_tool
Screenconnect_tool
Atera_tool
Avaddon
Ragnarlocker
Mimikatz
Lazagne
Netscan_tool
Ligolo
Procdump_tool
Diavol
Powersploit
Ryuk
Avoslocker
Empire_loader
Geo:
Canada
CVEs:
CVE-2021-34527 [Vulners]
Vulners: Score: 9.0, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 20h2, 21h1, 1809, 1909, 2004)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-, 20h2, 2004)
have more...
IOCs:
File: 16
IP: 6
Path: 2
Hash: 43
Domain: 1
Url: 6
Security
Bumblebee: New Loader Rapidly Assuming Central Position in Cyber-crime Ecosystem
New malware has links with multiple threat actors, including several high-profile ransomware operations.
#ParsedReport
28-06-2022
GlowSand
https://inquest.net/blog/2022/06/27/glowsand
Industry:
Government
Geo:
Ukrainian, Ukraine
IOCs:
Hash: 7
Url: 5
Path: 1
File: 2
IP: 1
Domain: 41
28-06-2022
GlowSand
https://inquest.net/blog/2022/06/27/glowsand
Industry:
Government
Geo:
Ukrainian, Ukraine
IOCs:
Hash: 7
Url: 5
Path: 1
File: 2
IP: 1
Domain: 41
inquest.net
GlowSand
Tools used by threat actors aimed at Ukraine and neighboring countries are constantly changing. Since in many cases the context of successful attacks is the use of documents in email attachments, we will consider some of the novelties of attackers that target…
#ParsedReport
28-06-2022
RansomHouse Extortion Group Claims AMD as Latest Victim
https://restoreprivacy.com/ransomhouse-group-amd-advanced-micro-devices
Actors/Campaigns:
Ransomhouse (motivation: financially_motivated)
Industry:
Entertainment, Retail
Geo:
California
28-06-2022
RansomHouse Extortion Group Claims AMD as Latest Victim
https://restoreprivacy.com/ransomhouse-group-amd-advanced-micro-devices
Actors/Campaigns:
Ransomhouse (motivation: financially_motivated)
Industry:
Entertainment, Retail
Geo:
California
RestorePrivacy
RansomHouse Extortion Group Claims AMD as Latest Victim
Update: AMD has acknowledged the potential breach and has provided us with a statement. RansomHouse, a relatively new data-extortion cybercrime group, has announced a major new victim. Today, the group published a new update on its darknet site and are claiming…
#ParsedReport #technique
28-06-2022
De-anonymizing ransomware domains on the dark web
http://blog.talosintelligence.com/2022/06/de-anonymizing-ransomware-domains-on.html
Threats:
Babuk (tags: ransomware)
Nokoyawa (tags: ransomware)
Ghostnet
Quantum_locker (tags: dns, ransomware)
Karma
Industry:
Financial
Geo:
Germany, Singapore, Sweden, Netherlands, German
TTPs:
Tactics: 1
Technics: 0
IOCs:
IP: 4
Domain: 10
Url: 1
File: 1
28-06-2022
De-anonymizing ransomware domains on the dark web
http://blog.talosintelligence.com/2022/06/de-anonymizing-ransomware-domains-on.html
Threats:
Babuk (tags: ransomware)
Nokoyawa (tags: ransomware)
Ghostnet
Quantum_locker (tags: dns, ransomware)
Karma
Industry:
Financial
Geo:
Germany, Singapore, Sweden, Netherlands, German
TTPs:
Tactics: 1
Technics: 0
IOCs:
IP: 4
Domain: 10
Url: 1
File: 1
Cisco Talos Blog
De-anonymizing ransomware domains on the dark web
* We have developed three techniques to identify ransomware operators' dark websites hosted on public IP addresses, allowing us to uncover previously unknown infrastructure for the DarkAngels, Snatch, Quantum and Nokoyawa ransomware groups.
* The methods…
* The methods…
#ParsedReport
28-06-2022
SpiderLabs Blog. Interactive Phishing Mark II: Messenger Chatbot Leveraged in a New Facebook-Themed Spam
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/interactive-phishing-mark-ii-messenger-chatbot-leveraged-in-a-new-facebook-themed-spam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 6
28-06-2022
SpiderLabs Blog. Interactive Phishing Mark II: Messenger Chatbot Leveraged in a New Facebook-Themed Spam
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/interactive-phishing-mark-ii-messenger-chatbot-leveraged-in-a-new-facebook-themed-spam
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 6
Trustwave
Interactive Phishing Mark II: Messenger Chatbot Leveraged in a New Facebook-Themed Spam | Trustwave
Facebook Messenger is one of the most popular messaging platform in the world, amassing 988 million monthly active users as of January 2022 according to Statista.
