#ParsedReport
08-07-2022
Vice Society: a discreet but steady double extortion ransomware group
https://blog.sekoia.io/vice-society-a-discreet-but-steady-double-extortion-ransomware-group
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Zeppelin (tags: ransomware)
Hellokitty (tags: ransomware)
Printnightmare_vuln
Vega_locker
Industry:
Healthcare, Government, Education
Geo:
Germany, France, Italy, America, Usa, Brazil, Spain
IOCs:
Email: 1
Hash: 7
YARA: Found
Links:
08-07-2022
Vice Society: a discreet but steady double extortion ransomware group
https://blog.sekoia.io/vice-society-a-discreet-but-steady-double-extortion-ransomware-group
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Zeppelin (tags: ransomware)
Hellokitty (tags: ransomware)
Printnightmare_vuln
Vega_locker
Industry:
Healthcare, Government, Education
Geo:
Germany, France, Italy, America, Usa, Brazil, Spain
IOCs:
Email: 1
Hash: 7
YARA: Found
Links:
https://github.com/reversinglabs/reversinglabs-yara-rules/blob/develop/yara/ransomware/Win32.Ransomware.Zeppelin.yaraSekoia.io Blog
Vice Society: a discreet but steady double extortion ransomware group
Vice Society is a little-known double extortion group. It showed a steady activity, encrypting and exfiltrating its victim’s data and threatening their victims to leak their information to pressure them into paying a ransom.
#ParsedReport
09-07-2022
Pseudo-APT-C-23 (Futao ) Organizational Equipment Threema Communication Case Attack Analysis
https://mp-weixin-qq-com.translate.goog/s/1uJaPS-nuGNI8lQ1-ZekIA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Aridviper
Threats:
Houdini_rat (tags: rat, dns)
Vamp
Njrat_rat
Industry:
Education
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 21
IP: 1
09-07-2022
Pseudo-APT-C-23 (Futao ) Organizational Equipment Threema Communication Case Attack Analysis
https://mp-weixin-qq-com.translate.goog/s/1uJaPS-nuGNI8lQ1-ZekIA?_x_tr_sl=ja&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp
Actors/Campaigns:
Aridviper
Threats:
Houdini_rat (tags: rat, dns)
Vamp
Njrat_rat
Industry:
Education
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 21
IP: 1
微信公众平台
疑似APT-C-23(双尾蝎)组织伪装Threema通讯软件攻击分析
以前的双尾蝎样本大多采用VC 版本、Delphi 版本,很少见到使用公开商业RAT组件进行攻击,此次发现的样本可能是该组织进攻方式的演变,也可能是双尾蝎组织内部出现的新的分支成员所采用的攻击手法
#ParsedReport
09-07-2022
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor
Threats:
Follina_vuln (tags: ransomware, backdoor, rat, malware)
Rozena (tags: backdoor, ransomware, rat, malware)
Metasploit_tool (tags: rat)
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 6
File: 12
Url: 1
Domain: 1
Functions Names: 1
09-07-2022
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
https://www.fortinet.com/blog/threat-research/follina-rozena-leveraging-discord-to-distribute-a-backdoor
Threats:
Follina_vuln (tags: ransomware, backdoor, rat, malware)
Rozena (tags: backdoor, ransomware, rat, malware)
Metasploit_tool (tags: rat)
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 6
File: 12
Url: 1
Domain: 1
Functions Names: 1
Fortinet Blog
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
FortiGuard Labs recently discovered a document that exploits CVE-2022-30190 (Follina) to trigger the download of the Rozena malware, capable of injecting a remote shell connection back to the attac…
#ParsedReport
09-07-2022
Koh: The Token Stealer. Motivation
https://posts.specterops.io/koh-the-token-stealer-41ca07a40ed6
Threats:
Koh_stealer (tags: stealer)
Cobalt_strike (tags: stealer)
Mimikatz
Psexec_tool
Geo:
Usa
IOCs:
File: 2
Functions Names: 15
Links:
09-07-2022
Koh: The Token Stealer. Motivation
https://posts.specterops.io/koh-the-token-stealer-41ca07a40ed6
Threats:
Koh_stealer (tags: stealer)
Cobalt_strike (tags: stealer)
Mimikatz
Psexec_tool
Geo:
Usa
IOCs:
File: 2
Functions Names: 15
Links:
https://github.com/GhostPack/Kohhttps://github.com/GhostPack/Rubeus#example-credential-extractionhttps://github.com/anthemtotheego/InlineExecute-Assemblyhttps://github.com/outflanknl/Dumperthttps://github.com/gentilkiwi/mimikatzhttps://github.com/eladshamir/Internal-Monologuehttps://github.com/PowerShellMafia/PowerSploit/blob/master/Exfiltration/Out-Minidump.ps1https://github.com/GhostPack/Koh/issueshttps://github.com/GhostPack/SharpDPAPI/https://github.com/kyleavery/inject-assemblyhttps://github.com/GhostPack/Koh/blob/master/README.md#the-inline-shenanigans-bughttps://github.com/gentilkiwi/mimikatz/https://github.com/b4rtik/ATPMiniDumphttps://github.com/GhostPack/RubeusMedium
Koh: The Token Stealer
Edit 07/13/22: After an awesome back and forth with Clément Notin and @SteveSyfuhs on Twitter on the effects of “TokenLeakDetectDelaySecs”…
#ParsedReport
09-07-2022
Magniber Ransomware, Changes in Injection Method
https://asec-ahnlab-com.translate.goog/ko/36276/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Magniber (tags: malware, ransomware)
IOCs:
File: 5
Path: 1
Hash: 2
09-07-2022
Magniber Ransomware, Changes in Injection Method
https://asec-ahnlab-com.translate.goog/ko/36276/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Magniber (tags: malware, ransomware)
IOCs:
File: 5
Path: 1
Hash: 2
ASEC BLOG
매그니베르(Magniber) 랜섬웨어, 인젝션 방식의 변화 - ASEC BLOG
ASEC 분석팀은 높은 유포건수를 보이는 매그니베르(Magniber) 랜섬웨어를 꾸준히 모니터링하고 있다. 매그니베르 랜섬웨어는 최근 몇년간 IE 취약점을 통해 유포되었지만, IE(Internet Explorer)의 지원 종료시기를 기점으로 IE 취약점 유포를 중단하였다. 그리고 최근 매그니베르 랜섬웨어는 Edge, Chrome 브라우저에서 Windows 설치 패키지 파일(.msi)로 유포되고 있다. Windows 설치 패키지 파일(.msi) 로 유포되는…
#ParsedReport
10-07-2022
Anubis Networks is back with new C2 server. Fake domains hosted automatically on Cloudflare CDN
https://seguranca-informatica.pt/anubis-networks-is-back-with-new-c2-server/?utm_source=rss&utm_medium=rss&utm_campaign=anubis-networks-is-back-with-new-c2-server
Threats:
Anubis (tags: dns, malware, phishing)
Industry:
Education, Financial, Iot
Geo:
Brazilian, Portugal, Portuguese, Brazil
IOCs:
Email: 78
File: 2
10-07-2022
Anubis Networks is back with new C2 server. Fake domains hosted automatically on Cloudflare CDN
https://seguranca-informatica.pt/anubis-networks-is-back-with-new-c2-server/?utm_source=rss&utm_medium=rss&utm_campaign=anubis-networks-is-back-with-new-c2-server
Threats:
Anubis (tags: dns, malware, phishing)
Industry:
Education, Financial, Iot
Geo:
Brazilian, Portugal, Portuguese, Brazil
IOCs:
Email: 78
File: 2
#ParsedReport
10-07-2022
North Korean APT targets US healthcare sector with Maui ransomware
https://blog.malwarebytes.com/ransomware/2022/07/north-korean-apt-targets-us-healthcare-sector-with-maui-ransomware
Threats:
Mauicrypt (tags: ransomware, malware)
Conti (tags: ransomware)
Shione (tags: ransomware)
Industry:
Healthcare
Geo:
Korean
IOCs:
File: 1
10-07-2022
North Korean APT targets US healthcare sector with Maui ransomware
https://blog.malwarebytes.com/ransomware/2022/07/north-korean-apt-targets-us-healthcare-sector-with-maui-ransomware
Threats:
Mauicrypt (tags: ransomware, malware)
Conti (tags: ransomware)
Shione (tags: ransomware)
Industry:
Healthcare
Geo:
Korean
IOCs:
File: 1
Malwarebytes Labs
North Korean APT targets US healthcare sector with Maui ransomware
CISA warns of an unusual ransomware.
