#ParsedReport
14-07-2022
Climbing Mount Everest: Black-Byte Bytes Back?
https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back
Threats:
Blackbyte (tags: scan, rat, malware, ransomware)
Everbe (tags: ransomware)
Procdump_tool
Cobalt_strike
Metasploit_tool
Splashtop_tool
Beacon
Meterpreter_tool
Netscan_tool
Atera_tool
TTPs:
Tactics: 10
Technics: 12
IOCs:
File: 12
Path: 5
Url: 3
14-07-2022
Climbing Mount Everest: Black-Byte Bytes Back?
https://research.nccgroup.com/2022/07/13/climbing-mount-everest-black-byte-bytes-back
Threats:
Blackbyte (tags: scan, rat, malware, ransomware)
Everbe (tags: ransomware)
Procdump_tool
Cobalt_strike
Metasploit_tool
Splashtop_tool
Beacon
Meterpreter_tool
Netscan_tool
Atera_tool
TTPs:
Tactics: 10
Technics: 12
IOCs:
File: 12
Path: 5
Url: 3
Nccgroup
Cyber Security Research
Cutting-edge cyber security research from NCC Group. Find public reports, technical advisories, analyses, & other novel insights from our global experts.
#ParsedReport
14-07-2022
Targeted Attack on Government Agencies
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/targeted-attack-on-government-agencies.html
Threats:
Asyncrat_rat
Limerat_rat (tags: rat, malware)
Industry:
Financial, Government, Healthcare
Geo:
Asian, Italy, Poland, Indian, Asia, Afghanistan, India
TTPs:
Tactics: 1
Technics: 8
IOCs:
File: 6
Registry: 1
IP: 1
Email: 7
Links:
14-07-2022
Targeted Attack on Government Agencies
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/targeted-attack-on-government-agencies.html
Threats:
Asyncrat_rat
Limerat_rat (tags: rat, malware)
Industry:
Financial, Government, Healthcare
Geo:
Asian, Italy, Poland, Indian, Asia, Afghanistan, India
TTPs:
Tactics: 1
Technics: 8
IOCs:
File: 6
Registry: 1
IP: 1
Email: 7
Links:
https://github.com/NYAN-x-CAT/Lime-RAThttps://github.com/NYAN-x-CAT/AsyncRAT-C-SharpTrellix
Targeted attack on Government Agencies
The Trellix Email Security Research Team has discovered a malicious campaign targeting government agencies of Afghanistan, India, Italy, Poland, and the United States since 2021.
#ParsedReport
14-07-2022
New variant of Android SpyJoker malware removed from Play Store after 3 million+ installs
https://blog.malwarebytes.com/android/2022/07/new-variant-of-android-spyjoker-malware-removed-from-play-store-after-3-million-installs
Threats:
Spyjoker (tags: rat, malware, trojan, fraud)
Joker (tags: malware, trojan)
Industry:
Financial
14-07-2022
New variant of Android SpyJoker malware removed from Play Store after 3 million+ installs
https://blog.malwarebytes.com/android/2022/07/new-variant-of-android-spyjoker-malware-removed-from-play-store-after-3-million-installs
Threats:
Spyjoker (tags: rat, malware, trojan, fraud)
Joker (tags: malware, trojan)
Industry:
Financial
Malwarebytes Labs
New variant of Android SpyJoker malware removed from Play Store after 3 million+ installs
A researcher found eight malware-laden apps in the Play Store which have been downloaded over 3 million times.
#ParsedReport
14-07-2022
Rise in Qakbot attacks traced to evolving threat techniques
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques
Threats:
Qakbot (tags: malware, botnet, scan, trojan)
Industry:
Financial
IOCs:
File: 32
Hash: 11
Path: 4
IP: 57
Domain: 136
Functions Names: 3
14-07-2022
Rise in Qakbot attacks traced to evolving threat techniques
https://www.zscaler.com/blogs/security-research/rise-qakbot-attacks-traced-evolving-threat-techniques
Threats:
Qakbot (tags: malware, botnet, scan, trojan)
Industry:
Financial
IOCs:
File: 32
Hash: 11
Path: 4
IP: 57
Domain: 136
Functions Names: 3
Zscaler
Rise in Qakbot attacks traced to evolving threat techniques | Zscaler
Qakbot leverages ZIP archive file having embedded files such as Microsoft Office files, LNK, Powershell, and more.
