#ParsedReport
08-07-2022
Brute Ratel Utilized By Threat Actors In New Ransomware Operations
https://socradar.io/brute-ratel-utilized-by-threat-actors-in-new-ransomware-operations
Actors/Campaigns:
Duke
Threats:
Brc4_tool (tags: ransomware, rat, phishing, malware)
Checkmate (tags: ransomware)
Red_alert (tags: ransomware)
Raspberry_robin (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Conti
Bumblebee
Geo:
Russian
IOCs:
File: 6
IP: 43
Hash: 15
Domain: 1
08-07-2022
Brute Ratel Utilized By Threat Actors In New Ransomware Operations
https://socradar.io/brute-ratel-utilized-by-threat-actors-in-new-ransomware-operations
Actors/Campaigns:
Duke
Threats:
Brc4_tool (tags: ransomware, rat, phishing, malware)
Checkmate (tags: ransomware)
Red_alert (tags: ransomware)
Raspberry_robin (tags: ransomware)
Cobalt_strike (tags: ransomware)
Beacon (tags: ransomware)
Conti
Bumblebee
Geo:
Russian
IOCs:
File: 6
IP: 43
Hash: 15
Domain: 1
SOCRadar® Cyber Intelligence Inc.
Brute Ratel Utilized By Threat Actors In New Ransomware Operations - SOCRadar® Cyber Intelligence Inc.
When Brute Ratel first appeared in the wild, almost no security solutions could detect it. To avoid being discovered by EDR and antivirus programs, hacking
#ParsedReport
08-07-2022
JPCERT/CC Eyes
https://blogs.jpcert.or.jp/en/2022/07/yamabot.html
Actors/Campaigns:
Lazarus
Threats:
Yamabot (tags: malware)
Vsingle (tags: malware)
Geo:
German, Usa, Japan
IOCs:
IP: 2
File: 1
Hash: 2
Links:
08-07-2022
JPCERT/CC Eyes
https://blogs.jpcert.or.jp/en/2022/07/yamabot.html
Actors/Campaigns:
Lazarus
Threats:
Yamabot (tags: malware)
Vsingle (tags: malware)
Geo:
German, Usa, Japan
IOCs:
IP: 2
File: 1
Hash: 2
Links:
https://github.com/JPCERTCC/Lazarus-research/JPCERT/CC Eyes
YamaBot Malware Used by Lazarus - JPCERT/CC Eyes
JPCERT/CC is continuously investigating ...
#ParsedReport
08-07-2022
ABCsoup: The Malicious Adware Extension with 350 Variants
https://blog.zimperium.com/abc-soup-the-malicious-adware-extension-with-350-variants
Geo:
Russian
IOCs:
File: 4
Hash: 136
Functions Names: 3
08-07-2022
ABCsoup: The Malicious Adware Extension with 350 Variants
https://blog.zimperium.com/abc-soup-the-malicious-adware-extension-with-350-variants
Geo:
Russian
IOCs:
File: 4
Hash: 136
Functions Names: 3
Zimperium
ABCsoup: The Malicious Adware Extension with 350 Variants - Zimperium
What can ABCsoup do? Recently Zimperium discovered and began monitoring the growth of a wide range of malicious browser extensions with the same extension
#ParsedReport
08-07-2022
YourCyanide: An Investigation into The Frankenstein Ransomware that Sends Malware Laced Love Letters
https://cloudsek.com/yourcyanide-an-investigation-into-the-frankenstein-ransomware-that-sends-malware-laced-love-letters
Threats:
Yourcyanide (tags: malware, stealer, ransomware, phishing, dropper)
Gonnacope
Kekpop (tags: ransomware)
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 40
Path: 2
Hash: 12
Functions Names: 2
08-07-2022
YourCyanide: An Investigation into The Frankenstein Ransomware that Sends Malware Laced Love Letters
https://cloudsek.com/yourcyanide-an-investigation-into-the-frankenstein-ransomware-that-sends-malware-laced-love-letters
Threats:
Yourcyanide (tags: malware, stealer, ransomware, phishing, dropper)
Gonnacope
Kekpop (tags: ransomware)
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 40
Path: 2
Hash: 12
Functions Names: 2
Cloudsek
YourCyanide: An Investigation into ‘The Frankenstein’ Ransomware that Sends Malware Laced Love Letters | CloudSEK
#ParsedReport
08-07-2022
THREAT ALERT: Raspberry Robin Worm Abuses Windows Installer and QNAP Devices
https://www.cybereason.com/blog/threat-alert-raspberry-robin-worm-abuses-windows-installer-and-qnap-devices
Threats:
Raspberry_robin (tags: rat, malware)
Lolbin
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 13
Hash: 1
Path: 1
Url: 2
Domain: 1
08-07-2022
THREAT ALERT: Raspberry Robin Worm Abuses Windows Installer and QNAP Devices
https://www.cybereason.com/blog/threat-alert-raspberry-robin-worm-abuses-windows-installer-and-qnap-devices
Threats:
Raspberry_robin (tags: rat, malware)
Lolbin
Industry:
Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 13
Hash: 1
Path: 1
Url: 2
Domain: 1
Cybereason
THREAT ALERT: Raspberry Robin Worm Abuses Windows Installer and QNAP Devices
Raspberry Robin involves a worm that spreads over USB devices or shared folders, leveraging compromised QNAP (Network Attached Storage or NAS) devices as stagers and an old but still effective method of using “LNK” shortcut files to lure its victims...
