#ParsedReport
31-07-2022
Ransomware Groups Ramping Up Operations
https://blog.cyble.com/2022/07/28/ransomware-groups-ramping-up-operations
Actors/Campaigns:
Blackcat
Karakurt
Threats:
Solidbit
Lockbit
Yashma
Conti
Blackcat
Industry:
Financial, Government
Languages:
rust
31-07-2022
Ransomware Groups Ramping Up Operations
https://blog.cyble.com/2022/07/28/ransomware-groups-ramping-up-operations
Actors/Campaigns:
Blackcat
Karakurt
Threats:
Solidbit
Lockbit
Yashma
Conti
Blackcat
Industry:
Financial, Government
Languages:
rust
Cyble
Ransomware Groups Ramping Up Operations
Cyble Research Labs analyzes new extortion activities used as ransomware groups resort to even more unscrupulous techniques.
#ParsedReport
31-07-2022
Targeted Attacks being carried out via DLL SideLoading
https://blog.cyble.com/2022/07/27/targeted-attacks-being-carried-out-via-dll-sideloading
Threats:
Cobalt_strike
Beacon
Qakbot
Mimikatz
Geo:
Italy
TTPs:
Tactics: 3
Technics: 5
IOCs:
File: 4
Url: 1
Hash: 2
Softs:
microsoft teams
Algorithms:
base64
Functions:
process, EnableContent, GetParagraph, AutoOpen
31-07-2022
Targeted Attacks being carried out via DLL SideLoading
https://blog.cyble.com/2022/07/27/targeted-attacks-being-carried-out-via-dll-sideloading
Threats:
Cobalt_strike
Beacon
Qakbot
Mimikatz
Geo:
Italy
TTPs:
Tactics: 3
Technics: 5
IOCs:
File: 4
Url: 1
Hash: 2
Softs:
microsoft teams
Algorithms:
base64
Functions:
process, EnableContent, GetParagraph, AutoOpen
Cyble
Cyble - Targeted Attacks Being Carried Out Via DLL SideLoading
Cyble Analyzes how Threat Actors are leveraging Microsoft applications and DLL Sideloading to deliver Cobalt Strike Beacons
#ParsedReport
31-07-2022
Underground Clipper Malware Targeting IBAN Transactions & Cryptocurrency
https://blog.cyble.com/2022/07/28/underground-clipper-malware-targeting-iban-transactions-cryptocurrency
Threats:
Iban_clipper
Stealerium_keylogger
Industry:
Financial
Geo:
Poland
Softs:
telegram
31-07-2022
Underground Clipper Malware Targeting IBAN Transactions & Cryptocurrency
https://blog.cyble.com/2022/07/28/underground-clipper-malware-targeting-iban-transactions-cryptocurrency
Threats:
Iban_clipper
Stealerium_keylogger
Industry:
Financial
Geo:
Poland
Softs:
telegram
Cyble
Underground Clipper Malware Targeting IBAN Transactions & Cryptocurrency
Cyble Analyzes Threat Actors selling Clipper Malware targeting IBAN transactions and cryptocurrency on cybercrime forums.
#ParsedReport
01-08-2022
Heres a Simple Script to Detect the Stealthy Nation-State BPFDoor
https://blog.qualys.com/vulnerabilities-threat-research/2022/08/01/heres-a-simple-script-to-detect-the-stealthy-nation-state-bpfdoor
Threats:
Bpfdoor
Red_menshen
Mangzamel
Gh0st_rat
Metasploit_tool
Timestomp_technique
Industry:
Government, Telco, Education, Logistic
Geo:
Taiwan, Asia, India, Vietnam, Myanmar, Turkey, Chinese, Korea
TTPs:
Tactics: 1
Technics: 7
IOCs:
Hash: 18
Softs:
unix
Functions:
utimes
Languages:
python, perl, lua
YARA: Found
01-08-2022
Heres a Simple Script to Detect the Stealthy Nation-State BPFDoor
https://blog.qualys.com/vulnerabilities-threat-research/2022/08/01/heres-a-simple-script-to-detect-the-stealthy-nation-state-bpfdoor
Threats:
Bpfdoor
Red_menshen
Mangzamel
Gh0st_rat
Metasploit_tool
Timestomp_technique
Industry:
Government, Telco, Education, Logistic
Geo:
Taiwan, Asia, India, Vietnam, Myanmar, Turkey, Chinese, Korea
TTPs:
Tactics: 1
Technics: 7
IOCs:
Hash: 18
Softs:
unix
Functions:
utimes
Languages:
python, perl, lua
YARA: Found
Qualys
Here’s a Simple Script to Detect the Stealthy Nation-State BPFDoor | Qualys
In this blog, the Qualys Research Team explains the mechanics of a Linux malware variant named BPFdoor. We then demonstrate the efficacy of Qualys Custom Assessment and Remediation to detect it…
#ParsedReport
01-08-2022
The TrickBot malware
https://www.telsy.com/the-trickbot-malware
Threats:
Trickbot
Ryuk
Dyre
Wannacry
Eternal_petya
Emotet
Mworm
Nworm
Eternalblue_vuln
Eternalromance_vuln
Eternalchampion_vuln
Industry:
Financial
01-08-2022
The TrickBot malware
https://www.telsy.com/the-trickbot-malware
Threats:
Trickbot
Ryuk
Dyre
Wannacry
Eternal_petya
Emotet
Mworm
Nworm
Eternalblue_vuln
Eternalromance_vuln
Eternalchampion_vuln
Industry:
Financial
Telsy
The TrickBot malware - Telsy
TrickBot è un trojan bancario che prende di mira aziende e consumatori per i loro dati, capace di adattarsi a qualsiasi ambiente o rete.