#ParsedReport
14-07-2022
Transparent Tribe begins targeting education sector in latest campaign
http://blog.talosintelligence.com/2022/07/transparent-tribe-targets-education.html
Actors/Campaigns:
Transparenttribe (motivation: cyber_espionage)
Threats:
Crimson_rat (tags: rat, keylogger)
Oblique_rat
Capra_rat
Industry:
Government, Education
Geo:
Afghanistan, Indian, Pakistani, Pakistan, India
IOCs:
Hash: 3
Domain: 28
Email: 1
IP: 2
Url: 2
Links:
14-07-2022
Transparent Tribe begins targeting education sector in latest campaign
http://blog.talosintelligence.com/2022/07/transparent-tribe-targets-education.html
Actors/Campaigns:
Transparenttribe (motivation: cyber_espionage)
Threats:
Crimson_rat (tags: rat, keylogger)
Oblique_rat
Capra_rat
Industry:
Government, Education
Geo:
Afghanistan, Indian, Pakistani, Pakistan, India
IOCs:
Hash: 3
Domain: 28
Email: 1
IP: 2
Url: 2
Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2022/07Talosintelligence
Transparent Tribe begins targeting education sector in latest campaign
A blog from the world class Intelligence Group, Talos, Cisco's Intelligence Group
#ParsedReport
14-07-2022
A Hit is made: Suspected India-based Sidewinder APT successfully cyber attacks Pakistan military focused targets
https://blog.checkpoint.com/2022/07/13/a-hit-is-made-suspected-india-based-sidewinder-apt-successfully-cyber-attacks-pakistan-military-focused-targets
Actors/Campaigns:
Sidewinder (motivation: cyber_espionage)
Industry:
Education, Maritime, Aerospace, Government
Geo:
Ukraine, Pakistan, China, India, Indian, Pakistani, Russian
IOCs:
Hash: 2
Url: 2
14-07-2022
A Hit is made: Suspected India-based Sidewinder APT successfully cyber attacks Pakistan military focused targets
https://blog.checkpoint.com/2022/07/13/a-hit-is-made-suspected-india-based-sidewinder-apt-successfully-cyber-attacks-pakistan-military-focused-targets
Actors/Campaigns:
Sidewinder (motivation: cyber_espionage)
Industry:
Education, Maritime, Aerospace, Government
Geo:
Ukraine, Pakistan, China, India, Indian, Pakistani, Russian
IOCs:
Hash: 2
Url: 2
#ParsedReport
14-07-2022
ApolloRat: Evasive Malware Compiled using Nuitka
https://blog.cyble.com/2022/07/14/apollorat-evasive-malware-compiled-using-nuitka
Threats:
Apollorat (tags: trojan, malware, rat, stealer, phishing)
Beacon
IOCs:
Hash: 3
File: 1
14-07-2022
ApolloRat: Evasive Malware Compiled using Nuitka
https://blog.cyble.com/2022/07/14/apollorat-evasive-malware-compiled-using-nuitka
Threats:
Apollorat (tags: trojan, malware, rat, stealer, phishing)
Beacon
IOCs:
Hash: 3
File: 1
Cyble
ApolloRat: Evasive Malware Compiled Using Nuitka - Cyble
Cyble analyzes ApolloRat, an Evasive Remote Access Trojan leveraging Discord as a Command & Control Server.
