#ParsedReport
06-07-2022
OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow
https://www.intezer.com/blog/incident-response/orbit-new-undetected-linux-threat
Actors/Campaigns:
Volatile_cedar
Threats:
Orbits_technique (tags: dropper, malware, backdoor)
Symbiote
Hiddenwasp
Hermeticwiper
Geo:
Israel
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 4
File: 1
Functions Names: 2
06-07-2022
OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow
https://www.intezer.com/blog/incident-response/orbit-new-undetected-linux-threat
Actors/Campaigns:
Volatile_cedar
Threats:
Orbits_technique (tags: dropper, malware, backdoor)
Symbiote
Hiddenwasp
Hermeticwiper
Geo:
Israel
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 4
File: 1
Functions Names: 2
Intezer
OrBit: New Undetected Linux Threat Uses Unique Hijack of Execution Flow
OrBit is a new Linux malware that hijacks the execution flow, evading and gaining persistence to get remote access and steal information.
#ParsedReport
06-07-2022
ALPHV Ransomware expands its Arsenal of Extortion techniques. Searchable Databases compound the risk of Supply Chain Attacks
https://blog.cyble.com/2022/07/06/alphv-ransomware-expands-its-arsenal-of-extortion-techniques
Actors/Campaigns:
Blackcat
Darkside
Blackmatter
Karakurt
06-07-2022
ALPHV Ransomware expands its Arsenal of Extortion techniques. Searchable Databases compound the risk of Supply Chain Attacks
https://blog.cyble.com/2022/07/06/alphv-ransomware-expands-its-arsenal-of-extortion-techniques
Actors/Campaigns:
Blackcat
Darkside
Blackmatter
Karakurt
Cyble
ALPHV Ransomware expands its Arsenal of Extortion techniques
Cyble analyzes ALPHV's updated TTPs and its possible links to other known ransomware groups like BlackMatter and DarkSide.
#ParsedReport
06-07-2022
ASEC Weekly Malware Statistics ( 20220627 \~ 20220703 )
https://asec-ahnlab-com.translate.goog/ko/36232/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Cloudeye (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Lokibot_stealer (tags: malware)
Avemaria_rat (tags: malware)
Industry:
Financial, Transport
Geo:
Korea
IOCs:
Domain: 1
IP: 3
Email: 6
File: 30
Url: 49
06-07-2022
ASEC Weekly Malware Statistics ( 20220627 \~ 20220703 )
https://asec-ahnlab-com.translate.goog/ko/36232/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Cloudeye (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Lokibot_stealer (tags: malware)
Avemaria_rat (tags: malware)
Industry:
Financial, Transport
Geo:
Korea
IOCs:
Domain: 1
IP: 3
Email: 6
File: 30
Url: 49
ASEC BLOG
ASEC 주간 악성코드 통계 ( 20220627 ~ 20220703 ) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 6월 27일 월요일부터 7월 3일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 48.0%로 1위를 차지하였으며, 그 다음으로는 뱅킹 악성코드가 26.5%, RAT 12.5%, 다운로더가 8.2%, 랜섬웨어 2.2%, 코인마이너 1.8%, 백도어가 0.7%로 집계되었다.…
#ParsedReport
06-07-2022
From the Front Lines \| New macOS covid Malware Masquerades as Apple, Wears Face of APT
https://www.sentinelone.com/blog/from-the-front-lines-new-macos-covid-malware-masquerades-as-apple-wears-face-of-apt
Actors/Campaigns:
Lazarus
Threats:
Dazzlespy (tags: malware)
Zuru (tags: malware)
Macma (tags: malware)
Gimmick (tags: malware)
Sliver_tool
Geo:
Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 1
Hash: 5
IP: 1
Links:
06-07-2022
From the Front Lines \| New macOS covid Malware Masquerades as Apple, Wears Face of APT
https://www.sentinelone.com/blog/from-the-front-lines-new-macos-covid-malware-masquerades-as-apple-wears-face-of-apt
Actors/Campaigns:
Lazarus
Threats:
Dazzlespy (tags: malware)
Zuru (tags: malware)
Macma (tags: malware)
Gimmick (tags: malware)
Sliver_tool
Geo:
Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 1
Hash: 5
IP: 1
Links:
https://github.com/BishopFox/sliverhttps://github.com/progrium/macdriverSentinelOne
From the Front Lines | New macOS ‘covid’ Malware Masquerades as Apple, Wears Face of APT
A fake VPN delivers a Sliver implant with a further malicious payload. APT or Red Team? The IoCs can look the same to defenders.