#ParsedReport
08-07-2022
NoMercy Stealer Adding New Features. New Stealer Rapidly Evolving into Clipper Malware
https://blog.cyble.com/2022/07/07/nomercy-stealer-adding-new-features
Geo:
Indian
TTPs:
Tactics: 5
Technics: 15
IOCs:
Url: 3
File: 3
IP: 1
Hash: 1
Functions Names: 4
08-07-2022
NoMercy Stealer Adding New Features. New Stealer Rapidly Evolving into Clipper Malware
https://blog.cyble.com/2022/07/07/nomercy-stealer-adding-new-features
Geo:
Indian
TTPs:
Tactics: 5
Technics: 15
IOCs:
Url: 3
File: 3
IP: 1
Hash: 1
Functions Names: 4
Cyble
NoMercy Stealer Adding New Features
Cyble analyzes NoMercy Stealer, a new information stealer evolving into Clipper Malware.
#ParsedReport
08-07-2022
THREAT ANALYSIS REPORT: LockBit 2.0 - All Paths Lead to Ransom
https://www.cybereason.com/blog/threat-analysis-report-lockbit-2.0-all-paths-lead-to-ransom
Actors/Campaigns:
Volatile_cedar
Ember_bear
Threats:
Lockbit (tags: phishing, vpn, ransomware, proxy, scan, malware)
Megasync_tool
Magnitude
Mimikatz
Netscan_tool
Spoolfool_vuln
Psexec_tool (tags: ransomware)
Wevtutil_tool
Neshta
Revil
Winrm_tool
Industry:
Telco, Retail, Financial, Government
Geo:
Cyprus, Russia
CVEs:
CVE-2022-21999 [Vulners]
Vulners: Score: 4.6, CVSS: 6.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, -, 1607, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 1809, 1809, 1809, 1909, 1909, 1909, 21h2, 21h2, 21h2)
- microsoft windows server 2008 (r2, -, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows server 2016 (-)
- microsoft windows rt 8.1 (-)
have more...
TTPs:
Tactics: 5
Technics: 0
IOCs:
File: 22
Path: 6
Registry: 1
IP: 2
Domain: 1
Hash: 2
Functions Names: 1
08-07-2022
THREAT ANALYSIS REPORT: LockBit 2.0 - All Paths Lead to Ransom
https://www.cybereason.com/blog/threat-analysis-report-lockbit-2.0-all-paths-lead-to-ransom
Actors/Campaigns:
Volatile_cedar
Ember_bear
Threats:
Lockbit (tags: phishing, vpn, ransomware, proxy, scan, malware)
Megasync_tool
Magnitude
Mimikatz
Netscan_tool
Spoolfool_vuln
Psexec_tool (tags: ransomware)
Wevtutil_tool
Neshta
Revil
Winrm_tool
Industry:
Telco, Retail, Financial, Government
Geo:
Cyprus, Russia
CVEs:
CVE-2022-21999 [Vulners]
Vulners: Score: 4.6, CVSS: 6.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, -, 1607, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 1809, 1809, 1809, 1909, 1909, 1909, 21h2, 21h2, 21h2)
- microsoft windows server 2008 (r2, -, -)
- microsoft windows server 2012 (r2, -)
- microsoft windows server 2016 (-)
- microsoft windows rt 8.1 (-)
have more...