#ParsedReport
15-07-2022
STOP/DJVU Employs Vidar Stealer Before Encrypting Files
https://labs.k7computing.com/index.php/stop-djvu-employs-vidar-stealer-before-encrypting-files
Threats:
Vidar_stealer (tags: ransomware, malware, stealer, rat, trojan)
Stop (tags: ransomware, malware, stealer, rat, trojan)
Process_injection_technique
Gandcrab
Geo:
Kyrgyzstan, Kazakhstan, Ukraine, Belarus, Syria, Armenia, Azerbaijan, Uzbekistan, Russia, Tajikistan
IOCs:
File: 7
Path: 1
Url: 2
IP: 1
Functions Names: 1
15-07-2022
STOP/DJVU Employs Vidar Stealer Before Encrypting Files
https://labs.k7computing.com/index.php/stop-djvu-employs-vidar-stealer-before-encrypting-files
Threats:
Vidar_stealer (tags: ransomware, malware, stealer, rat, trojan)
Stop (tags: ransomware, malware, stealer, rat, trojan)
Process_injection_technique
Gandcrab
Geo:
Kyrgyzstan, Kazakhstan, Ukraine, Belarus, Syria, Armenia, Azerbaijan, Uzbekistan, Russia, Tajikistan
IOCs:
File: 7
Path: 1
Url: 2
IP: 1
Functions Names: 1
K7 Labs
STOP/DJVU Employs Vidar Stealer Before Encrypting Files
STOP/DJVU ransomware was first seen in the last quarter of 2018. Since then we have seen various forms of this […]
#ParsedReport
15-07-2022
Dragon News Blog. An Analysis of Infrastructure linked to the Hagga Threat Actor
https://team-cymru.com/blog/2022/07/12/an-analysis-of-infrastructure-linked-to-the-hagga-threat-actor/?utm_source=Social&utm_medium=linkedin&utm_campaign=threat%20research%20blog
Actors/Campaigns:
Aggaa
Threats:
Agent_tesla
Mana_tool
Revenge_rat
Azorult
Lokibot_stealer
Formbook
Beacon
Industry:
Telco
Geo:
Vietnam, Pakistan
IOCs:
IP: 18
Domain: 3
File: 1
Url: 1
Functions Names: 1
15-07-2022
Dragon News Blog. An Analysis of Infrastructure linked to the Hagga Threat Actor
https://team-cymru.com/blog/2022/07/12/an-analysis-of-infrastructure-linked-to-the-hagga-threat-actor/?utm_source=Social&utm_medium=linkedin&utm_campaign=threat%20research%20blog
Actors/Campaigns:
Aggaa
Threats:
Agent_tesla
Mana_tool
Revenge_rat
Azorult
Lokibot_stealer
Formbook
Beacon
Industry:
Telco
Geo:
Vietnam, Pakistan
IOCs:
IP: 18
Domain: 3
File: 1
Url: 1
Functions Names: 1
👍1
#ParsedReport
15-07-2022
Digium Phones Under Attack: Insight Into the Web Shell Implant
https://unit42.paloaltonetworks.com/digium-phones-web-shell
Geo:
Netherlands, Russian
CVEs:
CVE-2021-45461 [Vulners]
Vulners: Score: 7.5, CVSS: 6.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sangoma restapps (15.0.19.87, 15.0.19.88, 16.0.18.40, 16.0.18.41)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Url: 3
IP: 1
Domain: 8
Hash: 1
Functions Names: 1
Links:
15-07-2022
Digium Phones Under Attack: Insight Into the Web Shell Implant
https://unit42.paloaltonetworks.com/digium-phones-web-shell
Geo:
Netherlands, Russian
CVEs:
CVE-2021-45461 [Vulners]
Vulners: Score: 7.5, CVSS: 6.7,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- sangoma restapps (15.0.19.87, 15.0.19.88, 16.0.18.40, 16.0.18.41)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Url: 3
IP: 1
Domain: 8
Hash: 1
Functions Names: 1
Links:
https://github.com/FreePBX/digium\_phonesUnit 42
Digium Phones Under Attack: Insight Into the Web Shell Implant
We witnessed more than 500,000 unique samples of malicious traffic targeting Digium Asterisk software for VoIP phone devices.
#ParsedReport
15-07-2022
Stealthy OpenDocument Malware Deployed Against Latin American Hotels
https://threatresearch.ext.hp.com/stealthy-opendocument-malware-targets-latin-american-hotels
Threats:
Asyncrat_rat
Geo:
Spanish, Portuguese, America, American
TTPs:
IOCs:
File: 4
Domain: 2
Hash: 14
Functions Names: 2
15-07-2022
Stealthy OpenDocument Malware Deployed Against Latin American Hotels
https://threatresearch.ext.hp.com/stealthy-opendocument-malware-targets-latin-american-hotels
Threats:
Asyncrat_rat
Geo:
Spanish, Portuguese, America, American
TTPs:
IOCs:
File: 4
Domain: 2
Hash: 14
Functions Names: 2
HP Wolf Security
Stealthy OpenDocument Malware Deployed Against Latin American Hotels | HP Wolf Security
Don’t let cyber threats get the best of you. Read our post, Stealthy OpenDocument Malware Deployed Against Latin American Hotels, to learn more about cyber threats and cyber security.
