#ParsedReport
11-07-2022
AppleSeed Disguised as Purchase Order and Request Form Being Distributed
https://asec.ahnlab.com/en/36368
Actors/Campaigns:
Kimsuky
Threats:
Appleseed (tags: dropper, backdoor, malware)
IOCs:
File: 2
Hash: 4
Url: 2
11-07-2022
AppleSeed Disguised as Purchase Order and Request Form Being Distributed
https://asec.ahnlab.com/en/36368
Actors/Campaigns:
Kimsuky
Threats:
Appleseed (tags: dropper, backdoor, malware)
IOCs:
File: 2
Hash: 4
Url: 2
ASEC BLOG
AppleSeed Disguised as Purchase Order and Request Form Being Distributed - ASEC BLOG
The ASEC analysis team has recently discovered the distribution of AppleSeed disguised as purchase orders and request forms. AppleSeed is a backdoor malware mainly used by the Kimsuky group. It stays in the system and performs malicious behaviors by receiving…
#ParsedReport
11-07-2022
Ransomware Spotlight: BlackByte
https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte
Threats:
Blackbyte (tags: rat, phishing, malware, ransomware)
Ransomexx (tags: ransomware)
Avoslocker (tags: ransomware)
Clop (tags: ransomware)
Lockbit (tags: ransomware)
Conti (tags: ransomware)
Proxyshell_vuln (tags: malware)
Cobalt_strike (tags: malware)
Netscan_tool (tags: malware)
Chinachopper (tags: malware)
Industry:
Retail, Foodtech, Financial, Energy, Entertainment, Ics, Government, Healthcare, Transport
Geo:
Russia, America, Peru, American, China
TTPs:
Tactics: 3
Technics: 14
IOCs:
Domain: 2
File: 16
Path: 2
Registry: 2
Url: 2
Coin: 1
11-07-2022
Ransomware Spotlight: BlackByte
https://www.trendmicro.com/vinfo/us/security/news/ransomware-spotlight/ransomware-spotlight-blackbyte
Threats:
Blackbyte (tags: rat, phishing, malware, ransomware)
Ransomexx (tags: ransomware)
Avoslocker (tags: ransomware)
Clop (tags: ransomware)
Lockbit (tags: ransomware)
Conti (tags: ransomware)
Proxyshell_vuln (tags: malware)
Cobalt_strike (tags: malware)
Netscan_tool (tags: malware)
Chinachopper (tags: malware)
Industry:
Retail, Foodtech, Financial, Energy, Entertainment, Ics, Government, Healthcare, Transport
Geo:
Russia, America, Peru, American, China
TTPs:
Tactics: 3
Technics: 14
IOCs:
Domain: 2
File: 16
Path: 2
Registry: 2
Url: 2
Coin: 1
Trendmicro
Ransomware Spotlight: BlackByte
BlackByte is a ransomware group that has been building a name for itself since 2021. Like its contemporaries, it has gone after critical infrastructure for a higher chance of getting a payout. What techniques sets it apart?
#ParsedReport
11-07-2022
Minerva Labs Blog
https://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Actors/Campaigns:
Blackcat
Threats:
Lockbit (tags: ransomware, cryptomining)
Geo:
Russian, Belarusian, Moldova, Syria, Romanian, Ukrainian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Functions Names: 4
11-07-2022
Minerva Labs Blog
https://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Actors/Campaigns:
Blackcat
Threats:
Lockbit (tags: ransomware, cryptomining)
Geo:
Russian, Belarusian, Moldova, Syria, Romanian, Ukrainian
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Functions Names: 4
Minerva-Labs
Lockbit 3.0 AKA Lockbit Black is here, with a new icon, new ransom note, new wallpaper, but less evasiveness?