TTPs:
Tactics: 5
Technics: 0
IOCs:
File: 22
Path: 6
Registry: 1
IP: 2
Domain: 1
Hash: 2
Functions Names: 1
Cybereason
THREAT ANALYSIS REPORT: LockBit 2.0 - All Paths Lead to Ransom
LockBit 2.0 ransomware attackers are constantly evolving and making detection, investigation, and prevention more complex by disabling EDR and other security products and deleting the evidence to stifle forensics attempts...
#ParsedReport
08-07-2022
Vice Society: a discreet but steady double extortion ransomware group
https://blog.sekoia.io/vice-society-a-discreet-but-steady-double-extortion-ransomware-group
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Zeppelin (tags: ransomware)
Hellokitty (tags: ransomware)
Printnightmare_vuln
Vega_locker
Industry:
Healthcare, Government, Education
Geo:
Germany, France, Italy, America, Usa, Brazil, Spain
IOCs:
Email: 1
Hash: 7
YARA: Found
Links:
08-07-2022
Vice Society: a discreet but steady double extortion ransomware group
https://blog.sekoia.io/vice-society-a-discreet-but-steady-double-extortion-ransomware-group
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Zeppelin (tags: ransomware)
Hellokitty (tags: ransomware)
Printnightmare_vuln
Vega_locker
Industry:
Healthcare, Government, Education
Geo:
Germany, France, Italy, America, Usa, Brazil, Spain
IOCs:
Email: 1
Hash: 7
YARA: Found
Links:
https://github.com/reversinglabs/reversinglabs-yara-rules/blob/develop/yara/ransomware/Win32.Ransomware.Zeppelin.yaraSekoia.io Blog
Vice Society: a discreet but steady double extortion ransomware group
Vice Society is a little-known double extortion group. It showed a steady activity, encrypting and exfiltrating its victim’s data and threatening their victims to leak their information to pressure them into paying a ransom.
#ParsedReport
09-07-2022
Pseudo-APT-C-23 (Futao ) Organizational Equipment Threema Communication Case Attack Analysis
https://mp-weixin-qq-com.translate.goog/s/1uJaPS-nuGNI8lQ1-ZekIA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Aridviper
Threats:
Houdini_rat (tags: rat, dns)
Vamp
Njrat_rat
Industry:
Education
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 21
IP: 1
09-07-2022
Pseudo-APT-C-23 (Futao ) Organizational Equipment Threema Communication Case Attack Analysis
https://mp-weixin-qq-com.translate.goog/s/1uJaPS-nuGNI8lQ1-ZekIA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Aridviper
Threats:
Houdini_rat (tags: rat, dns)
Vamp
Njrat_rat
Industry:
Education
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 21
IP: 1
微信公众平台
疑似APT-C-23(双尾蝎)组织伪装Threema通讯软件攻击分析
以前的双尾蝎样本大多采用VC 版本、Delphi 版本,很少见到使用公开商业RAT组件进行攻击,此次发现的样本可能是该组织进攻方式的演变,也可能是双尾蝎组织内部出现的新的分支成员所采用的攻击手法
#ParsedReport
09-07-2022
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor
Threats:
Follina_vuln (tags: ransomware, backdoor, rat, malware)
Rozena (tags: backdoor, ransomware, rat, malware)
Metasploit_tool (tags: rat)
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 6
File: 12
Url: 1
Domain: 1
Functions Names: 1
09-07-2022
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor
Threats:
Follina_vuln (tags: ransomware, backdoor, rat, malware)
Rozena (tags: backdoor, ransomware, rat, malware)
Metasploit_tool (tags: rat)
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 6
File: 12
Url: 1
Domain: 1
Functions Names: 1
Fortinet Blog
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
FortiGuard Labs recently discovered a document that exploits CVE-2022-30190 (Follina) to trigger the download of the Rozena malware, capable of injecting a remote shell connection back to the attac…
#ParsedReport
09-07-2022
Koh: The Token Stealer. Motivation
https://posts.specterops.io/koh-the-token-stealer-41ca07a40ed6
