#technique
A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.
https://github.com/m3rcer/Chisel-Strike
A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities.
https://github.com/m3rcer/Chisel-Strike
GitHub
GitHub - m3rcer/Chisel-Strike: A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and…
A .NET XOR encrypted cobalt strike aggressor implementation for chisel to utilize faster proxy and advanced socks5 capabilities. - m3rcer/Chisel-Strike
#ParsedReport
13-07-2022
. AutoCAD Trojan is rampant, An Tianzhi Jia comprehensively protects
https://www.antiy.cn/research/notice&report/research_report/20220712.html
Threats:
Medre (tags: trojan)
Industry:
Government
Geo:
Turkey, China, India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 11
Hash: 2
IP: 2
13-07-2022
. AutoCAD Trojan is rampant, An Tianzhi Jia comprehensively protects
https://www.antiy.cn/research/notice&report/research_report/20220712.html
Threats:
Medre (tags: trojan)
Industry:
Government
Geo:
Turkey, China, India
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 11
Hash: 2
IP: 2
www.antiy.cn
AutoCAD木马猖獗,安天智甲全面防护
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
12-07-2022
Rise in Qakbot attacks traced to evolving threat techniques
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques-13
Threats:
Qakbot (tags: scan, trojan, malware, botnet)
Industry:
Financial
IOCs:
File: 32
Hash: 11
Path: 4
IP: 57
Domain: 136
Functions Names: 3
12-07-2022
Rise in Qakbot attacks traced to evolving threat techniques
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques-13
Threats:
Qakbot (tags: scan, trojan, malware, botnet)
Industry:
Financial
IOCs:
File: 32
Hash: 11
Path: 4
IP: 57
Domain: 136
Functions Names: 3
Zscaler
Qakbot Attacks Increasing due to Evolving Threats | Zscaler
Qakbot leverages ZIP archive file having embedded files such as Microsoft Office files, LNK, Powershell, and more.
#ParsedReport
13-07-2022
Go malware on the rise. Introduction
https://decoded.avast.io/davidalvarez/go-malware-on-the-rise/?utm_source=rss&utm_medium=rss&utm_campaign=go-malware-on-the-rise
Threats:
Synflood
Geo:
Russian
CVEs:
CVE-2021-24098 [Vulners]
Vulners: Score: 2.1, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.5
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2021-28312 [Vulners]
Vulners: Score: 4.3, CVSS: 3.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 3.3
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
IOCs:
File: 2
IP: 1
Path: 1
Hash: 10
Links:
13-07-2022
Go malware on the rise. Introduction
https://decoded.avast.io/davidalvarez/go-malware-on-the-rise/?utm_source=rss&utm_medium=rss&utm_campaign=go-malware-on-the-rise
Threats:
Synflood
Geo:
Russian
CVEs:
CVE-2021-24098 [Vulners]
Vulners: Score: 2.1, CVSS: 4.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 5.5
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2021-28312 [Vulners]
Vulners: Score: 4.3, CVSS: 3.6,
Vulners: Exploitation: Unknown
X-Force: Risk: 3.3
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
IOCs:
File: 2
IP: 1
Path: 1
Hash: 10
Links:
https://github.com/whyrusleeping/hellabothttps://github.com/avast/ioc/tree/master/Caligulahttps://github.com/mattn/go-isattyhttps://github.com/ftrvxmtrx/fdhttps://github.com/mattn/go-shellwordshttps://github.com/mattn/go-colorablehttps://github.com/inconshreveable/log15Avast Threat Labs
Go malware on the rise - Avast Threat Labs
Introduction The Go programming language is becoming more and more popular. One of the reasons being that Go programs can be compiled for multiple operating systems and architectures in a single binary self containing all needed dependencies. Based on these…
#ParsedReport
13-07-2022
AIRAVAT Malware Targeting Android Users
https://blog.cyble.com/2022/07/13/airavat-malware-targeting-android-users
Threats:
Airavat_rat (tags: malware, ransomware, phishing, rat)
Opendir (tags: ransomware, rat)
Spynote
Spymax
Industry:
Education, Petroleum, Financial, E-commerce
TTPs:
Tactics: 3
Technics: 0
IOCs:
Url: 3
File: 2
Hash: 3
Functions Names: 2
SIGMA: Found
Links:
13-07-2022
AIRAVAT Malware Targeting Android Users
https://blog.cyble.com/2022/07/13/airavat-malware-targeting-android-users
Threats:
Airavat_rat (tags: malware, ransomware, phishing, rat)
Opendir (tags: ransomware, rat)
Spynote
Spymax
Industry:
Education, Petroleum, Financial, E-commerce
TTPs:
Tactics: 3
Technics: 0
IOCs:
Url: 3
File: 2
Hash: 3
Functions Names: 2
SIGMA: Found
Links:
https://github.com/Th30neAnd0nly/AIRAVATCyble
AIRAVAT Malware Targeting Android Users
Cyble analyzes AIRAVAT, a sophisticated Android RAT that is capable of performing Ransomware attacks.