#ParsedReport
06-07-2022
Luna Moth: The Actors Behind the Recent False Subscription Scams
https://blog.sygnia.co/luna-moth-false-subscription-scams
Actors/Campaigns:
Luna_moth (motivation: information_theft)
Threats:
Atera_tool
Splashtop_tool
Syncro_tool
Sharpshares_tool
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
Email: 4
Domain: 88
IP: 46
Links:
06-07-2022
Luna Moth: The Actors Behind the Recent False Subscription Scams
https://blog.sygnia.co/luna-moth-false-subscription-scams
Actors/Campaigns:
Luna_moth (motivation: information_theft)
Threats:
Atera_tool
Splashtop_tool
Syncro_tool
Sharpshares_tool
Industry:
Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
Email: 4
Domain: 88
IP: 46
Links:
https://github.com/djhohnstein/SharpSharesblog.sygnia.co
Luna Moth: The Threat Actors Behind Recent False Subscription Scams
Sygnia’s team identified 'Luna Moth' ransom group. The threat actors resemble false subscription scammers, focusing on corporate data theft.
#ParsedReport
06-07-2022
research report. Analysis of Active Hezb Mining Trojans
https://www-antiy-cn.translate.goog/research/notice&report/research_report/20220705.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-29464 [Vulners]
Vulners: Score: 10.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- wso2 api manager (le4.0.0)
- wso2 enterprise integrator (le6.6.0)
- wso2 identity server (le5.11.0)
- wso2 identity server analytics (5.4.0, 5.4.1, 5.5.0, 5.6.0)
- wso2 identity server as key manager (le5.10.0)
have more...
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
IOCs:
File: 10
Url: 10
IP: 3
Coin: 1
Hash: 6
06-07-2022
research report. Analysis of Active Hezb Mining Trojans
https://www-antiy-cn.translate.goog/research/notice&report/research_report/20220705.html?_x_tr_sl=auto&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
CVE-2022-29464 [Vulners]
Vulners: Score: 10.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- wso2 api manager (le4.0.0)
- wso2 enterprise integrator (le6.6.0)
- wso2 identity server (le5.11.0)
- wso2 identity server analytics (5.4.0, 5.4.1, 5.5.0, 5.6.0)
- wso2 identity server as key manager (le5.10.0)
have more...
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 3.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
IOCs:
File: 10
Url: 10
IP: 3
Coin: 1
Hash: 6
www-antiy-cn.translate.goog
活跃的Hezb挖矿木马分析
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
07-07-2022
AsyncRAT Being Distributed to Vulnerable MySQL Servers
https://asec.ahnlab.com/en/36315
Threats:
Asyncrat_rat (tags: malware, spam, rat)
Cobalt_strike
Remcos_rat
Cringe_rat
Gh0st_rat
Metasploit_tool
Trojan/win32.rl_generic.c4239825
Trojan/win32.inject.c500093
IOCs:
File: 1
Hash: 2
Url: 1
IP: 3
07-07-2022
AsyncRAT Being Distributed to Vulnerable MySQL Servers
https://asec.ahnlab.com/en/36315
Threats:
Asyncrat_rat (tags: malware, spam, rat)
Cobalt_strike
Remcos_rat
Cringe_rat
Gh0st_rat
Metasploit_tool
Trojan/win32.rl_generic.c4239825
Trojan/win32.inject.c500093
IOCs:
File: 1
Hash: 2
Url: 1
IP: 3
ASEC BLOG
AsyncRAT Being Distributed to Unsecured MySQL Servers - ASEC BLOG
The ShadowServer foundation has recently released a report showing that there are about 3.6 million MySQL servers exposed to outside. Along with MS-SQL server, MySQL server is one of the main database servers that provides the feature of managing large amounts…
#ParsedReport
07-07-2022
ASEC Weekly Malware Statistics (June 27th, 2022 July 3rd, 2022)
https://asec.ahnlab.com/en/36294
Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Cloudeye (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Lokibot_stealer (tags: malware)
Industry:
Financial
IOCs:
Domain: 2
IP: 3
Email: 6
File: 30
Url: 48
07-07-2022
ASEC Weekly Malware Statistics (June 27th, 2022 July 3rd, 2022)
https://asec.ahnlab.com/en/36294
Threats:
Agent_tesla (tags: malware)
Formbook (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Emotet (tags: malware)
Qakbot (tags: malware)
Trickbot (tags: malware)
Cloudeye (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Lokibot_stealer (tags: malware)