Threats:
Koh_stealer (tags: stealer)
Cobalt_strike (tags: stealer)
Mimikatz
Psexec_tool
Geo:
Usa
IOCs:
File: 2
Functions Names: 15
Links:
09-07-2022
Koh: The Token Stealer. Motivation
https://posts.specterops.io/koh-the-token-stealer-41ca07a40ed6
Threats:
Koh_stealer (tags: stealer)
Cobalt_strike (tags: stealer)
Mimikatz
Psexec_tool
Geo:
Usa
IOCs:
File: 2
Functions Names: 15
Links:
https://github.com/GhostPack/Kohhttps://github.com/GhostPack/Rubeus#example-credential-extractionhttps://github.com/anthemtotheego/InlineExecute-Assemblyhttps://github.com/outflanknl/Dumperthttps://github.com/gentilkiwi/mimikatzhttps://github.com/eladshamir/Internal-Monologuehttps://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Out-Minidump.ps1https://github.com/GhostPack/Koh/issueshttps://github.com/GhostPack/SharpDPAPI/https://github.com/kyleavery/inject-assemblyhttps://github.com/GhostPack/Koh/blob/master/README.md#the-inline-shenanigans-bughttps://github.com/gentilkiwi/mimikatz/https://github.com/b4rtik/ATPMiniDumphttps://github.com/GhostPack/RubeusMedium
Koh: The Token Stealer
Edit 07/13/22: After an awesome back and forth with Clément Notin and @SteveSyfuhs on Twitter on the effects of “TokenLeakDetectDelaySecs”…
#ParsedReport
09-07-2022
Magniber Ransomware, Changes in Injection Method
https://asec-ahnlab-com.translate.goog/ko/36276/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Magniber (tags: malware, ransomware)
IOCs:
File: 5
Path: 1
Hash: 2
09-07-2022
Magniber Ransomware, Changes in Injection Method
https://asec-ahnlab-com.translate.goog/ko/36276/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Magniber (tags: malware, ransomware)
IOCs:
File: 5
Path: 1
Hash: 2
ASEC BLOG
매그니베르(Magniber) 랜섬웨어, 인젝션 방식의 변화 - ASEC BLOG
ASEC 분석팀은 높은 유포건수를 보이는 매그니베르(Magniber) 랜섬웨어를 꾸준히 모니터링하고 있다. 매그니베르 랜섬웨어는 최근 몇년간 IE 취약점을 통해 유포되었지만, IE(Internet Explorer)의 지원 종료시기를 기점으로 IE 취약점 유포를 중단하였다. 그리고 최근 매그니베르 랜섬웨어는 Edge, Chrome 브라우저에서 Windows 설치 패키지 파일(.msi)로 유포되고 있다. Windows 설치 패키지 파일(.msi) 로 유포되는…
#ParsedReport
10-07-2022
Anubis Networks is back with new C2 server. Fake domains hosted automatically on Cloudflare CDN
https://seguranca-informatica.pt/anubis-networks-is-back-with-new-c2-server/?utm_source=rss&utm_medium=rss&utm_campaign=anubis-networks-is-back-with-new-c2-server
Threats:
Anubis (tags: dns, malware, phishing)
Industry:
Education, Financial, Iot
Geo:
Brazilian, Portugal, Portuguese, Brazil
IOCs:
Email: 78
File: 2
10-07-2022
Anubis Networks is back with new C2 server. Fake domains hosted automatically on Cloudflare CDN
https://seguranca-informatica.pt/anubis-networks-is-back-with-new-c2-server/?utm_source=rss&utm_medium=rss&utm_campaign=anubis-networks-is-back-with-new-c2-server
Threats:
Anubis (tags: dns, malware, phishing)
Industry:
Education, Financial, Iot
Geo:
Brazilian, Portugal, Portuguese, Brazil
IOCs:
Email: 78
File: 2
#ParsedReport
10-07-2022
North Korean APT targets US healthcare sector with Maui ransomware
https://blog.malwarebytes.com/ransomware/2022/07/north-korean-apt-targets-us-healthcare-sector-with-maui-ransomware
Threats:
Mauicrypt (tags: ransomware, malware)
Conti (tags: ransomware)
Shione (tags: ransomware)
Industry:
Healthcare
Geo:
Korean
IOCs:
File: 1
10-07-2022
North Korean APT targets US healthcare sector with Maui ransomware
https://blog.malwarebytes.com/ransomware/2022/07/north-korean-apt-targets-us-healthcare-sector-with-maui-ransomware
Threats:
Mauicrypt (tags: ransomware, malware)
Conti (tags: ransomware)
Shione (tags: ransomware)
Industry:
Healthcare
Geo:
Korean
IOCs:
File: 1
Malwarebytes Labs
North Korean APT targets US healthcare sector with Maui ransomware
CISA warns of an unusual ransomware.