#ParsedReport
28-06-2022
Raccoon Stealer v2 Part 1: The return of the dead
https://blog.sekoia.io/raccoon-stealer-v2-part-1-the-return-of-the-dead
Threats:
Raccoon_stealer (tags: stealer, rat, scan, vpn, malware)
Recordbreaker_stealer
Mars_stealer (tags: malware)
Geo:
Russian, Ukraine
TTPs:
Tactics: 6
Technics: 17
IOCs:
Domain: 1
Email: 1
File: 5
Registry: 2
IP: 86
Hash: 21
Functions Names: 1
Links:
28-06-2022
Raccoon Stealer v2 Part 1: The return of the dead
https://blog.sekoia.io/raccoon-stealer-v2-part-1-the-return-of-the-dead
Threats:
Raccoon_stealer (tags: stealer, rat, scan, vpn, malware)
Recordbreaker_stealer
Mars_stealer (tags: malware)
Geo:
Russian, Ukraine
TTPs:
Tactics: 6
Technics: 17
IOCs:
Domain: 1
Email: 1
File: 5
Registry: 2
IP: 86
Hash: 21
Functions Names: 1
Links:
https://github.com/SEKOIA-IO/Community/blob/main/IOCs/raccoonstealer/raccoon\_stealer\_iocs\_20220628.csvSekoia
Raccoon Stealer v2 - Part 1: The return of the dead
On June 10, 2022, Sekoia analysts stumbled upon active servers hosting a web page named “Raccoon Stealer 2.0”. Discover their research.
#ParsedReport
28-06-2022
AsyncRAT malware being distributed targeting vulnerable MySQL servers
https://asec-ahnlab-com.translate.goog/ko/35866/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Asyncrat_rat (tags: rat, cryptomining, malware)
Cobalt_strike (tags: malware)
Remcos_rat (tags: malware)
Cringe_rat (tags: malware)
Gh0st_rat (tags: malware)
Metasploit_tool (tags: malware)
Trojan/win32.rl_generic.c4239825 (tags: malware)
Trojan/win32.inject.c500093 (tags: malware)
IOCs:
Hash: 2
Url: 1
IP: 3
28-06-2022
AsyncRAT malware being distributed targeting vulnerable MySQL servers
https://asec-ahnlab-com.translate.goog/ko/35866/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Asyncrat_rat (tags: rat, cryptomining, malware)
Cobalt_strike (tags: malware)
Remcos_rat (tags: malware)
Cringe_rat (tags: malware)
Gh0st_rat (tags: malware)
Metasploit_tool (tags: malware)
Trojan/win32.rl_generic.c4239825 (tags: malware)
Trojan/win32.inject.c500093 (tags: malware)
IOCs:
Hash: 2
Url: 1
IP: 3
ASEC BLOG
취약한 MySQL 서버를 대상으로 유포 중인 AsyncRAT 악성코드 - ASEC BLOG
ShadowServer 재단은 최근 전 세계에서 외부에 노출되어 있는 MySQL 서버의 수가 약 360만 대 존재한다는 보고서를 공개하였다. MySQL 서버는 MS-SQL 서버와 함께 대표적인 데이터베이스 서버로서 기업이나 사용자 환경에서 대량의 데이터를 관리하는 기능을 제공한다. 일반적으로 윈도우 환경에서는 MS-SQL이 대표적이지만 리눅스 환경에서는 MySQL이 아직까지 많이 사용되고 있다. ASEC 분석팀에서는 취약한 데이터베이스 서버를 대상으로…
#ParsedReport
29-06-2022
ASEC Weekly Malware Statistics (June 20th, 2022 June 26th, 2022)
https://asec.ahnlab.com/en/36042
Threats:
Agent_tesla (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Industry:
Financial
Geo:
Asian
IOCs:
Domain: 4
IP: 4
Email: 6
File: 22
Url: 26
29-06-2022
ASEC Weekly Malware Statistics (June 20th, 2022 June 26th, 2022)
https://asec.ahnlab.com/en/36042
Threats:
Agent_tesla (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Industry:
Financial
Geo:
Asian
IOCs:
Domain: 4
IP: 4
Email: 6
File: 22
Url: 26
ASEC BLOG
ASEC Weekly Malware Statistics (June 20th, 2022 - June 26th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from June 20th, 2022 (Monday) to June 26th, 2022 (Sunday). For the main category, info-stealer…
#ParsedReport
29-06-2022
Forced Chrome extensions get removed, keep reappearing
https://blog.malwarebytes.com/threat-analysis/2022/06/forced-chrome-extensions-keep-reappearing
IOCs:
File: 8
Domain: 5
Registry: 1
29-06-2022
Forced Chrome extensions get removed, keep reappearing
https://blog.malwarebytes.com/threat-analysis/2022/06/forced-chrome-extensions-keep-reappearing