Industry:
Financial
IOCs:
Domain: 2
IP: 3
Email: 6
File: 30
Url: 48
ASEC BLOG
ASEC Weekly Malware Statistics (June 27th, 2022 - July 3rd, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from June 27th, 2022 (Monday) to July 3rd, 2022 (Sunday). For the main category, info-stealer…
#ParsedReport
07-07-2022
Targets of Interest \| Russian Organizations Increasingly Under Attack By Chinese APTs
https://www.sentinelone.com/labs/targets-of-interest-russian-organizations-increasingly-under-attack-by-chinese-apts
Actors/Campaigns:
Red_delta
Scarab
Tonto_team
Threats:
Korlia (tags: malware)
Industry:
Telco, Government
Geo:
Russian, Russia, Chinese, Pakistan, Pakistani, Ukraines, Asia, Ukraine, Chinas
CVEs:
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
IOCs:
File: 3
Hash: 11
Domain: 4
IP: 2
07-07-2022
Targets of Interest \| Russian Organizations Increasingly Under Attack By Chinese APTs
https://www.sentinelone.com/labs/targets-of-interest-russian-organizations-increasingly-under-attack-by-chinese-apts
Actors/Campaigns:
Red_delta
Scarab
Tonto_team
Threats:
Korlia (tags: malware)
Industry:
Telco, Government
Geo:
Russian, Russia, Chinese, Pakistan, Pakistani, Ukraines, Asia, Ukraine, Chinas
CVEs:
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
IOCs:
File: 3
Hash: 11
Domain: 4
IP: 2
SentinelOne
Targets of Interest | Russian Organizations Increasingly Under Attack By Chinese APTs
Chinese-linked phishing campaign seeks to compromise Russian targets with custom malware designed for espionage.
#ParsedReport
07-07-2022
Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines
https://www.trendmicro.com/en_us/research/22/g/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html
Threats:
Xmrig_miner (tags: cryptomining)
Industry:
E-commerce
IOCs:
File: 2
Coin: 7
Hash: 2
Links:
07-07-2022
Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines
https://www.trendmicro.com/en_us/research/22/g/unpacking-cloud-based-cryptocurrency-miners-that-abuse-github-ac.html
Threats:
Xmrig_miner (tags: cryptomining)
Industry:
E-commerce
IOCs:
File: 2
Coin: 7
Hash: 2
Links:
https://github.com/Hffffhujft/hahsy/blob/main/.github/workflows/main.ymlhttps://github.com/limoain14/Langs/blob/main/.github/workflows/main.ymlhttps://github.com/aldilariskhameilenia2018/mining22/blob/main/.github/workflows/blank.ymlhttps://github.com/nick-fields/retryhttps://github.com/gesbul1989/VERUS/blob/main/.github/workflows/baru.ymlhttps://github.com/search?q=xmrig+extension%3Ayaml+extension%3Ayml+path%3A.github%2Fworkflows&type=Codehttps://docs.github.com/en/actions/using-workflows/events-that-trigger-workflows#workflow\_dispatchhttps://docs.github.com/en/actions/using-jobs/using-a-matrix-for-your-jobshttps://docs.github.com/en/actions/using-github-hosted-runners/about-github-hosted-runnershttps://github.com/000h0/1hars/blob/circleci-project-setup/.github/workflows/main.ymlhttps://github.com/janjan1999/shiba/blob/main/.github/Workflows/KaptenCrypto.ymlhttps://github.com/wa2nderma1/StartNew/blob/main/.github/workflows/mulai1.ymlhttps://github.com/FixKRI1/miner/blob/main/.github/workflows/main.ymlhttps://github.com/wizman008/shiba/blob/main/.github/workflows/coins.ymlhttps://github.com/aldilariskhameilenia2018/mininggg/blob/main/.github/workflows/blank.ymlhttps://github.com/actions/checkouthttps://github.com/jaknan/pg/blob/main/.github/workflows/main.ymlhttps://github.com/Olish420/nubatur/blob/main/.github/workflows/nubatur.ymlhttps://docs.github.com/en/actions/learn-github-actions/understanding-github-actionshttps://github.com/dsdnklasmals/aaaaaaaaaaaaa/blob/main/.github/Workflows/KaptenCrypto.ymlhttps://github.com/Olish420/tron/blob/main/.github/workflows/tron.ymlhttps://github.com/jaknan/pg/actionsTrend Micro
Unpacking Cloud-Based Cryptocurrency Miners That Abuse GitHub Actions and Azure Virtual Machines
We investigate cloud-based cryptocurrency miners that leverage GitHub Actions and Azure virtual machines, including the cloud infrastructure and vulnerabilities that malicious actors exploit for easy monetary gain.