#ParsedReport
13-07-2022
Cobalt Strikes again: UAC-0056 continues to target Ukraine in its latest campaign. Different themes, same techniques
https://blog.malwarebytes.com/threat-intelligence/2022/07/cobalt-strikes-again-uac-0056-continues-to-target-ukraine-in-its-latest-campaign
Actors/Campaigns:
Ember_bear
Unc2589
Ice_fog
Threats:
Cobalt_strike (tags: malware, dropper, phishing, rat)
Beacon
Industry:
Government
Geo:
Ukraine, Ukrainian, Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 6
Domain: 3
Hash: 6
IP: 1
Registry: 2
Path: 1
13-07-2022
Cobalt Strikes again: UAC-0056 continues to target Ukraine in its latest campaign. Different themes, same techniques
https://blog.malwarebytes.com/threat-intelligence/2022/07/cobalt-strikes-again-uac-0056-continues-to-target-ukraine-in-its-latest-campaign
Actors/Campaigns:
Ember_bear
Unc2589
Ice_fog
Threats:
Cobalt_strike (tags: malware, dropper, phishing, rat)
Beacon
Industry:
Government
Geo:
Ukraine, Ukrainian, Russian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 6
Domain: 3
Hash: 6
IP: 1
Registry: 2
Path: 1
ThreatDown by Malwarebytes
Cobalt Strikes again: UAC-0056 continues to target Ukraine in its latest campaign - ThreatDown by Malwarebytes
This blog was authored by Roberto Santos and Hossein Jazi The Malwarebytes Threat Intelligence team recently reviewed a series of cyber attacks against Ukraine that we attribute with high confidence…
#ParsedReport
13-07-2022
Objet: / Feed MISP public
https://www.cert.ssi.gouv.fr/ioc/CERTFR-2022-IOC-001
YARA: Found
13-07-2022
Objet: / Feed MISP public
https://www.cert.ssi.gouv.fr/ioc/CERTFR-2022-IOC-001
YARA: Found
#ParsedReport
12-07-2022
New Ransomware Groups on the Rise
https://blog.cyble.com/2022/07/12/new-ransomware-groups-on-the-rise
Actors/Campaigns:
N13v
Threats:
Red_alert (tags: rat, cryptomining, ransomware, malware)
Lilith_rat (tags: ransomware, malware)
0mega (tags: ransomware, malware)
Lilith (tags: ransomware, malware)
Babuk
Industry:
Financial
TTPs:
Tactics: 4
Technics: 6
IOCs:
File: 4
Hash: 3
Functions Names: 15
12-07-2022
New Ransomware Groups on the Rise
https://blog.cyble.com/2022/07/12/new-ransomware-groups-on-the-rise
Actors/Campaigns:
N13v
Threats:
Red_alert (tags: rat, cryptomining, ransomware, malware)
Lilith_rat (tags: ransomware, malware)
0mega (tags: ransomware, malware)
Lilith (tags: ransomware, malware)
Babuk
Industry:
Financial
TTPs:
Tactics: 4
Technics: 6
IOCs:
File: 4
Hash: 3
Functions Names: 15
#ParsedReport
13-07-2022
ASEC ( 20220704 \~ 20220710 ). ASEC Weekly Malware Statistics (20220704 \~ 20220710)
https://asec.ahnlab.com/ko/36533
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 45
Domain: 3
IP: 3
Email: 3
Url: 34
13-07-2022
ASEC ( 20220704 \~ 20220710 ). ASEC Weekly Malware Statistics (20220704 \~ 20220710)
https://asec.ahnlab.com/ko/36533
Threats:
Agent_tesla (tags: malware)
Azorult (tags: malware)
Cloudeye (tags: malware)
Formbook (tags: malware)
Remcos_rat (tags: malware)
Nanocore_rat (tags: malware)
Clipboard_grabbing_technique (tags: malware)
Redline_stealer (tags: malware)
Beamwinhttp_loader (tags: malware)
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 45
Domain: 3
IP: 3
Email: 3
Url: 34
ASEC BLOG
ASEC 주간 악성코드 통계 ( 20220704 ~ 20220710 ) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 7월 4일 월요일부터 7월 10일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 43.9%로 1위를 차지하였으며, 그 다음으로는 다운로더 악성코드가 27.2%, 백도어 21.1%, 뱅킹 6.1%, 랜섬웨어 1.1%, 코인마이너가 0.6%로 집계되었다. Top 1…
#ParsedReport
13-07-2022
Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption
https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption
Threats:
Cobalt_strike (tags: malware, rat)
Beacon
IOCs:
File: 1
Hash: 2
IP: 1
Functions Names: 4
Links:
13-07-2022
Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption
https://unit42.paloaltonetworks.com/cobalt-strike-metadata-encryption-decryption
Threats:
Cobalt_strike (tags: malware, rat)
Beacon
IOCs:
File: 1
Hash: 2
IP: 1
Functions Names: 4
Links:
https://github.com/DidierStevens/DidierStevensSuite/blob/master/1768.jsonhttps://github.com/DidierStevens/AdHoc/blob/master/cs-mitm.pyhttps://gist.github.com/olliencc/af056560e943bafa145120103a0947a3#file-dump-javaUnit 42
Cobalt Strike Analysis and Tutorial: CS Metadata Encryption and Decryption
We show how metadata encryption and decryption contributes to making Cobalt Strike an effective emulator that is difficult to defend against.
Добавил в парсер отчетов:
- словарик с софтами
- словарик криптографических алгоритмов
- алгоритм разбора вертикально ориентированных таблиц с описанием TTP из отчетов.
- автоматический перевод (надоело скармливать руками в гугл транслейт корейские и китайские отчеты). Теперь парсер сам понимает что отчет надо переводить.
Скоро дотащу это и до скрипта, формирующего сообщения в телегу.
- словарик с софтами
- словарик криптографических алгоритмов
- алгоритм разбора вертикально ориентированных таблиц с описанием TTP из отчетов.
- автоматический перевод (надоело скармливать руками в гугл транслейт корейские и китайские отчеты). Теперь парсер сам понимает что отчет надо переводить.
Скоро дотащу это и до скрипта, формирующего сообщения в телегу.
#ParsedReport
14-07-2022
. Confucius: The fisherman hidden under Cloudflare
https://www.antiy.cn/research/notice&report/research_report/20220713.html
Actors/Campaigns:
Confucius
Sidewinder
Dropping_elephant
Threats:
Quasar_rat
Chrysaor
Backdoor/win32.agentb
Trojan/win32.agent
Polyloader
Asyncrat_rat
Industry:
Energy, Government, Education, Retail, Telco
Geo:
American, Chinese, India, Pakistan, Indian, Asia, China, Bangladesh, Pakistani
TTPs:
Tactics: 5
Technics: 0
IOCs:
File: 18
IP: 2
Hash: 16
Registry: 1
Path: 1
14-07-2022
. Confucius: The fisherman hidden under Cloudflare
https://www.antiy.cn/research/notice&report/research_report/20220713.html
Actors/Campaigns:
Confucius
Sidewinder
Dropping_elephant
Threats:
Quasar_rat
Chrysaor
Backdoor/win32.agentb
Trojan/win32.agent
Polyloader
Asyncrat_rat
Industry:
Energy, Government, Education, Retail, Telco
Geo:
American, Chinese, India, Pakistan, Indian, Asia, China, Bangladesh, Pakistani
TTPs:
Tactics: 5
Technics: 0
IOCs:
File: 18
IP: 2
Hash: 16
Registry: 1
Path: 1
www.antiy.cn
Confucius:隐藏在CloudFlare下的垂钓者
安天是引领威胁检测与防御能力发展的网络安全国家队,为客户构建端点防护、流量监测、边界防护、导流捕获、深度分析、应急处置的安全基石
#ParsedReport
14-07-2022
GhostSec Raising the Bar
https://cyberint.com/blog/research/ghostsec-raising-the-bar
Actors/Campaigns:
Ghostsec (motivation: hacktivism)
Threats:
Conti
Dirty_pipe_vuln
Webadmin_tool
Metasploit_tool
Zerologon_vuln
Industry:
Ics, Telco, Aerospace, Energy, Financial, Iot
Geo:
Israeli, Israel, American, Russian, Lebanon, Ukraine, Nigeria, Colombia, Africa
CVEs:
CVE-2021-41773 [Vulners]
Vulners: Score: 4.3, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache http server (2.4.49)
- fedoraproject fedora (34, 35)
- oracle instantis enterprisetrack (17.1, 17.2, 17.3)
- netapp cloud backup (-)
CVE-2021-41277 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- metabase (0.40.0, 0.40.1, 0.40.2, 0.40.3, 0.40.4, 1.40.0, 1.40.1, 1.40.2, 1.40.3, 1.40.4)
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2022-0847 [Vulners]
Vulners: Score: 7.2, CVSS: 4.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- linux linux kernel (<5.16.11, <5.15.25, <5.10.102)
- fedoraproject fedora (35)
- redhat enterprise linux (8.0)
- redhat enterprise linux eus (8.2, 8.4)
- redhat enterprise linux server tus (8.2, 8.4)
have more...