Lockbit 3.0, also known as Lockbit Black was recently released and has already claimed its first victims. We dive into how it works and how you can protect yourselves
#ParsedReport
11-07-2022
Amadey Bot disseminating via SmokeLoader
https://asec-ahnlab-com.translate.goog/ko/36419/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Ta505
Threats:
Amadey (tags: rat, malware, stealer, ransomware, vpn)
Smokeloader (tags: rat, malware, stealer, ransomware, vpn)
Gandcrab
Flawedammyy
Clop
Rig_tool
Redline_stealer
Tightvnc_tool
Trojan/win.malpe.r503126
Delf
Trojan/win.generic.r503640
Malware/win.trojanspy.r438708
Malware/mdp.download.m1197
IOCs:
File: 16
Path: 7
Registry: 1
Url: 15
Hash: 10
IP: 1
Functions Names: 1
11-07-2022
Amadey Bot disseminating via SmokeLoader
https://asec-ahnlab-com.translate.goog/ko/36419/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Actors/Campaigns:
Ta505
Threats:
Amadey (tags: rat, malware, stealer, ransomware, vpn)
Smokeloader (tags: rat, malware, stealer, ransomware, vpn)
Gandcrab
Flawedammyy
Clop
Rig_tool
Redline_stealer
Tightvnc_tool
Trojan/win.malpe.r503126
Delf
Trojan/win.generic.r503640
Malware/win.trojanspy.r438708
Malware/mdp.download.m1197
IOCs:
File: 16
Path: 7
Registry: 1
Url: 15
Hash: 10
IP: 1
Functions Names: 1
ASEC BLOG
SmokeLoader를 통해 유포 중인 Amadey Bot - ASEC BLOG
Amadey Bot은 2018년경부터 확인되는 악성코드로서 공격자의 명령을 받아 정보 탈취나 추가 악성코드를 설치할 수 있다. 일반적인 악성코드들처럼 Amadey 또한 불법 포럼 등을 통해 판매되고 있으며, 이에 따라 현재까지도 다양한 공격자들에 의해 사용되고 있다. ASEC 분석팀에서는 2019년 ASEC 블로그를 통해 Amadey가 공격에 사용된 사례들을 공개한 바 있다. 대표적으로 GandCrab 랜섬웨어 공격자들에 의해 랜섬웨어를 설치하는 데 사용되거나…
#ParsedReport
11-07-2022
Pro-Russian Hacktivists Possible Ransomware Ambitions
https://cyberknow.medium.com/pro-russian-hacktivists-possible-ransomware-ambitions-84e804c10a93
Actors/Campaigns:
Red_hackers (motivation: hacktivism)
Geo:
Russia, Norway, Turkey, Denmark, Cyprus, Austria, Ukraine
11-07-2022
Pro-Russian Hacktivists Possible Ransomware Ambitions
https://cyberknow.medium.com/pro-russian-hacktivists-possible-ransomware-ambitions-84e804c10a93
Actors/Campaigns:
Red_hackers (motivation: hacktivism)
Geo:
Russia, Norway, Turkey, Denmark, Cyprus, Austria, Ukraine
Medium
Pro-Russian Hacktivists Possible Ransomware Ambitions
Are hacktivists looking to upgrade capability to match intent in the cyberspace struggle for dominance during the Russia-Ukraine War? Or…
#ParsedReport
11-07-2022
New 0mega ransomware targets businesses in double-extortion attacks
https://www.bleepingcomputer.com/news/security/new-0mega-ransomware-targets-businesses-in-double-extortion-attacks
Threats:
0mega (tags: ransomware)
Industry:
Financial
IOCs:
File: 1
11-07-2022
New 0mega ransomware targets businesses in double-extortion attacks
https://www.bleepingcomputer.com/news/security/new-0mega-ransomware-targets-businesses-in-double-extortion-attacks
Threats:
0mega (tags: ransomware)
Industry:
Financial
IOCs:
File: 1
BleepingComputer
New 0mega ransomware targets businesses in double-extortion attacks
A new ransomware operation named '0mega' targets organizations worldwide in double-extortion attacks and demands millions of dollars in ransoms.