#ParsedReport
07-07-2022
Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine
https://securityintelligence.com/posts/trickbot-group-systematically-attacking-ukraine
Actors/Campaigns:
Wizard_spider (motivation: cyber_criminal, financially_motivated, information_theft)
Ta578
Threats:
Trickbot (tags: malware, backdoor, phishing, ransomware, dropper, ddos, trojan)
Icedid (tags: malware, phishing, ransomware, dropper)
Cobalt_strike (tags: malware, phishing, ransomware, dropper, rat)
Meterpreter_tool (tags: phishing)
Bumblebee (tags: malware, ransomware, rat)
Conti
Ryuk
Diavol
Emotet
Tron
Bazarbackdoor
Anchor (tags: dropper)
Follina_vuln
Beacon
Putty_tool (tags: malware)
Industry:
Financial
Geo:
Ukraine, Ukraines, Belarus, Ukrainian, Russian, Russia
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Hash: 38
Url: 13
Domain: 3
Path: 4
Functions Names: 1
07-07-2022
Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine
https://securityintelligence.com/posts/trickbot-group-systematically-attacking-ukraine
Actors/Campaigns:
Wizard_spider (motivation: cyber_criminal, financially_motivated, information_theft)
Ta578
Threats:
Trickbot (tags: malware, backdoor, phishing, ransomware, dropper, ddos, trojan)
Icedid (tags: malware, phishing, ransomware, dropper)
Cobalt_strike (tags: malware, phishing, ransomware, dropper, rat)
Meterpreter_tool (tags: phishing)
Bumblebee (tags: malware, ransomware, rat)
Conti
Ryuk
Diavol
Emotet
Tron
Bazarbackdoor
Anchor (tags: dropper)
Follina_vuln
Beacon
Putty_tool (tags: malware)
Industry:
Financial
Geo:
Ukraine, Ukraines, Belarus, Ukrainian, Russian, Russia
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
IOCs:
File: 10
Hash: 38
Url: 13
Domain: 3
Path: 4
Functions Names: 1
Security Intelligence
Unprecedented Shift: The Trickbot Group is Systematically Attacking Ukraine
IBM Security X-Force uncovered evidence indicating that the Russia-based cybercriminal syndicate "Trickbot group" has been attacking Ukraine since the Russian invasion. Explore an in-depth analysis on six of ITG23's campaigns.
#ParsedReport
07-07-2022
Stormous Ransomware Group Runs Opinion Polls, Leaks Intellectual Property of Indian Companies
https://cloudsek.com/threatintelligence/stormous-ransomware-group-runs-opinion-polls-leaks-intellectual-property-of-indian-companies/?utm_source=rss&utm_medium=rss&utm_campaign=stormous-ransomware-group-runs-opinion-polls-leaks-intellectual-property-of-indian-companies
Actors/Campaigns:
Stormous (motivation: financially_motivated, hacktivism)
Threats:
Ekipa_rat (tags: ransomware)
Industry:
Financial, Telco, Education
Geo:
Russian, Indiacounty, India, Indian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 19
IP: 10
Url: 4
07-07-2022
Stormous Ransomware Group Runs Opinion Polls, Leaks Intellectual Property of Indian Companies
https://cloudsek.com/threatintelligence/stormous-ransomware-group-runs-opinion-polls-leaks-intellectual-property-of-indian-companies/?utm_source=rss&utm_medium=rss&utm_campaign=stormous-ransomware-group-runs-opinion-polls-leaks-intellectual-property-of-indian-companies
Actors/Campaigns:
Stormous (motivation: financially_motivated, hacktivism)
Threats:
Ekipa_rat (tags: ransomware)
Industry:
Financial, Telco, Education
Geo:
Russian, Indiacounty, India, Indian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 19
IP: 10
Url: 4
Cloudsek
Stormous Ransomware Group Runs Opinion Polls, Leaks Intellectual Property of Indian Companies | Threat Intelligence | CloudSEK
CloudSEK team has identified Stormous ransomware campaigns targeting multiple organizations globally. The threat group is financially motivated and their latest chain of attacks has been directed at Indian entities as well.