IOCs:
File: 1
Links:
14-07-2022
GhostSec Raising the Bar
https://cyberint.com/blog/research/ghostsec-raising-the-bar
Actors/Campaigns:
Ghostsec (motivation: hacktivism)
Threats:
Conti
Dirty_pipe_vuln
Webadmin_tool
Metasploit_tool
Zerologon_vuln
Industry:
Ics, Telco, Aerospace, Energy, Financial, Iot
Geo:
Israeli, Israel, American, Russian, Lebanon, Ukraine, Nigeria, Colombia, Africa
CVEs:
CVE-2021-41773 [Vulners]
Vulners: Score: 4.3, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- apache http server (2.4.49)
- fedoraproject fedora (34, 35)
- oracle instantis enterprisetrack (17.1, 17.2, 17.3)
- netapp cloud backup (-)
CVE-2021-41277 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.9
X-Force: Patch: Official fix
Soft:
- metabase (0.40.0, 0.40.1, 0.40.2, 0.40.3, 0.40.4, 1.40.0, 1.40.1, 1.40.2, 1.40.3, 1.40.4)
CVE-2020-1472 [Vulners]
Vulners: Score: 9.3, CVSS: 3.3,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2)
- microsoft windows server 2012 (-, r2)
- microsoft windows server 2016 (-, 1903, 1909, 2004)
- microsoft windows server 2019 (-)
- fedoraproject fedora (31, 32, 33)
have more...
CVE-2022-0847 [Vulners]
Vulners: Score: 7.2, CVSS: 4.0,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- linux linux kernel (<5.16.11, <5.15.25, <5.10.102)
- fedoraproject fedora (35)
- redhat enterprise linux (8.0)
- redhat enterprise linux eus (8.2, 8.4)
- redhat enterprise linux server tus (8.2, 8.4)
have more...
IOCs:
File: 1
Links:
https://github.com/FueledAmphttps://github.com/SoloMschttps://github.com/U53RW4R3https://github.com/ghostsec420https://github.com/NeverWonderLandCyberint
GhostSec Raising the Bar
Cyberint observed a new hacktivist campaign targeting multiple organizations. The campaign is led by hacktivists group called GhostSec.
#ParsedReport
14-07-2022
Above the Fold and in Your Inbox: Tracing State-Aligned Activity Targeting Journalists, Media
https://www.proofpoint.com/us/blog/threat-insight/above-fold-and-your-inbox-tracing-state-aligned-activity-targeting-journalists
Actors/Campaigns:
Ta412 (motivation: cyber_espionage)
Apt31
Ta459
Ta404
Lazarus
Dream_job
Ta482
Cleaver
Ta456
Tortoiseshell
Ta457
Threats:
Beacon
Atmosphere
Industry:
Government, Financial, Energy
Geo:
Israel, Ukraine, Iran, Georgia, Belarus, Russia, Korean, Asia, Pakistani, Turkish, Korea, Afghanistan, Turkey, Chinese, China
IOCs:
File: 4
Domain: 2
Email: 1
14-07-2022
Above the Fold and in Your Inbox: Tracing State-Aligned Activity Targeting Journalists, Media
https://www.proofpoint.com/us/blog/threat-insight/above-fold-and-your-inbox-tracing-state-aligned-activity-targeting-journalists
Actors/Campaigns:
Ta412 (motivation: cyber_espionage)
Apt31
Ta459
Ta404
Lazarus
Dream_job
Ta482
Cleaver
Ta456
Tortoiseshell
Ta457
Threats:
Beacon
Atmosphere
Industry:
Government, Financial, Energy
Geo:
Israel, Ukraine, Iran, Georgia, Belarus, Russia, Korean, Asia, Pakistani, Turkish, Korea, Afghanistan, Turkey, Chinese, China
IOCs:
File: 4
Domain: 2
Email: 1
Proofpoint
APTs Targeting Journalists & Media Organizations | Proofpoint US
APTs regularly target and pose as journalists and media organizations to advance their state-aligned initiatives. Learn more about Proofpoint's research.