#ParsedReport
11-07-2022
GuLoader Disguised as Estimate Requests Being Distributed via Phishing Email
https://asec.ahnlab.com/en/36470
Threats:
Cloudeye (tags: stealer, phishing, rat, malware)
Formbook (tags: phishing)
Agent_tesla (tags: phishing)
Remcos_rat (tags: phishing)
Nanocore_rat (tags: phishing)
Geo:
Korean
IOCs:
File: 5
Url: 1
Hash: 1
Functions Names: 1
11-07-2022
GuLoader Disguised as Estimate Requests Being Distributed via Phishing Email
https://asec.ahnlab.com/en/36470
Threats:
Cloudeye (tags: stealer, phishing, rat, malware)
Formbook (tags: phishing)
Agent_tesla (tags: phishing)
Remcos_rat (tags: phishing)
Nanocore_rat (tags: phishing)
Geo:
Korean
IOCs:
File: 5
Url: 1
Hash: 1
Functions Names: 1
ASEC BLOG
GuLoader Disguised as Estimate Requests Being Distributed via Phishing Email - ASEC BLOG
GuLoader has ranked again in Top 5 malware keywords of ASEC Weekly Malware Statistics for the first time in two years. It is a downloader malware that can download additional malware, and got its name as Google Drive is frequently used as its download URL.…
#ParsedReport
12-07-2022
From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud
https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud
Threats:
Aitm_technique (tags: proxy, fraud, malware, scan, phishing, vpn)
Industry:
Financial, Telco, Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 2
Domain: 50
Links:
12-07-2022
From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud
https://www.microsoft.com/security/blog/2022/07/12/from-cookie-theft-to-bec-attackers-use-aitm-phishing-sites-as-entry-point-to-further-financial-fraud
Threats:
Aitm_technique (tags: proxy, fraud, malware, scan, phishing, vpn)
Industry:
Financial, Telco, Government
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
Url: 2
Domain: 50
Links:
https://github.com/drk1wi/Modlishka
https://github.com/kgretzky/evilginx2
https://github.com/muraenateam/muraenaMicrosoft News
From cookie theft to BEC: Attackers use AiTM phishing sites as entry point to further financial fraud
A large-scale phishing campaign that attempted to target over 10,000 organizations since September 2021 used adversary-in-the-middle (AiTM) phishing sites to steal passwords, hijack a user’s sign-in session, and skip the authentication process, even if the…
#ParsedReport
12-07-2022
OilRig Attack Graphs: Emulating the Iranian Threat Actors Global Campaigns
https://attackiq.com/2022/07/11/oilrig-attack-graphs-emulating-the-iranian-threat-actors-global-campaigns
Actors/Campaigns:
Oilrig
Threats:
Quadagent (tags: malware, dns, backdoor)
Disttrack
Bespoke (tags: phishing)
Tonedeaf (tags: phishing)
Longwatch (tags: phishing)
Valuevault (tags: phishing)
Pickpocket (tags: phishing)
Lazagne (tags: phishing)
Powerview
Industry:
Financial, Telco, Government, Energy
Geo:
Irans, Iranian
TTPs:
Links:
12-07-2022
OilRig Attack Graphs: Emulating the Iranian Threat Actors Global Campaigns
https://attackiq.com/2022/07/11/oilrig-attack-graphs-emulating-the-iranian-threat-actors-global-campaigns
Actors/Campaigns:
Oilrig
Threats:
Quadagent (tags: malware, dns, backdoor)
Disttrack
Bespoke (tags: phishing)
Tonedeaf (tags: phishing)
Longwatch (tags: phishing)
Valuevault (tags: phishing)
Pickpocket (tags: phishing)
Lazagne (tags: phishing)
Powerview
Industry:
Financial, Telco, Government, Energy
Geo:
Irans, Iranian
TTPs:
Links:
https://github.com/AlessandroZ/LaZagneAttackIQ
OilRig Attack Graphs: Emulating the Iranian Threat Actor’s Global Campaigns
AttackIQ has released two new attack graphs that emulate different aspects of OilRig’s operations against multiple sectors around the globe. With these attack graphs, you can test and validate your defenses to improve cybersecurity readiness.