#ParsedReport
11-07-2022
SELECT XMRig FROM SQLServer
https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver
Threats:
Xmrig_miner (tags: cryptomining, rat, dropper, malware)
Thor
Cyberchef_tool
Geo:
Chinese
TTPs:
Tactics: 8
Technics: 14
IOCs:
File: 32
Path: 8
Domain: 3
Url: 1
Registry: 4
Coin: 1
Hash: 7
Email: 1
YARA: Found
SIGMA: Found
Links:
11-07-2022
SELECT XMRig FROM SQLServer
https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver
Threats:
Xmrig_miner (tags: cryptomining, rat, dropper, malware)
Thor
Cyberchef_tool
Geo:
Chinese
TTPs:
Tactics: 8
Technics: 14
IOCs:
File: 32
Path: 8
Domain: 3
Url: 1
Registry: 4
Coin: 1
Hash: 7
Email: 1
YARA: Found
SIGMA: Found
Links:
https://github.com/decoder-it/NetworkServiceExploitThe DFIR Report
SELECT XMRig FROM SQLServer
In March 2022, we observed an intrusion on a public-facing Microsoft SQL Server. The end goal of this intrusion was to deploy a coin miner. Although deploying a coin miner on a vulnerable server af…
#ParsedReport
11-07-2022
Meterpreter Distributed to Vulnerable Server of Korean Medical Institution
https://asec.ahnlab.com/en/36397
Threats:
Meterpreter_tool (tags: malware, scan, backdoor, ransomware)
Samsam
Smokeloader
Metasploit_tool
Malware/mdp.download.m1900
Industry:
Healthcare
Geo:
Korean
IOCs:
File: 9
Path: 5
Hash: 3
IP: 1
Url: 3
Links:
11-07-2022
Meterpreter Distributed to Vulnerable Server of Korean Medical Institution
https://asec.ahnlab.com/en/36397
Threats:
Meterpreter_tool (tags: malware, scan, backdoor, ransomware)
Samsam
Smokeloader
Metasploit_tool
Malware/mdp.download.m1900
Industry:
Healthcare
Geo:
Korean
IOCs:
File: 9
Path: 5
Hash: 3
IP: 1
Url: 3
Links:
https://github.com/joaomatosf/jexbossASEC BLOG
Meterpreter Distributed to Vulnerable Server of Korean Medical Institution - ASEC BLOG
While monitoring malware strains distributed to vulnerable servers, the ASEC analysis team discovered an attack case for PACS (Picture Archiving and Communication System) server used by Korean medical institutions. PACS is a system for digitally managing…
#ParsedReport
11-07-2022
AppleSeed Disguised as Purchase Order and Request Form Being Distributed
https://asec.ahnlab.com/en/36368
Actors/Campaigns:
Kimsuky
Threats:
Appleseed (tags: dropper, backdoor, malware)
IOCs:
File: 2
Hash: 4
Url: 2
11-07-2022
AppleSeed Disguised as Purchase Order and Request Form Being Distributed
https://asec.ahnlab.com/en/36368
Actors/Campaigns:
Kimsuky
Threats:
Appleseed (tags: dropper, backdoor, malware)
IOCs:
File: 2
Hash: 4
Url: 2
ASEC BLOG
AppleSeed Disguised as Purchase Order and Request Form Being Distributed - ASEC BLOG
The ASEC analysis team has recently discovered the distribution of AppleSeed disguised as purchase orders and request forms. AppleSeed is a backdoor malware mainly used by the Kimsuky group. It stays in the system and performs malicious behaviors by receiving…
#ParsedReport
11-07-2022
Ransomware Spotlight: BlackByte
https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte
Threats:
Blackbyte (tags: rat, phishing, malware, ransomware)
Ransomexx (tags: ransomware)
Avoslocker (tags: ransomware)
Clop (tags: ransomware)
Lockbit (tags: ransomware)
Conti (tags: ransomware)
Proxyshell_vuln (tags: malware)
Cobalt_strike (tags: malware)
Netscan_tool (tags: malware)
Chinachopper (tags: malware)
Industry:
Retail, Foodtech, Financial, Energy, Entertainment, Ics, Government, Healthcare, Transport
Geo:
Russia, America, Peru, American, China
TTPs:
Tactics: 3
Technics: 14
IOCs:
Domain: 2
File: 16
Path: 2
Registry: 2
Url: 2
Coin: 1
11-07-2022
Ransomware Spotlight: BlackByte
https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte
Threats:
Blackbyte (tags: rat, phishing, malware, ransomware)
Ransomexx (tags: ransomware)
Avoslocker (tags: ransomware)
Clop (tags: ransomware)
Lockbit (tags: ransomware)
Conti (tags: ransomware)
Proxyshell_vuln (tags: malware)
Cobalt_strike (tags: malware)
Netscan_tool (tags: malware)
Chinachopper (tags: malware)
Industry:
Retail, Foodtech, Financial, Energy, Entertainment, Ics, Government, Healthcare, Transport
Geo:
Russia, America, Peru, American, China
TTPs:
Tactics: 3
Technics: 14
IOCs:
Domain: 2
File: 16
Path: 2
Registry: 2
Url: 2
Coin: 1
Trendmicro
Ransomware Spotlight: BlackByte
BlackByte is a ransomware group that has been building a name for itself since 2021. Like its contemporaries, it has gone after critical infrastructure for a higher chance of getting a payout. What techniques sets it apart?