#ParsedReport
14-07-2022
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware
https://www.microsoft.com/security/blog/2022/07/14/north-korean-threat-actor-targets-small-and-midsize-businesses-with-h0lygh0st-ransomware
Actors/Campaigns:
Dev-0530
Plutonium
Lazarus
Threats:
H0lygh0st (tags: ransomware, backdoor, malware)
Siennapurple (tags: ransomware, backdoor, malware)
Siennablue (tags: ransomware, malware)
Lockdown (tags: ransomware)
Beacon (tags: ransomware)
Industry:
Government, Energy, Financial
Geo:
Korea, Korean, India
CVEs:
CVE-2022-26352 [Vulners]
Vulners: Score: Unknown, CVSS: Unknown,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Url: 7
IP: 3
Email: 1
Hash: 4
Path: 1
YARA: Found
Links:
14-07-2022
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware
https://www.microsoft.com/security/blog/2022/07/14/north-korean-threat-actor-targets-small-and-midsize-businesses-with-h0lygh0st-ransomware
Actors/Campaigns:
Dev-0530
Plutonium
Lazarus
Threats:
H0lygh0st (tags: ransomware, backdoor, malware)
Siennapurple (tags: ransomware, backdoor, malware)
Siennablue (tags: ransomware, malware)
Lockdown (tags: ransomware)
Beacon (tags: ransomware)
Industry:
Government, Energy, Financial
Geo:
Korea, Korean, India
CVEs:
CVE-2022-26352 [Vulners]
Vulners: Score: Unknown, CVSS: Unknown,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Url: 7
IP: 3
Email: 1
Hash: 4
Path: 1
YARA: Found
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0530\_FileExtRename.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0530\_July2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/SecurityAlert/Dev-0530AVHits.yamlMicrosoft News
North Korean threat actor targets small and midsize businesses with H0lyGh0st ransomware
A group of actors originating from North Korea that MSTIC tracks as DEV-0530 has been developing and using ransomware in attacks since June 2021. This group, which calls itself H0lyGh0st, utilizes a ransomware payload with the same name.
#ParsedReport
14-07-2022
Climbing Mount Everest: Black-Byte Bytes Back?
https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back
Threats:
Blackbyte (tags: scan, rat, malware, ransomware)
Everbe (tags: ransomware)
Procdump_tool
Cobalt_strike
Metasploit_tool
Splashtop_tool
Beacon
Meterpreter_tool
Netscan_tool
Atera_tool
TTPs:
Tactics: 10
Technics: 12
IOCs:
File: 12
Path: 5
Url: 3
14-07-2022
Climbing Mount Everest: Black-Byte Bytes Back?
https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back
Threats:
Blackbyte (tags: scan, rat, malware, ransomware)
Everbe (tags: ransomware)
Procdump_tool
Cobalt_strike
Metasploit_tool
Splashtop_tool
Beacon
Meterpreter_tool
Netscan_tool
Atera_tool
TTPs:
Tactics: 10
Technics: 12
IOCs:
File: 12
Path: 5
Url: 3
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
#ParsedReport
14-07-2022
Targeted Attack on Government Agencies
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/targeted-attack-on-government-agencies.html
Threats:
Asyncrat_rat
Limerat_rat (tags: rat, malware)
Industry:
Financial, Government, Healthcare
Geo:
Asian, Italy, Poland, Indian, Asia, Afghanistan, India
TTPs:
Tactics: 1
Technics: 8
IOCs:
File: 6
Registry: 1
IP: 1
Email: 7
Links:
14-07-2022
Targeted Attack on Government Agencies
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/targeted-attack-on-government-agencies.html
Threats:
Asyncrat_rat
Limerat_rat (tags: rat, malware)
Industry:
Financial, Government, Healthcare
Geo:
Asian, Italy, Poland, Indian, Asia, Afghanistan, India
TTPs:
Tactics: 1
Technics: 8
IOCs:
File: 6
Registry: 1
IP: 1
Email: 7
Links:
https://github.com/NYAN-x-CAT/Lime-RAThttps://github.com/NYAN-x-CAT/AsyncRAT-C-SharpTrellix
Targeted attack on Government Agencies
The Trellix Email Security Research Team has discovered a malicious campaign targeting government agencies of Afghanistan, India, Italy, Poland, and the United States since 2021.