#ParsedReport
15-07-2022
Hacktivist Group DragonForce Actively Targeting Indian Entities, Shares an Exploit for a Critical Confluence Server Vulnerability CVE-2022-26134
https://cloudsek.com/threatintelligence/hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134/?utm_source=rss&utm_medium=rss&utm_campaign=hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134
Actors/Campaigns:
Dragonforce (motivation: hacktivism)
Industry:
Government
Geo:
Malaysia, India, Indian
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
15-07-2022
Hacktivist Group DragonForce Actively Targeting Indian Entities, Shares an Exploit for a Critical Confluence Server Vulnerability CVE-2022-26134
https://cloudsek.com/threatintelligence/hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134/?utm_source=rss&utm_medium=rss&utm_campaign=hacktivist-group-dragonforce-actively-targeting-indian-entities-shares-an-exploit-for-a-critical-confluence-server-vulnerability-cve-2022-26134
Actors/Campaigns:
Dragonforce (motivation: hacktivism)
Industry:
Government
Geo:
Malaysia, India, Indian
CVEs:
CVE-2022-26134 [Vulners]
Vulners: Score: 7.5, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- atlassian confluence data center (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
- atlassian confluence server (7.18.0, <7.17.4, <7.16.4, <7.15.2, <7.14.3, <7.13.7, <7.4.17)
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 1
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
Hacktivist Group DragonForce Actively Targeting Indian Entities, Shares an Exploit for a Critical Confluence Server Vulnerability…
XVigil identified a post on a Telegram channel where the hacktivist group, DragonForce Malaysia has shared an exploit to CVE-2022-26134 to actively target and exploit Indian entities.
#ParsedReport
15-07-2022
Resurgence in Qakbot Malware Activity
https://www.esentire.com/blog/resurgence-in-qakbot-malware-activity
Threats:
Qakbot (tags: malware, phishing, rat)
More_eggs (tags: malware)
Html_smuggling_technique
Follina_vuln
Emotet
Bumblebee
Icedid
Quantum_tool
Geo:
Emea, Apac, America, Africa
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
15-07-2022
Resurgence in Qakbot Malware Activity
https://www.esentire.com/blog/resurgence-in-qakbot-malware-activity
Threats:
Qakbot (tags: malware, phishing, rat)
More_eggs (tags: malware)
Html_smuggling_technique
Follina_vuln
Emotet
Bumblebee
Icedid
Quantum_tool
Geo:
Emea, Apac, America, Africa
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
eSentire
Resurgence in Qakbot Malware Activity
Learn about the Qakbot malware including what we found, how we found it and recommendations from our Threat Response Unit (TRU) to protect your business from this cyber threat.
#ParsedReport
15-07-2022
APT-C-26Lazarus. APT-C-26 (lazarus) organization forgery e-commerce component attack activity analysis report
https://mp.weixin.qq.com/s/USitU4jAg9y2XkQxbwcAPQ
Actors/Campaigns:
Lazarus
Ice_fog
Threats:
Httpupploader
Nukesped_rat
Nukespd
Mimikatz
Industry:
Government, E-commerce
Geo:
Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Path: 1
Url: 2
Hash: 2
IP: 2
15-07-2022
APT-C-26Lazarus. APT-C-26 (lazarus) organization forgery e-commerce component attack activity analysis report
https://mp.weixin.qq.com/s/USitU4jAg9y2XkQxbwcAPQ
Actors/Campaigns:
Lazarus
Ice_fog
Threats:
Httpupploader
Nukesped_rat
Nukespd
Mimikatz
Industry:
Government, E-commerce
Geo:
Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Path: 1
Url: 2
Hash: 2
IP: 2
Weixin Official Accounts Platform
APT-C-26(Lazarus)组织伪造电商组件攻击活动分析报告
近期,360高级威胁研究院发现了来自Lazarus组织的攻击活动,本次攻击目的明确,攻击手段隐蔽性强,并且不排除有相关后续行动
#ParsedReport
15-07-2022
Exploiting Arbitrary Object Instantiations in PHP without Custom Classes
https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations
Geo:
Russian
CVEs:
CVE-2022-31085 [Vulners]
Vulners: Score: 4.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.2
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31084 [Vulners]