#ParsedReport
12-07-2022
Malicious code disguised as V3 Lite icon
https://asec-ahnlab-com.translate.goog/ko/36338/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Avemaria_rat (tags: malware)
Agent_tesla (tags: malware)
Lokibot_stealer (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Azorult (tags: malware)
Trojan/win.msilkrypt.r495355 (tags: malware)
Trojan/win.msilkrypt.r498085 (tags: malware)
Trojan/win.msil.c5152589 (tags: malware)
Trojan/win.msil.r500015 (tags: malware)
Trojan/win.msil.c515258 (tags: malware)
Tnega (tags: malware)
IOCs:
File: 5
Hash: 3
IP: 1
Url: 2
12-07-2022
Malicious code disguised as V3 Lite icon
https://asec-ahnlab-com.translate.goog/ko/36338/?_x_tr_sl=ko&_x_tr_tl=en&_x_tr_hl=ru&_x_tr_pto=wapp
Threats:
Avemaria_rat (tags: malware)
Agent_tesla (tags: malware)
Lokibot_stealer (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Azorult (tags: malware)
Trojan/win.msilkrypt.r495355 (tags: malware)
Trojan/win.msilkrypt.r498085 (tags: malware)
Trojan/win.msil.c5152589 (tags: malware)
Trojan/win.msil.r500015 (tags: malware)
Trojan/win.msil.c515258 (tags: malware)
Tnega (tags: malware)
IOCs:
File: 5
Hash: 3
IP: 1
Url: 2
ASEC BLOG
V3 Lite 아이콘을 위장하여 유포되는 악성코드 - ASEC BLOG
ASEC 분석팀은 V3 Lite 아이콘을 위장한 악성코드가 닷넷(.NET) 외형의 패커로 패킹되어 유포되는 정황을 확인하였다. 실제 V3 Lite 제품의 아이콘과 매우 유사하게 제작하여 사용자를 속이기 위한 목적으로 판단되며, 최근 한 달 간에는 AveMaria RAT와 AgentTesla 악성코드가 확인되었다. 위와 같이 아이콘의 외형 상으로는 실제 V3 Lite 제품의 아이콘과 차이가 없음을 알 수 있다. AveMaria 악성코드는 원격제어 기능의…
#ParsedReport
12-07-2022
ChromeLoader: New Stubborn Malware Campaign
https://unit42.paloaltonetworks.com/chromeloader-malware
Threats:
Chromeloader (tags: stealer, scan, malware, dropper)
Empire_loader
IOCs:
File: 16
Domain: 83
Hash: 173
Functions Names: 4
Links:
12-07-2022
ChromeLoader: New Stubborn Malware Campaign
https://unit42.paloaltonetworks.com/chromeloader-malware
Threats:
Chromeloader (tags: stealer, scan, malware, dropper)
Empire_loader
IOCs:
File: 16
Domain: 83
Hash: 173
Functions Names: 4
Links:
https://github.com/xephora/Threat-Remediation-Scripts/tree/main/Threat-Track/CS\_INSTALLERUnit 42
ChromeLoader: New Stubborn Malware Campaign
A malicious browser extension is the payload of the ChromeLoader malware family, serving as adware and an infostealer, leaking users’ search queries.
#ParsedReport
12-07-2022
Dragon News Blog. An Analysis of Infrastructure linked to the Hagga Threat Actor
https://team-cymru.com/blog/2022/07/12/an-analysis-of-infrastructure-linked-to-the-hagga-threat-actor
Actors/Campaigns:
Aggaa
Threats:
Agent_tesla
Mana_tool
Revenge_rat
Azorult
Lokibot_stealer
Formbook
Beacon
Industry:
Telco
Geo:
Vietnam, Pakistan
IOCs:
IP: 18
Domain: 3
File: 1
Url: 1
Functions Names: 1
12-07-2022
Dragon News Blog. An Analysis of Infrastructure linked to the Hagga Threat Actor
https://team-cymru.com/blog/2022/07/12/an-analysis-of-infrastructure-linked-to-the-hagga-threat-actor
Actors/Campaigns:
Aggaa
Threats:
Agent_tesla
Mana_tool
Revenge_rat
Azorult
Lokibot_stealer
Formbook
Beacon
Industry:
Telco
Geo:
Vietnam, Pakistan
IOCs:
IP: 18
Domain: 3
File: 1
Url: 1
Functions Names: 1
#technique
A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.
https://github.com/m3rcer/Chisel-Strike
A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.