#ParsedReport
14-07-2022
New variant of Android SpyJoker malware removed from Play Store after 3 million+ installs
https://blog.malwarebytes.com/android/2022/07/new-variant-of-android-spyjoker-malware-removed-from-play-store-after-3-million-installs
Threats:
Spyjoker (tags: rat, malware, trojan, fraud)
Joker (tags: malware, trojan)
Industry:
Financial
14-07-2022
New variant of Android SpyJoker malware removed from Play Store after 3 million+ installs
https://blog.malwarebytes.com/android/2022/07/new-variant-of-android-spyjoker-malware-removed-from-play-store-after-3-million-installs
Threats:
Spyjoker (tags: rat, malware, trojan, fraud)
Joker (tags: malware, trojan)
Industry:
Financial
Malwarebytes Labs
New variant of Android SpyJoker malware removed from Play Store after 3 million+ installs
A researcher found eight malware-laden apps in the Play Store which have been downloaded over 3 million times.
#ParsedReport
14-07-2022
Rise in Qakbot attacks traced to evolving threat techniques
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques
Threats:
Qakbot (tags: malware, botnet, scan, trojan)
Industry:
Financial
IOCs:
File: 32
Hash: 11
Path: 4
IP: 57
Domain: 136
Functions Names: 3
14-07-2022
Rise in Qakbot attacks traced to evolving threat techniques
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques
Threats:
Qakbot (tags: malware, botnet, scan, trojan)
Industry:
Financial
IOCs:
File: 32
Hash: 11
Path: 4
IP: 57
Domain: 136
Functions Names: 3
Zscaler
Rise in Qakbot attacks traced to evolving threat techniques | Zscaler
Qakbot leverages ZIP archive file having embedded files such as Microsoft Office files, LNK, Powershell, and more.
#ParsedReport
14-07-2022
Transparent Tribe begins targeting education sector in latest campaign
http://blog.talosintelligence.com/2022/07/transparent-tribe-targets-education.html
Actors/Campaigns:
Transparenttribe (motivation: cyber_espionage)
Threats:
Crimson_rat (tags: rat, keylogger)
Oblique_rat
Capra_rat
Industry:
Government, Education
Geo:
Afghanistan, Indian, Pakistani, Pakistan, India
IOCs:
Hash: 3
Domain: 28
Email: 1
IP: 2
Url: 2
Links:
14-07-2022
Transparent Tribe begins targeting education sector in latest campaign
http://blog.talosintelligence.com/2022/07/transparent-tribe-targets-education.html
Actors/Campaigns:
Transparenttribe (motivation: cyber_espionage)
Threats:
Crimson_rat (tags: rat, keylogger)
Oblique_rat
Capra_rat
Industry:
Government, Education
Geo:
Afghanistan, Indian, Pakistani, Pakistan, India
IOCs:
Hash: 3
Domain: 28
Email: 1
IP: 2
Url: 2
Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2022/07Talosintelligence
Transparent Tribe begins targeting education sector in latest campaign
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
#ParsedReport
14-07-2022
A Hit is made: Suspected India-based Sidewinder APT successfully cyber attacks Pakistan military focused targets
https://blog.checkpoint.com/2022/07/13/a-hit-is-made-suspected-india-based-sidewinder-apt-successfully-cyber-attacks-pakistan-military-focused-targets
Actors/Campaigns:
Sidewinder (motivation: cyber_espionage)
Industry:
Education, Maritime, Aerospace, Government
Geo:
Ukraine, Pakistan, China, India, Indian, Pakistani, Russian
IOCs:
Hash: 2
Url: 2
14-07-2022
A Hit is made: Suspected India-based Sidewinder APT successfully cyber attacks Pakistan military focused targets
https://blog.checkpoint.com/2022/07/13/a-hit-is-made-suspected-india-based-sidewinder-apt-successfully-cyber-attacks-pakistan-military-focused-targets
Actors/Campaigns:
Sidewinder (motivation: cyber_espionage)
Industry:
Education, Maritime, Aerospace, Government
Geo:
Ukraine, Pakistan, China, India, Indian, Pakistani, Russian
IOCs:
Hash: 2
Url: 2