Vulners: Score: 6.8, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31088 [Vulners]
Vulners: Score: 5.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31087 [Vulners]
Vulners: Score: 7.2, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31086 [Vulners]
Vulners: Score: 6.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 4.7
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
TTPs:
Tactics: 1
Technics: 0
IOCs:
IP: 1
Functions Names: 3
Links:
15-07-2022
Exploiting Arbitrary Object Instantiations in PHP without Custom Classes
https://swarm.ptsecurity.com/exploiting-arbitrary-object-instantiations
Geo:
Russian
CVEs:
CVE-2022-31085 [Vulners]
Vulners: Score: 4.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.2
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31084 [Vulners]
Vulners: Score: 6.8, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.4
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31088 [Vulners]
Vulners: Score: 5.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.5
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31087 [Vulners]
Vulners: Score: 7.2, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
CVE-2022-31086 [Vulners]
Vulners: Score: 6.0, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 4.7
X-Force: Patch: Official fix
Soft:
- ldap-account-manager ldap account manager (<8.0)
- debian debian linux (11.0)
TTPs:
Tactics: 1
Technics: 0
IOCs:
IP: 1
Functions Names: 3
Links:
https://github.com/LDAPAccountManager/lam/blob/6d24baa18223f0babfed2c8890381fb54cdcd6e9/lam-packaging/debian/controlhttps://github.com/ImageMagick/ImageMagick/blob/d2a918098878bd73a57a34b901b5ae85c0c8d17f/MagickCore/utility.c#L692https://github.com/ImageMagick/ImageMagick/blob/d2a918098878bd73a57a34b901b5ae85c0c8d17f/coders/vid.c#L98https://github.com/LDAPAccountManager/lamЕсли к Вам обращаются на CTI-ном, и Вы не совсем понимаете что от Вас хотят, то вотъ словарикъ
https://github.com/BushidoUK/CTI-Lexicon/blob/main/Lexicon.md
https://github.com/BushidoUK/CTI-Lexicon/blob/main/Lexicon.md
GitHub
CTI-Lexicon/Lexicon.md at main · BushidoUK/CTI-Lexicon
Dictionary of CTI-related acronyms, terms, and jargon - BushidoUK/CTI-Lexicon
#ParsedReport
18-07-2022
Raccoon back with new claws!
https://labs.k7computing.com/index.php/raccoon-back-with-new-claws
Threats:
Raccoon_stealer (tags: malware, proxy, trojan, stealer)
Vmprotect
Geo:
Russia
IOCs:
File: 16
Hash: 2
Registry: 3
Url: 1
IP: 1
Functions Names: 10
18-07-2022
Raccoon back with new claws!
https://labs.k7computing.com/index.php/raccoon-back-with-new-claws
Threats:
Raccoon_stealer (tags: malware, proxy, trojan, stealer)
Vmprotect
Geo:
Russia
IOCs:
File: 16
Hash: 2
Registry: 3
Url: 1
IP: 1
Functions Names: 10
K7 Labs
Raccoon back with new claws!
Raccoon infostealer was first released in April 2019, the initial Version1(V1) was distributed in telegram groups and other forums as […]
#ParsedReport
18-07-2022
From the Front Lines \| 8220 Gang Massively Expands Cloud Botnet to 30,000 Infected Hosts
https://www.sentinelone.com/blog/from-the-front-lines-8220-gang-massively-expands-cloud-botnet-to-30000-infected-hosts
Threats:
Pwnrig_botnet (tags: botnet, cryptomining)
Whatminer
Tsunami_botnet (tags: botnet)
Xmrig_miner (tags: cryptomining)
Industry:
Government
Geo:
Brazil
IOCs:
IP: 3
Hash: 145
Domain: 14
Functions Names: 1
Links:
18-07-2022
From the Front Lines \| 8220 Gang Massively Expands Cloud Botnet to 30,000 Infected Hosts
https://www.sentinelone.com/blog/from-the-front-lines-8220-gang-massively-expands-cloud-botnet-to-30000-infected-hosts
Threats:
Pwnrig_botnet (tags: botnet, cryptomining)
Whatminer
Tsunami_botnet (tags: botnet)
Xmrig_miner (tags: cryptomining)
Industry:
Government
Geo:
Brazil
IOCs:
IP: 3
Hash: 145
Domain: 14
Functions Names: 1
Links:
https://github.com/xmrig/xmrigSentinelOne
From the Front Lines | 8220 Gang Massively Expands Cloud Botnet to 30,000 Infected Hosts
Low-level crimeware gang has been exploiting misconfigured and publicly accessible Docker and other cloud instances with roaring success.