IOCs:
File: 8
Domain: 5
Registry: 1
Malwarebytes Labs
Forced Chrome extensions get removed, keep reappearing
A family of forced Chrome extensions can't be removed because of a policy change that tells users "Your browser is managed"
#ParsedReport
29-06-2022
YTStealer Malware: YouTube Cookies! Om Nom Nom Nom
https://www.intezer.com/blog/research/ytstealer-malware-youtube-cookies
Actors/Campaigns:
Nitro
Threats:
Ytstealer (tags: stealer, malware, ransomware)
Redline_stealer
Vidar_stealer
Sanny
Industry:
Petroleum, Entertainment
Geo:
Iranian, American, Mexico
TTPs:
Tactics: 1
Technics: 0
IOCs:
Domain: 2
Functions Names: 1
Links:
29-06-2022
YTStealer Malware: YouTube Cookies! Om Nom Nom Nom
https://www.intezer.com/blog/research/ytstealer-malware-youtube-cookies
Actors/Campaigns:
Nitro
Threats:
Ytstealer (tags: stealer, malware, ransomware)
Redline_stealer
Vidar_stealer
Sanny
Industry:
Petroleum, Entertainment
Geo:
Iranian, American, Mexico
TTPs:
Tactics: 1
Technics: 0
IOCs:
Domain: 2
Functions Names: 1
Links:
https://github.com/intezer/community-intellignce/blob/master/YTStealer\_hashes.txthttps://github.com/p3tr0v/chacalIntezer
YTStealer Malware: “YouTube Cookies! Om Nom Nom Nom” - Intezer
YTStealer is a new malware we believe is sold as a service on the Dark Web for stealing authentication cookies from YouTube content creators.
#ParsedReport
30-06-2022
The Ryuk Ransomware
https://www.telsy.com/the-ryuk-ransomware
Actors/Campaigns:
Wizard_spider (motivation: cyber_criminal)
Unc1878 (motivation: cyber_criminal)
Threats:
Ryuk (tags: phishing, ransomware, trojan, malware, dropper)
Hermes (tags: ransomware)
Trickbot (tags: trojan, malware, ransomware)
Z_loader
Bazarbackdoor
Cobalt_strike
Beacon
Zerologon_vuln
Industry:
Financial, Healthcare
Geo:
Russian
IOCs:
File: 3
Path: 2
30-06-2022
The Ryuk Ransomware
https://www.telsy.com/the-ryuk-ransomware
Actors/Campaigns:
Wizard_spider (motivation: cyber_criminal)
Unc1878 (motivation: cyber_criminal)
Threats:
Ryuk (tags: phishing, ransomware, trojan, malware, dropper)
Hermes (tags: ransomware)
Trickbot (tags: trojan, malware, ransomware)
Z_loader
Bazarbackdoor
Cobalt_strike
Beacon
Zerologon_vuln
Industry:
Financial, Healthcare
Geo:
Russian
IOCs:
File: 3
Path: 2
Telsy
The Ryuk Ransomware - Telsy
Ryuk tops the list of the most dangerous ransomware attacks and has successfully attacked sectors and companies worldwide.
#ParsedReport
30-06-2022
Raccoon Stealer v2 Part 2: In-depth analysis
https://blog.sekoia.io/raccoon-stealer-v2-part-2-in-depth-analysis
Threats:
Raccoon_stealer (tags: malware, rat, trojan, stealer, cryptomining, scan)
Agent_tesla
Formbook
Redline_stealer
Vidar_stealer
Industry:
Financial
Geo:
Ukraine, Russia
TTPs:
Tactics: 6
Technics: 17
IOCs:
Domain: 1
File: 15
Registry: 2
Functions Names: 2
YARA: Found
Links:
30-06-2022
Raccoon Stealer v2 Part 2: In-depth analysis
https://blog.sekoia.io/raccoon-stealer-v2-part-2-in-depth-analysis
Threats:
Raccoon_stealer (tags: malware, rat, trojan, stealer, cryptomining, scan)
Agent_tesla
Formbook
Redline_stealer
Vidar_stealer
Industry:
Financial
Geo:
Ukraine, Russia
TTPs:
Tactics: 6
Technics: 17
IOCs:
Domain: 1
File: 15
Registry: 2
Functions Names: 2
YARA: Found
Links:
https://github.com/SEKOIA-IO/Community/blob/main/scripts/raccoon\_stealer\_v2\_c2\_extrator.pySekoia.io Blog
Raccoon Stealer v2 - Part 2: In-depth analysis
Raccoon stealer 2.0 targets various crypto wallets, retrieves cookies and saves credit card numbers from browsers (Edge, Firefox and Chrome).