#ParsedReport
11-07-2022
Minerva Labs Blog
https://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Actors/Campaigns:
Blackcat
Threats:
Lockbit (tags: ransomware, cryptomining)
Geo:
Russian, Belarusian, Moldova, Syria, Romanian, Ukrainian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Functions Names: 4
11-07-2022
Minerva Labs Blog
https://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Actors/Campaigns:
Blackcat
Threats:
Lockbit (tags: ransomware, cryptomining)
Geo:
Russian, Belarusian, Moldova, Syria, Romanian, Ukrainian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Functions Names: 4
Minerva-Labs
Lockbit 3.0 AKA Lockbit Black is here, with a new icon, new ransom note, new wallpaper, but less evasiveness?
Lockbit 3.0, also known as Lockbit Black was recently released and has already claimed its first victims. We dive into how it works and how you can protect yourselves
#ParsedReport
11-07-2022
Amadey Bot disseminating via SmokeLoader
https://asec-ahnlab-com.translate.goog/ko/36419/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Ta505
Threats:
Amadey (tags: rat, malware, stealer, ransomware, vpn)
Smokeloader (tags: rat, malware, stealer, ransomware, vpn)
Gandcrab
Flawedammyy
Clop
Rig_tool
Redline_stealer
Tightvnc_tool
Trojan/win.malpe.r503126
Delf
Trojan/win.generic.r503640
Malware/win.trojanspy.r438708
Malware/mdp.download.m1197
IOCs:
File: 16
Path: 7
Registry: 1
Url: 15
Hash: 10
IP: 1
Functions Names: 1
11-07-2022
Amadey Bot disseminating via SmokeLoader
https://asec-ahnlab-com.translate.goog/ko/36419/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Ta505
Threats:
Amadey (tags: rat, malware, stealer, ransomware, vpn)
Smokeloader (tags: rat, malware, stealer, ransomware, vpn)
Gandcrab
Flawedammyy
Clop
Rig_tool
Redline_stealer
Tightvnc_tool
Trojan/win.malpe.r503126
Delf
Trojan/win.generic.r503640
Malware/win.trojanspy.r438708
Malware/mdp.download.m1197
IOCs:
File: 16
Path: 7
Registry: 1
Url: 15
Hash: 10
IP: 1
Functions Names: 1
ASEC BLOG
SmokeLoader를 통해 유포 중인 Amadey Bot - ASEC BLOG
Amadey Bot은 2018년경부터 확인되는 악성코드로서 공격자의 명령을 받아 정보 탈취나 추가 악성코드를 설치할 수 있다. 일반적인 악성코드들처럼 Amadey 또한 불법 포럼 등을 통해 판매되고 있으며, 이에 따라 현재까지도 다양한 공격자들에 의해 사용되고 있다. ASEC 분석팀에서는 2019년 ASEC 블로그를 통해 Amadey가 공격에 사용된 사례들을 공개한 바 있다. 대표적으로 GandCrab 랜섬웨어 공격자들에 의해 랜섬웨어를 설치하는 데 사용되거나…
#ParsedReport
11-07-2022
Pro-Russian Hacktivists Possible Ransomware Ambitions
https://cyberknow.medium.com/pro-russian-hacktivists-possible-ransomware-ambitions-84e804c10a93
Actors/Campaigns:
Red_hackers (motivation: hacktivism)
Geo:
Russia, Norway, Turkey, Denmark, Cyprus, Austria, Ukraine
11-07-2022
Pro-Russian Hacktivists Possible Ransomware Ambitions
https://cyberknow.medium.com/pro-russian-hacktivists-possible-ransomware-ambitions-84e804c10a93
Actors/Campaigns:
Red_hackers (motivation: hacktivism)
Geo:
Russia, Norway, Turkey, Denmark, Cyprus, Austria, Ukraine
Medium
Pro-Russian Hacktivists Possible Ransomware Ambitions
Are hacktivists looking to upgrade capability to match intent in the cyberspace struggle for dominance during the Russia-Ukraine War? Or…
#ParsedReport
11-07-2022
New 0mega ransomware targets businesses in double-extortion attacks
https://www.bleepingcomputer.com/news/security/new-0mega-ransomware-targets-businesses-in-double-extortion-attacks
Threats:
0mega (tags: ransomware)
Industry:
Financial
IOCs:
File: 1
11-07-2022
New 0mega ransomware targets businesses in double-extortion attacks
https://www.bleepingcomputer.com/news/security/new-0mega-ransomware-targets-businesses-in-double-extortion-attacks
Threats:
0mega (tags: ransomware)
Industry:
Financial
IOCs:
File: 1
BleepingComputer
New 0mega ransomware targets businesses in double-extortion attacks