#ParsedReport
11-07-2022
SELECT XMRig FROM SQLServer
https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver
Threats:
Xmrig_miner (tags: cryptomining, rat, dropper, malware)
Thor
Cyberchef_tool
Geo:
Chinese
TTPs:
Tactics: 8
Technics: 14
IOCs:
File: 32
Path: 8
Domain: 3
Url: 1
Registry: 4
Coin: 1
Hash: 7
Email: 1
YARA: Found
SIGMA: Found
Links:
11-07-2022
SELECT XMRig FROM SQLServer
https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver
Threats:
Xmrig_miner (tags: cryptomining, rat, dropper, malware)
Thor
Cyberchef_tool
Geo:
Chinese
TTPs:
Tactics: 8
Technics: 14
IOCs:
File: 32
Path: 8
Domain: 3
Url: 1
Registry: 4
Coin: 1
Hash: 7
Email: 1
YARA: Found
SIGMA: Found
Links:
https://github.com/decoder-it/NetworkServiceExploitThe DFIR Report
SELECT XMRig FROM SQLServer
In March 2022, we observed an intrusion on a public-facing Microsoft SQL Server. The end goal of this intrusion was to deploy a coin miner. Although deploying a coin miner on a vulnerable server af…
#ParsedReport
11-07-2022
Meterpreter Distributed to Vulnerable Server of Korean Medical Institution
https://asec.ahnlab.com/en/36397
Threats:
Meterpreter_tool (tags: malware, scan, backdoor, ransomware)
Samsam
Smokeloader
Metasploit_tool
Malware/mdp.download.m1900
Industry:
Healthcare
Geo:
Korean
IOCs:
File: 9
Path: 5
Hash: 3
IP: 1
Url: 3
Links:
11-07-2022
Meterpreter Distributed to Vulnerable Server of Korean Medical Institution
https://asec.ahnlab.com/en/36397
Threats:
Meterpreter_tool (tags: malware, scan, backdoor, ransomware)
Samsam
Smokeloader
Metasploit_tool
Malware/mdp.download.m1900
Industry:
Healthcare
Geo:
Korean
IOCs:
File: 9
Path: 5
Hash: 3
IP: 1
Url: 3
Links:
https://github.com/joaomatosf/jexbossASEC BLOG
Meterpreter Distributed to Vulnerable Server of Korean Medical Institution - ASEC BLOG
While monitoring malware strains distributed to vulnerable servers, the ASEC analysis team discovered an attack case for PACS (Picture Archiving and Communication System) server used by Korean medical institutions. PACS is a system for digitally managing…
#ParsedReport
11-07-2022
AppleSeed Disguised as Purchase Order and Request Form Being Distributed
https://asec.ahnlab.com/en/36368
Actors/Campaigns:
Kimsuky
Threats:
Appleseed (tags: dropper, backdoor, malware)
IOCs:
File: 2
Hash: 4
Url: 2
11-07-2022
AppleSeed Disguised as Purchase Order and Request Form Being Distributed
https://asec.ahnlab.com/en/36368
Actors/Campaigns:
Kimsuky
Threats:
Appleseed (tags: dropper, backdoor, malware)
IOCs:
File: 2
Hash: 4
Url: 2
ASEC BLOG
AppleSeed Disguised as Purchase Order and Request Form Being Distributed - ASEC BLOG
The ASEC analysis team has recently discovered the distribution of AppleSeed disguised as purchase orders and request forms. AppleSeed is a backdoor malware mainly used by the Kimsuky group. It stays in the system and performs malicious behaviors by receiving…
#ParsedReport
11-07-2022
Ransomware Spotlight: BlackByte
https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte
Threats:
Blackbyte (tags: rat, phishing, malware, ransomware)
Ransomexx (tags: ransomware)
Avoslocker (tags: ransomware)
Clop (tags: ransomware)
Lockbit (tags: ransomware)
Conti (tags: ransomware)
Proxyshell_vuln (tags: malware)
Cobalt_strike (tags: malware)
Netscan_tool (tags: malware)
Chinachopper (tags: malware)
Industry:
Retail, Foodtech, Financial, Energy, Entertainment, Ics, Government, Healthcare, Transport