#ParsedReport
30-06-2022
Countering hack-for-hire groups
https://blog.google/threat-analysis-group/countering-hack-for-hire-groups
Actors/Campaigns:
Voidbalaur
Threats:
Gophish_tool
Njrat_rat
Houdini_rat
Industry:
Education, Government, Healthcare, Ngo, Financial, Telco
Geo:
Israel, Arab, Nigeria, Bahrain, Indian, Cyprus, India, Saudi, Russia, Arabia, Russian, Africa
IOCs:
Domain: 36
Links:
30-06-2022
Countering hack-for-hire groups
https://blog.google/threat-analysis-group/countering-hack-for-hire-groups
Actors/Campaigns:
Voidbalaur
Threats:
Gophish_tool
Njrat_rat
Houdini_rat
Industry:
Education, Government, Healthcare, Ngo, Financial, Telco
Geo:
Israel, Arab, Nigeria, Bahrain, Indian, Cyprus, India, Saudi, Russia, Arabia, Russian, Africa
IOCs:
Domain: 36
Links:
https://github.com/kgretzky/evilginx2https://github.com/gophish/gophishGoogle
Countering hack-for-hire groups
As part of TAG's mission to counter serious threats to Google and our users, we've published analysis on a range of persistent threats including government-backed attackers, commercial surveillance vendors, and serious criminal operators. Today, we're sharing…
#ParsedReport
30-06-2022
"Validator" - Trojan horse of the NSA (APT-C-40)
https://www-anquanke-com.translate.goog/post/id/275517?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Apt-c-40
Threats:
Quantum_tool
Foxacid_tool
Industry:
Government
Geo:
China
IOCs:
File: 14
IP: 2
Hash: 1
Registry: 6
30-06-2022
"Validator" - Trojan horse of the NSA (APT-C-40)
https://www-anquanke-com.translate.goog/post/id/275517?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Apt-c-40
Threats:
Quantum_tool
Foxacid_tool
Industry:
Government
Geo:
China
IOCs:
File: 14
IP: 2
Hash: 1
Registry: 6
www-anquanke-com.translate.goog
“验证器”(Validator)— 美国国家安全局NSA(APT—C—40)的木马尖兵 - 安全客,安全资讯平台
根据斯诺登曝光文档描述,“验证器”(Validator)是与美国国家安全局(NSA)接入技术行动处(TAO)“酸狐狸”(FOXACID)攻击武器平台相配套的专用木马程序。
#ParsedReport
30-06-2022
The SessionManager IIS backdoor
https://securelist.com/the-sessionmanager-iis-backdoor/106868
Actors/Campaigns:
Volatile_cedar
Threats:
Gelsemium (tags: malware, backdoor)
Owowa
Proxylogon_exploit (tags: malware)
Owlproxy
Mimikatz
Sessionmanager
Industry:
Ngo, Healthcare, Petroleum, Government, Transport
Geo:
Taiwan, Thailand, Argentina, Turkey, Indonesia, Malaysia, Kenya, Guinea, Asia, Armenia, Vietnam, China, Kuwait, Russia, Pakistan, Russian, America, Africa, Nigeria, Arabia, Poland, Djibouti, Saudi
IOCs:
Hash: 10
Path: 18
File: 1
IP: 2
Links:
30-06-2022
The SessionManager IIS backdoor
https://securelist.com/the-sessionmanager-iis-backdoor/106868
Actors/Campaigns:
Volatile_cedar
Threats:
Gelsemium (tags: malware, backdoor)
Owowa
Proxylogon_exploit (tags: malware)
Owlproxy
Mimikatz
Sessionmanager
Industry:
Ngo, Healthcare, Petroleum, Government, Transport
Geo:
Taiwan, Thailand, Argentina, Turkey, Indonesia, Malaysia, Kenya, Guinea, Asia, Armenia, Vietnam, China, Kuwait, Russia, Pakistan, Russian, America, Africa, Nigeria, Arabia, Poland, Djibouti, Saudi
IOCs:
Hash: 10
Path: 18
File: 1
IP: 2
Links:
https://github.com/3gstudent/Hook-PasswordChangeNotifyhttps://github.com/dionach/stripheaders