A new ransomware operation named '0mega' targets organizations worldwide in double-extortion attacks and demands millions of dollars in ransoms.
#ParsedReport
11-07-2022
GuLoader Disguised as Estimate Requests Being Distributed via Phishing Email
https://asec.ahnlab.com/en/36470
Threats:
Cloudeye (tags: stealer, phishing, rat, malware)
Formbook (tags: phishing)
Agent_tesla (tags: phishing)
Remcos_rat (tags: phishing)
Nanocore_rat (tags: phishing)
Geo:
Korean
IOCs:
File: 5
Url: 1
Hash: 1
Functions Names: 1
11-07-2022
GuLoader Disguised as Estimate Requests Being Distributed via Phishing Email
https://asec.ahnlab.com/en/36470
Threats:
Cloudeye (tags: stealer, phishing, rat, malware)
Formbook (tags: phishing)
Agent_tesla (tags: phishing)
Remcos_rat (tags: phishing)
Nanocore_rat (tags: phishing)
Geo:
Korean
IOCs:
File: 5
Url: 1
Hash: 1
Functions Names: 1
ASEC BLOG
GuLoader Disguised as Estimate Requests Being Distributed via Phishing Email - ASEC BLOG
GuLoader has ranked again in Top 5 malware keywords of ASEC Weekly Malware Statistics for the first time in two years. It is a downloader malware that can download additional malware, and got its name as Google Drive is frequently used as its download URL.…
#ParsedReport
12-07-2022
From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud
https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud
Threats:
Aitm_technique (tags: proxy, fraud, malware, scan, phishing, vpn)
Industry:
Financial, Telco, Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 2
Domain: 50
Links:
12-07-2022
From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud
https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud
Threats:
Aitm_technique (tags: proxy, fraud, malware, scan, phishing, vpn)
Industry:
Financial, Telco, Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 2
Domain: 50
Links:
https://github.com/drk1wi/Modlishka
https://github.com/kgretzky/evilginx2
https://github.com/muraenateam/muraenaMicrosoft News
From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud
A large-scale phishing campaign that attempted to target over 10,000 organizations since September 2021 used adversary-in-the-middle (AiTM) phishing sites to steal passwords, hijack a user’s sign-in session, and skip the authentication process, even if the…
#ParsedReport
12-07-2022
OilRig Attack Graphs: Emulating the Iranian Threat Actors Global Campaigns
https://attackiq.com/2022/07/11/oilrig-attack-graphs-emulating-the-iranian-threat-actors-global-campaigns
Actors/Campaigns:
Oilrig
Threats:
Quadagent (tags: malware, dns, backdoor)
Disttrack
Bespoke (tags: phishing)
Tonedeaf (tags: phishing)
Longwatch (tags: phishing)
Valuevault (tags: phishing)
Pickpocket (tags: phishing)
Lazagne (tags: phishing)
Powerview
Industry:
Financial, Telco, Government, Energy
Geo:
Irans, Iranian
TTPs:
Links:
12-07-2022
OilRig Attack Graphs: Emulating the Iranian Threat Actors Global Campaigns
https://attackiq.com/2022/07/11/oilrig-attack-graphs-emulating-the-iranian-threat-actors-global-campaigns
Actors/Campaigns:
Oilrig
Threats:
Quadagent (tags: malware, dns, backdoor)
Disttrack
Bespoke (tags: phishing)
Tonedeaf (tags: phishing)
Longwatch (tags: phishing)
Valuevault (tags: phishing)
Pickpocket (tags: phishing)
Lazagne (tags: phishing)
Powerview
Industry:
Financial, Telco, Government, Energy
Geo:
Irans, Iranian
TTPs:
Links:
https://github.com/AlessandroZ/LaZagneAttackIQ
OilRig Attack Graphs: Emulating the Iranian Threat Actor’s Global Campaigns
AttackIQ has released two new attack graphs that emulate different aspects of OilRig’s operations against multiple sectors around the globe. With these attack graphs, you can test and validate your defenses to improve cybersecurity readiness.