https://github.com/m3rcer/Chisel-Strike
GitHub
GitHub - m3rcer/Chisel-Strike: A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and…
A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities. - m3rcer/Chisel-Strike
#ParsedReport
13-07-2022
. AutoCAD Trojan is rampant, An Tianzhi Jia comprehensively protects
https://www.antiy.cn/research/notice&report/research_report/20220712.html
Threats:
Medre (tags: trojan)
Industry:
Government
Geo:
Turkey, China, India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 11
Hash: 2
IP: 2
13-07-2022
. AutoCAD Trojan is rampant, An Tianzhi Jia comprehensively protects
https://www.antiy.cn/research/notice&report/research_report/20220712.html
Threats:
Medre (tags: trojan)
Industry:
Government
Geo:
Turkey, China, India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 11
Hash: 2
IP: 2
www.antiy.cn
AutoCAD木马猖獗,安天智甲全面防护
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
12-07-2022
Rise in Qakbot attacks traced to evolving threat techniques
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques-13
Threats:
Qakbot (tags: scan, trojan, malware, botnet)
Industry:
Financial
IOCs:
File: 32
Hash: 11
Path: 4
IP: 57
Domain: 136
Functions Names: 3
12-07-2022
Rise in Qakbot attacks traced to evolving threat techniques
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques-13
Threats:
Qakbot (tags: scan, trojan, malware, botnet)
Industry:
Financial
IOCs:
File: 32
Hash: 11
Path: 4
IP: 57
Domain: 136
Functions Names: 3
Zscaler
Qakbot Attacks Increasing due to Evolving Threats | Zscaler
Qakbot leverages ZIP archive file having embedded files such as Microsoft Office files, LNK, Powershell, and more.
#ParsedReport
13-07-2022
Go malware on the rise. Introduction
https://decoded.avast.io/davidalvarez/go-malware-on-the-rise/?utm_source=rss&utm_medium=rss&utm_campaign=go-malware-on-the-rise
Threats:
Synflood
Geo:
Russian
CVEs:
CVE-2021-24098 [Vulners]
Vulners: Score: 2.1, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.5
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2021-28312 [Vulners]
Vulners: Score: 4.3, CVSS: 3.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 3.3
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
IOCs:
File: 2
IP: 1
Path: 1
Hash: 10
Links:
13-07-2022
Go malware on the rise. Introduction
https://decoded.avast.io/davidalvarez/go-malware-on-the-rise/?utm_source=rss&utm_medium=rss&utm_campaign=go-malware-on-the-rise
Threats:
Synflood
Geo:
Russian
CVEs:
CVE-2021-24098 [Vulners]
Vulners: Score: 2.1, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.5
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2021-28312 [Vulners]
Vulners: Score: 4.3, CVSS: 3.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 3.3
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
IOCs:
File: 2
IP: 1
Path: 1
Hash: 10
Links:
https://github.com/whyrusleeping/hellabothttps://github.com/avast/ioc/tree/master/Caligulahttps://github.com/mattn/go-isattyhttps://github.com/ftrvxmtrx/fdhttps://github.com/mattn/go-shellwordshttps://github.com/mattn/go-colorablehttps://github.com/inconshreveable/log15Avast Threat Labs
Go malware on the rise - Avast Threat Labs
Introduction The Go programming language is becoming more and more popular. One of the reasons being that Go programs can be compiled for multiple operating systems and architectures in a single binary self containing all needed dependencies. Based on these…
#ParsedReport
13-07-2022
AIRAVAT Malware Targeting Android Users
https://blog.cyble.com/2022/07/13/airavat-malware-targeting-android-users
Threats:
Airavat_rat (tags: malware, ransomware, phishing, rat)
Opendir (tags: ransomware, rat)
Spynote
Spymax
Industry:
Education, Petroleum, Financial, E-commerce
TTPs:
Tactics: 3
Technics: 0
IOCs:
Url: 3
File: 2
Hash: 3
Functions Names: 2
SIGMA: Found
Links:
13-07-2022
AIRAVAT Malware Targeting Android Users
https://blog.cyble.com/2022/07/13/airavat-malware-targeting-android-users
Threats:
Airavat_rat (tags: malware, ransomware, phishing, rat)
Opendir (tags: ransomware, rat)
Spynote
Spymax
Industry:
Education, Petroleum, Financial, E-commerce
TTPs:
Tactics: 3
Technics: 0
IOCs:
Url: 3
File: 2
Hash: 3
Functions Names: 2
SIGMA: Found
Links:
https://github.com/Th30neAnd0nly/AIRAVATCyble
AIRAVAT Malware Targeting Android Users
Cyble analyzes AIRAVAT, a sophisticated Android RAT that is capable of performing Ransomware attacks.