#ParsedReport
18-07-2022
Joker, Facestealer and Coper banking malwares on Google Play store
https://www.zscaler.com/blogs/security-research/joker-facestealer-and-coper-banking-malwares-google-play-store
Threats:
Joker (tags: scan, spam, malware)
Facestealer (tags: spam, malware)
Coper (tags: spam, dropper, backdoor, trojan, malware)
Industry:
Healthcare, E-commerce, Financial
Geo:
India, Australia, America
IOCs:
File: 12
Url: 8
Domain: 3
Hash: 1
Functions Names: 1
18-07-2022
Joker, Facestealer and Coper banking malwares on Google Play store
https://www.zscaler.com/blogs/security-research/joker-facestealer-and-coper-banking-malwares-google-play-store
Threats:
Joker (tags: scan, spam, malware)
Facestealer (tags: spam, malware)
Coper (tags: spam, dropper, backdoor, trojan, malware)
Industry:
Healthcare, E-commerce, Financial
Geo:
India, Australia, America
IOCs:
File: 12
Url: 8
Domain: 3
Hash: 1
Functions Names: 1
Zscaler
On Google Play, Joker, Facestealer, & Coper Banking Malware
Joker, Facestealers and Banker swarming Google Play store
#ParsedReport
19-07-2022
Netskope Threat Coverage: Microsoft Discloses New Adversary-in-the-Middle (AiTM) Phishing Attack
https://www.netskope.com/blog/netskope-threat-coverage-microsoft-discloses-new-adversary-in-the-middle-aitm-phishing-attack
Actors/Campaigns:
Bec
Threats:
Aitm_technique (tags: proxy, rat, phishing, scan, malware, fraud)
Phoca_technique
Evilginx2_tool
Emotet
Industry:
Financial, Telco
Links:
19-07-2022
Netskope Threat Coverage: Microsoft Discloses New Adversary-in-the-Middle (AiTM) Phishing Attack
https://www.netskope.com/blog/netskope-threat-coverage-microsoft-discloses-new-adversary-in-the-middle-aitm-phishing-attack
Actors/Campaigns:
Bec
Threats:
Aitm_technique (tags: proxy, rat, phishing, scan, malware, fraud)
Phoca_technique
Evilginx2_tool
Emotet
Industry:
Financial, Telco
Links:
https://github.com/kgretzky/evilginx2Netskope
Netskope Threat Coverage: Microsoft Discloses New Adversary-in-the-Middle (AiTM) Phishing Attack
Summary On July 12, 2022, Microsoft researchers disclosed a large-scale phishing campaign that has targeted more than 10,000 organizations since September
#ParsedReport
19-07-2022
Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive
https://unit42.paloaltonetworks.com/cloaked-ursa-online-storage-services-campaigns
Actors/Campaigns:
Duke
Threats:
Cobalt_strike
Mispadu (tags: dropper, phishing, malware)
Envyscout (tags: malware)
Whispergate
Html_smuggling_technique (tags: malware)
Beacon
Industry:
Government
Geo:
Ukraine, Russian, Egypt, Turkey, Czech, Emea, Japan, America, Portugal, Austrian, Brazil, Apac, Portuguese
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 12
Hash: 16
Domain: 3
Registry: 3
Path: 1
Email: 1
IP: 3
19-07-2022
Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive
https://unit42.paloaltonetworks.com/cloaked-ursa-online-storage-services-campaigns
Actors/Campaigns:
Duke
Threats:
Cobalt_strike
Mispadu (tags: dropper, phishing, malware)
Envyscout (tags: malware)
Whispergate
Html_smuggling_technique (tags: malware)
Beacon
Industry:
Government
Geo:
Ukraine, Russian, Egypt, Turkey, Czech, Emea, Japan, America, Portugal, Austrian, Brazil, Apac, Portuguese
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 12
Hash: 16
Domain: 3
Registry: 3
Path: 1
Email: 1
IP: 3
Unit 42
Russian APT29 Hackers Use Online Storage Services, DropBox and Google Drive
Cloaked Ursa (aka APT29, Nobelium or Cozy Bear) has recently used trusted online storage services to deliver Cobalt Strike.