#ParsedReport
12-07-2022
Malicious code disguised as V3 Lite icon
https://asec-ahnlab-com.translate.goog/ko/36338/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Avemaria_rat (tags: malware)
Agent_tesla (tags: malware)
Lokibot_stealer (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Azorult (tags: malware)
Trojan/win.msilkrypt.r495355 (tags: malware)
Trojan/win.msilkrypt.r498085 (tags: malware)
Trojan/win.msil.c5152589 (tags: malware)
Trojan/win.msil.r500015 (tags: malware)
Trojan/win.msil.c515258 (tags: malware)
Tnega (tags: malware)
IOCs:
File: 5
Hash: 3
IP: 1
Url: 2
12-07-2022
Malicious code disguised as V3 Lite icon
https://asec-ahnlab-com.translate.goog/ko/36338/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Avemaria_rat (tags: malware)
Agent_tesla (tags: malware)
Lokibot_stealer (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Azorult (tags: malware)
Trojan/win.msilkrypt.r495355 (tags: malware)
Trojan/win.msilkrypt.r498085 (tags: malware)
Trojan/win.msil.c5152589 (tags: malware)
Trojan/win.msil.r500015 (tags: malware)
Trojan/win.msil.c515258 (tags: malware)
Tnega (tags: malware)
IOCs:
File: 5
Hash: 3
IP: 1
Url: 2
ASEC BLOG
V3 Lite 아이콘을 위장하여 유포되는 악성코드 - ASEC BLOG
ASEC 분석팀은 V3 Lite 아이콘을 위장한 악성코드가 닷넷(.NET) 외형의 패커로 패킹되어 유포되는 정황을 확인하였다. 실제 V3 Lite 제품의 아이콘과 매우 유사하게 제작하여 사용자를 속이기 위한 목적으로 판단되며, 최근 한 달 간에는 AveMaria RAT와 AgentTesla 악성코드가 확인되었다. 위와 같이 아이콘의 외형 상으로는 실제 V3 Lite 제품의 아이콘과 차이가 없음을 알 수 있다. AveMaria 악성코드는 원격제어 기능의…
#ParsedReport
12-07-2022
ChromeLoader: New Stubborn Malware Campaign
https://unit42.paloaltonetworks.com/chromeloader-malware
Threats:
Chromeloader (tags: stealer, scan, malware, dropper)
Empire_loader
IOCs:
File: 16
Domain: 83
Hash: 173
Functions Names: 4
Links:
12-07-2022
ChromeLoader: New Stubborn Malware Campaign
https://unit42.paloaltonetworks.com/chromeloader-malware
Threats:
Chromeloader (tags: stealer, scan, malware, dropper)
Empire_loader
IOCs:
File: 16
Domain: 83
Hash: 173
Functions Names: 4
Links:
https://github.com/xephora/Threat-Remediation-Scripts/tree/main/Threat-Track/CS\_INSTALLERUnit 42
ChromeLoader: New Stubborn Malware Campaign
A malicious browser extension is the payload of the ChromeLoader malware family, serving as adware and an infostealer, leaking users’ search queries.