#ParsedReport
07-07-2022
Ekipa Remote Access Trojan Designed by Russian Hacktivists for Targeted Attacks. Executive Summary
https://cloudsek.com/threatintelligence/ekipa-remote-access-trojan-designed-by-russian-hacktivists-for-targeted-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=ekipa-remote-access-trojan-designed-by-russian-hacktivists-for-targeted-attacks
Threats:
Ekipa_rat (tags: rat, trojan, malware)
Putty_tool
Geo:
Ukraine, Crimea, Russian, Russia
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 6
07-07-2022
Ekipa Remote Access Trojan Designed by Russian Hacktivists for Targeted Attacks. Executive Summary
https://cloudsek.com/threatintelligence/ekipa-remote-access-trojan-designed-by-russian-hacktivists-for-targeted-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=ekipa-remote-access-trojan-designed-by-russian-hacktivists-for-targeted-attacks
Threats:
Ekipa_rat (tags: rat, trojan, malware)
Putty_tool
Geo:
Ukraine, Crimea, Russian, Russia
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 6
Cloudsek
Ekipa Remote Access Trojan Designed by Russian Hacktivists for “Targeted Attacks” | Threat Intelligence | CloudSEK
XVigil discovered a threat actor advertising a macro RAT (Remote Access Trojan) dubbed “Ekipa", created by Russian hacktivists.
#ParsedReport
07-07-2022
Alert: Malicious campaign on behalf of the Tax and Customs Authority. Indicadores de Compromisso (IoCs)
https://seguranca-informatica.pt/alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira/?utm_source=rss&utm_medium=rss&utm_campaign=alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira
Industry:
Financial, Iot
Geo:
Portugal, Brasil, Portuguese
IOCs:
Url: 2
File: 2
07-07-2022
Alert: Malicious campaign on behalf of the Tax and Customs Authority. Indicadores de Compromisso (IoCs)
https://seguranca-informatica.pt/alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira/?utm_source=rss&utm_medium=rss&utm_campaign=alerta-campanha-maliciosa-em-nome-da-autoridade-tributaria-e-aduaneira
Industry:
Financial, Iot
Geo:
Portugal, Brasil, Portuguese
IOCs:
Url: 2
File: 2
#ParsedReport
06-07-2022
Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&C Server. Arrival
https://www.trendmicro.com/en_us/research/22/g/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html
Threats:
Havanacrypt (tags: ransomware, malware, scan)
IOCs:
File: 8
IP: 1
Url: 3
Hash: 5
Links:
06-07-2022
Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&C Server. Arrival
https://www.trendmicro.com/en_us/research/22/g/brand-new-havanacrypt-ransomware-poses-as-google-software-update.html
Threats:
Havanacrypt (tags: ransomware, malware, scan)
IOCs:
File: 8
IP: 1
Url: 3
Hash: 5
Links:
https://github.com/aramrami/KeePass-2.41/blob/master/KeePassLib/Cryptography/CryptoRandom.cshttps://github.com/DarkObb/DeObfuscar-Statichttps://github.com/obfuscar/obfuscarhttps://github.com/de4dot/de4dotTrend Micro
Brand-New HavanaCrypt Ransomware Poses as Google Software Update App, Uses Microsoft Hosting Service IP Address as C&C Server
We recently found a new ransomware family, which we have dubbed as HavanaCrypt, that disguises itself as a Google Software Update application and uses a Microsoft web hosting service IP address as its command-and-control server to circumvent detection.