Geo:
Russia, America, Peru, American, China
TTPs:
Tactics: 3
Technics: 14
IOCs:
Domain: 2
File: 16
Path: 2
Registry: 2
Url: 2
Coin: 1
11-07-2022
Ransomware Spotlight: BlackByte
https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte
Threats:
Blackbyte (tags: rat, phishing, malware, ransomware)
Ransomexx (tags: ransomware)
Avoslocker (tags: ransomware)
Clop (tags: ransomware)
Lockbit (tags: ransomware)
Conti (tags: ransomware)
Proxyshell_vuln (tags: malware)
Cobalt_strike (tags: malware)
Netscan_tool (tags: malware)
Chinachopper (tags: malware)
Industry:
Retail, Foodtech, Financial, Energy, Entertainment, Ics, Government, Healthcare, Transport
Geo:
Russia, America, Peru, American, China
TTPs:
Tactics: 3
Technics: 14
IOCs:
Domain: 2
File: 16
Path: 2
Registry: 2
Url: 2
Coin: 1
Trendmicro
Ransomware Spotlight: BlackByte
BlackByte is a ransomware group that has been building a name for itself since 2021. Like its contemporaries, it has gone after critical infrastructure for a higher chance of getting a payout. What techniques sets it apart?
#ParsedReport
11-07-2022
Minerva Labs Blog
https://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Actors/Campaigns:
Blackcat
Threats:
Lockbit (tags: ransomware, cryptomining)
Geo:
Russian, Belarusian, Moldova, Syria, Romanian, Ukrainian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Functions Names: 4
11-07-2022
Minerva Labs Blog
https://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Actors/Campaigns:
Blackcat
Threats:
Lockbit (tags: ransomware, cryptomining)
Geo:
Russian, Belarusian, Moldova, Syria, Romanian, Ukrainian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Functions Names: 4
Minerva-Labs
Lockbit 3.0 AKA Lockbit Black is here, with a new icon, new ransom note, new wallpaper, but less evasiveness?
Lockbit 3.0, also known as Lockbit Black was recently released and has already claimed its first victims. We dive into how it works and how you can protect yourselves
#ParsedReport
11-07-2022
Amadey Bot disseminating via SmokeLoader
https://asec-ahnlab-com.translate.goog/ko/36419/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Ta505
Threats:
Amadey (tags: rat, malware, stealer, ransomware, vpn)
Smokeloader (tags: rat, malware, stealer, ransomware, vpn)
Gandcrab
Flawedammyy
Clop
Rig_tool
Redline_stealer
Tightvnc_tool
Trojan/win.malpe.r503126
Delf
Trojan/win.generic.r503640
Malware/win.trojanspy.r438708
Malware/mdp.download.m1197
IOCs:
File: 16
Path: 7
Registry: 1
Url: 15
Hash: 10
IP: 1
Functions Names: 1
11-07-2022
Amadey Bot disseminating via SmokeLoader
https://asec-ahnlab-com.translate.goog/ko/36419/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Ta505
Threats:
Amadey (tags: rat, malware, stealer, ransomware, vpn)
Smokeloader (tags: rat, malware, stealer, ransomware, vpn)
Gandcrab
Flawedammyy
Clop
Rig_tool
Redline_stealer
Tightvnc_tool
Trojan/win.malpe.r503126
Delf
Trojan/win.generic.r503640
Malware/win.trojanspy.r438708
Malware/mdp.download.m1197
IOCs:
File: 16
Path: 7
Registry: 1
Url: 15
Hash: 10
IP: 1
Functions Names: 1
ASEC BLOG
SmokeLoader를 통해 유포 중인 Amadey Bot - ASEC BLOG
Amadey Bot은 2018년경부터 확인되는 악성코드로서 공격자의 명령을 받아 정보 탈취나 추가 악성코드를 설치할 수 있다. 일반적인 악성코드들처럼 Amadey 또한 불법 포럼 등을 통해 판매되고 있으며, 이에 따라 현재까지도 다양한 공격자들에 의해 사용되고 있다. ASEC 분석팀에서는 2019년 ASEC 블로그를 통해 Amadey가 공격에 사용된 사례들을 공개한 바 있다. 대표적으로 GandCrab 랜섬웨어 공격자들에 의해 랜섬웨어를 설치하는 데 사용되거나…