#ParsedReport
13-07-2022
Cobalt Strikes again: UAC-0056 continues to target Ukraine in its latest campaign. Different themes, same techniques
https://blog.malwarebytes.com/threat-intelligence/2022/07/cobalt-strikes-again-uac-0056-continues-to-target-ukraine-in-its-latest-campaign
Actors/Campaigns:
Ember_bear
Unc2589
Ice_fog
Threats:
Cobalt_strike (tags: malware, dropper, phishing, rat)
Beacon
Industry:
Government
Geo:
Ukraine, Ukrainian, Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 6
Domain: 3
Hash: 6
IP: 1
Registry: 2
Path: 1
13-07-2022
Cobalt Strikes again: UAC-0056 continues to target Ukraine in its latest campaign. Different themes, same techniques
https://blog.malwarebytes.com/threat-intelligence/2022/07/cobalt-strikes-again-uac-0056-continues-to-target-ukraine-in-its-latest-campaign
Actors/Campaigns:
Ember_bear
Unc2589
Ice_fog
Threats:
Cobalt_strike (tags: malware, dropper, phishing, rat)
Beacon
Industry:
Government
Geo:
Ukraine, Ukrainian, Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 6
Domain: 3
Hash: 6
IP: 1
Registry: 2
Path: 1
ThreatDown by Malwarebytes
Cobalt Strikes again: UAC-0056 continues to target Ukraine in its latest campaign - ThreatDown by Malwarebytes
This blog was authored by Roberto Santos and Hossein Jazi The Malwarebytes Threat Intelligence team recently reviewed a series of cyber attacks against Ukraine that we attribute with high confidence…
#ParsedReport
13-07-2022
Objet: / Feed MISP public
https://www.cert.ssi.gouv.fr/ioc/CERTFR-2022-IOC-001
YARA: Found
13-07-2022
Objet: / Feed MISP public
https://www.cert.ssi.gouv.fr/ioc/CERTFR-2022-IOC-001
YARA: Found
#ParsedReport
12-07-2022
New Ransomware Groups on the Rise
https://blog.cyble.com/2022/07/12/new-ransomware-groups-on-the-rise
Actors/Campaigns:
N13v
Threats:
Red_alert (tags: rat, cryptomining, ransomware, malware)
Lilith_rat (tags: ransomware, malware)
0mega (tags: ransomware, malware)
Lilith (tags: ransomware, malware)
Babuk
Industry:
Financial
TTPs:
Tactics: 4
Technics: 6
IOCs:
File: 4
Hash: 3
Functions Names: 15
12-07-2022
New Ransomware Groups on the Rise
https://blog.cyble.com/2022/07/12/new-ransomware-groups-on-the-rise
Actors/Campaigns:
N13v
Threats:
Red_alert (tags: rat, cryptomining, ransomware, malware)
Lilith_rat (tags: ransomware, malware)
0mega (tags: ransomware, malware)
Lilith (tags: ransomware, malware)
Babuk
Industry:
Financial
TTPs:
Tactics: 4
Technics: 6
IOCs:
File: 4
Hash: 3
Functions Names: 15
#ParsedReport
13-07-2022
ASEC ( 20220704 \~ 20220710 ). ASEC Weekly Malware Statistics (20220704 \~ 20220710)
https://asec.ahnlab.com/ko/36533
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 45
Domain: 3
IP: 3
Email: 3
Url: 34
13-07-2022
ASEC ( 20220704 \~ 20220710 ). ASEC Weekly Malware Statistics (20220704 \~ 20220710)
https://asec.ahnlab.com/ko/36533
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 45
Domain: 3
IP: 3
Email: 3
Url: 34
ASEC BLOG
ASEC 주간 악성코드 통계 ( 20220704 ~ 20220710 ) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 7월 4일 월요일부터 7월 10일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 43.9%로 1위를 차지하였으며, 그 다음으로는 다운로더 악성코드가 27.2%, 백도어 21.1%, 뱅킹 6.1%, 랜섬웨어 1.1%, 코인마이너가 0.6%로 집계되었다. Top 1…