#ParsedReport
08-07-2022
Whatever floats your Boat Bitter APT continues to target Bangladesh
https://www.secuinfra.com/en/techtalk/whatever-floats-your-boat-bitter-apt-continues-to-target-bangladesh
Actors/Campaigns:
Bitter (motivation: cyber_espionage)
Threats:
Artradownloader
Zxxz_loader (tags: rat, dns, malware)
Procmon_tool
Cyberchef_tool
Bitter_rat (tags: rat)
Industry:
Transport, Maritime, Financial
Geo:
China, Bangladesh, Chinese, Indian, Asia, Pakistan
CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 5.7,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2017-1182 [Vulners]
Vulners: Score: 5.4, CVSS: 4.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- ibm tivoli monitoring (6.2.2.9, 6.3.0.7, 6.2.3.5)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
CVE-2021-28310 [Vulners]
Vulners: Score: 4.6, CVSS: 6.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1803, 1809, 1909, 2004, 20h2)
- microsoft windows server 2019 (-)
- microsoft windows server 2016 (1909, 2004, 20h2)
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
TTPs:
Tactics: 9
Technics: 11
IOCs:
Hash: 11
File: 7
Path: 2
Domain: 6
IP: 4
Url: 1
Functions Names: 2
YARA: Found
08-07-2022
Whatever floats your Boat Bitter APT continues to target Bangladesh
https://www.secuinfra.com/en/techtalk/whatever-floats-your-boat-bitter-apt-continues-to-target-bangladesh
Actors/Campaigns:
Bitter (motivation: cyber_espionage)
Threats:
Artradownloader
Zxxz_loader (tags: rat, dns, malware)
Procmon_tool
Cyberchef_tool
Bitter_rat (tags: rat)
Industry:
Transport, Maritime, Financial
Geo:
China, Bangladesh, Chinese, Indian, Asia, Pakistan
CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 5.7,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2017-1182 [Vulners]
Vulners: Score: 5.4, CVSS: 4.5,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- ibm tivoli monitoring (6.2.2.9, 6.3.0.7, 6.2.3.5)
CVE-2018-0798 [Vulners]
Vulners: Score: 9.3, CVSS: 9.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2016, 2016, 2007, 2013)
- microsoft word (2013, 2016, 2007, 2010, 2013)
- microsoft office compatibility pack (-)
CVE-2021-28310 [Vulners]
Vulners: Score: 4.6, CVSS: 6.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1803, 1809, 1909, 2004, 20h2)
- microsoft windows server 2019 (-)
- microsoft windows server 2016 (1909, 2004, 20h2)
CVE-2012-0158 [Vulners]
Vulners: Score: 9.3, CVSS: 7.5,
Vulners: Exploitation: True
X-Force: Risk: 9.3
X-Force: Patch: Official fix
Soft:
- microsoft office (2010, 2010, 2003, 2007, 2007)
- microsoft office web components (2003)
- microsoft sql server (2000, 2008, 2008, 2005, 2008, 2008, 2008, 2000, 2005, 2008, 2008, 2005, 2005, 2008, 2008)
- microsoft biztalk server (2002)
- microsoft commerce server (2002, 2007, 2009, 2009)
have more...
TTPs:
Tactics: 9
Technics: 11
IOCs:
Hash: 11
File: 7
Path: 2
Domain: 6
IP: 4
Url: 1
Functions Names: 2
YARA: Found
Secuinfra GmbH
Bitter APT continues to target Bangladesh | SECUINFRA Falcon Team
The SECUINFRA Falcon Team analyzed a recent attack conducted by the south-Asian Advanced Persistent Threat group „Bitter“.
#ParsedReport
08-07-2022
Brute Ratel Utilized By Threat Actors In New Ransomware Operations
https://socradar.io/brute-ratel-utilized-by-threat-actors-in-new-ransomware-operations
Actors/Campaigns:
Duke
Threats:
Brc4_tool (tags: ransomware, rat, phishing, malware)
Checkmate (tags: ransomware)
Red_alert (tags: ransomware)
Raspberry_robin (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Conti
Bumblebee
Geo:
Russian
IOCs:
File: 6
IP: 43
Hash: 15
Domain: 1
08-07-2022
Brute Ratel Utilized By Threat Actors In New Ransomware Operations
https://socradar.io/brute-ratel-utilized-by-threat-actors-in-new-ransomware-operations
Actors/Campaigns:
Duke
Threats:
Brc4_tool (tags: ransomware, rat, phishing, malware)
Checkmate (tags: ransomware)
Red_alert (tags: ransomware)
Raspberry_robin (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Conti
Bumblebee
Geo:
Russian
IOCs:
File: 6
IP: 43
Hash: 15
Domain: 1
SOCRadar® Cyber Intelligence Inc.
Brute Ratel Utilized By Threat Actors In New Ransomware Operations - SOCRadar® Cyber Intelligence Inc.
When Brute Ratel first appeared in the wild, almost no security solutions could detect it. To avoid being discovered by EDR and antivirus programs, hacking
#ParsedReport
08-07-2022
JPCERT/CC Eyes
https://blogs.jpcert.or.jp/en/2022/07/yamabot.html
Actors/Campaigns:
Lazarus
Threats:
Yamabot (tags: malware)
Vsingle (tags: malware)
Geo:
German, Usa, Japan
IOCs:
IP: 2
File: 1
Hash: 2
Links:
08-07-2022
JPCERT/CC Eyes
https://blogs.jpcert.or.jp/en/2022/07/yamabot.html
Actors/Campaigns:
Lazarus
Threats:
Yamabot (tags: malware)
Vsingle (tags: malware)
Geo:
German, Usa, Japan
IOCs:
IP: 2
File: 1
Hash: 2
Links:
https://github.com/JPCERTCC/Lazarus-research/JPCERT/CC Eyes
YamaBot Malware Used by Lazarus - JPCERT/CC Eyes
JPCERT/CC is continuously investigating ...
#ParsedReport
08-07-2022
ABCsoup: The Malicious Adware Extension with 350 Variants
https://blog.zimperium.com/abc-soup-the-malicious-adware-extension-with-350-variants
Geo:
Russian
IOCs:
File: 4
Hash: 136
Functions Names: 3
08-07-2022
ABCsoup: The Malicious Adware Extension with 350 Variants
https://blog.zimperium.com/abc-soup-the-malicious-adware-extension-with-350-variants
Geo:
Russian
IOCs:
File: 4
Hash: 136
Functions Names: 3
Zimperium
ABCsoup: The Malicious Adware Extension with 350 Variants - Zimperium
What can ABCsoup do? Recently Zimperium discovered and began monitoring the growth of a wide range of malicious browser extensions with the same extension
#ParsedReport
08-07-2022
YourCyanide: An Investigation into The Frankenstein Ransomware that Sends Malware Laced Love Letters
https://cloudsek.com/yourcyanide-an-investigation-into-the-frankenstein-ransomware-that-sends-malware-laced-love-letters
Threats:
Yourcyanide (tags: malware, stealer, ransomware, phishing, dropper)
Gonnacope
Kekpop (tags: ransomware)
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 40
Path: 2
Hash: 12
Functions Names: 2
08-07-2022
YourCyanide: An Investigation into The Frankenstein Ransomware that Sends Malware Laced Love Letters
https://cloudsek.com/yourcyanide-an-investigation-into-the-frankenstein-ransomware-that-sends-malware-laced-love-letters
Threats:
Yourcyanide (tags: malware, stealer, ransomware, phishing, dropper)
Gonnacope
Kekpop (tags: ransomware)
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 40
Path: 2
Hash: 12
Functions Names: 2
Cloudsek
YourCyanide: An Investigation into ‘The Frankenstein’ Ransomware that Sends Malware Laced Love Letters | CloudSEK
#ParsedReport
08-07-2022
THREAT ALERT: Raspberry Robin Worm Abuses Windows Installer and QNAP Devices
https://www.cybereason.com/blog/threat-alert-raspberry-robin-worm-abuses-windows-installer-and-qnap-devices
Threats:
Raspberry_robin (tags: rat, malware)
Lolbin
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 13
Hash: 1
Path: 1
Url: 2
Domain: 1
08-07-2022
THREAT ALERT: Raspberry Robin Worm Abuses Windows Installer and QNAP Devices
https://www.cybereason.com/blog/threat-alert-raspberry-robin-worm-abuses-windows-installer-and-qnap-devices
Threats:
Raspberry_robin (tags: rat, malware)
Lolbin
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 13
Hash: 1
Path: 1
Url: 2
Domain: 1
Cybereason
THREAT ALERT: Raspberry Robin Worm Abuses Windows Installer and QNAP Devices
Raspberry Robin involves a worm that spreads over USB devices or shared folders, leveraging compromised QNAP (Network Attached Storage or NAS) devices as stagers and an old but still effective method of using “LNK” shortcut files to lure its victims...