#ParsedReport
01-08-2022
Technical Analysis of Industrial SpyRansomware. Industrial Spy Market Promoter
https://www.zscaler.com/blogs/security-research/technical-analysis-industrial-spy-ransomware
Threats:
Spyransomware
Smokeloader
Cloudeye
Redline_stealer
Win32.ransom.industrialspy
Cuba
Gozi
Wastedlocker
Antidebugging_technique
Industry:
E-commerce
IOCs:
Hash: 7
File: 4
Algorithms:
3des, des
Functions:
R_RandomUpdate, R_GenerateBytes
Languages:
python
Platforms:
x86, x64
Links:
01-08-2022
Technical Analysis of Industrial SpyRansomware. Industrial Spy Market Promoter
https://www.zscaler.com/blogs/security-research/technical-analysis-industrial-spy-ransomware
Threats:
Spyransomware
Smokeloader
Cloudeye
Redline_stealer
Win32.ransom.industrialspy
Cuba
Gozi
Wastedlocker
Antidebugging_technique
Industry:
E-commerce
IOCs:
Hash: 7
File: 4
Algorithms:
3des, des
Functions:
R_RandomUpdate, R_GenerateBytes
Languages:
python
Platforms:
x86, x64
Links:
https://github.com/gbrindisi/malware/tree/667b44f64edcd1c5e8c42489b8e767813a589158/windows/gozi-isfbZscaler
Technical Analysis of Industrial Spy Ransomware | Zscaler
Industrial Spy is a relatively new ransomware group that emerged in April 2022. Their primary objective is exfiltrating data to sell on their data leak website.
#ParsedReport
01-08-2022
. Monero Coin Minor Malware, which is being distributed through Webhard
https://asec.ahnlab.com/ko/37333
Threats:
Njrat_rat
Udprat
Xmrig_miner
Trojan/win.fy.c5155016
Xmr_miner
Trojan/win.launcher.c5217400
IOCs:
File: 8
Domain: 1
Coin: 1
Hash: 5
Url: 3
01-08-2022
. Monero Coin Minor Malware, which is being distributed through Webhard
https://asec.ahnlab.com/ko/37333
Threats:
Njrat_rat
Udprat
Xmrig_miner
Trojan/win.fy.c5155016
Xmr_miner
Trojan/win.launcher.c5217400
IOCs:
File: 8
Domain: 1
Coin: 1
Hash: 5
Url: 3
ASEC BLOG
웹하드를 통해 유포 중인 모네로 코인 마이너 악성코드 - ASEC BLOG
웹하드는 국내 사용자를 대상으로 하는 공격자들이 사용하는 대표적인 악성코드 유포 플랫폼이다. ASEC 분석팀에서는 웹하드를 통해 유포되는 악성코드들을 모니터링하고 있으며 과거 다수의 블로그를 통해 정보를 공유한 바 있다. 일반적으로 공격자들은 성인 게임이나 사용 게임의 크랙 버전과 같은 불법 프로그램과 함께 악성코드를 유포한다. 이렇게 웹하드를 유포 경로로 사용하는 공격자들은 주로 njRAT이나 UdpRAT, DDoS IRC Bot과 같은 RAT 유형의…
#ParsedReport
01-08-2022
SEARCH. Threat Actor Targets Financial Entities With Evilnum Malware
https://www.proofpoint.com/us/newsroom/news/threat-actor-targets-financial-entities-evilnum-malware
Actors/Campaigns:
Evilnum (motivation: information_theft)
Ta4563
Venom_spider
Industry:
Financial
IOCs:
File: 3
Softs:
windows defender, microsoft word
01-08-2022
SEARCH. Threat Actor Targets Financial Entities With Evilnum Malware
https://www.proofpoint.com/us/newsroom/news/threat-actor-targets-financial-entities-evilnum-malware
Actors/Campaigns:
Evilnum (motivation: information_theft)
Ta4563
Venom_spider
Industry:
Financial
IOCs:
File: 3
Softs:
windows defender, microsoft word
Decipher
Threat Actor Targets Financial Entities With Evilnum Malware
The threat actor has been observed targeting companies with operations supporting foreign exchanges and cryptocurrency, and organizations in the Decentralized Finance (DeFi) industry.
#ParsedReport
31-07-2022
CUBA Ransomware Campaign Analysis. Key Takeaways
https://www.elastic.co/security-labs/cuba-ransomware-campaign-analysis
Actors/Campaigns:
Unc2596
Threats:
Cuba
Seth_locker
Credential_harvesting_technique
Process_injection_technique
Meterpreter_tool
Mimikatz
Cobalt_strike
Bughatch
Systembc
Proxylogon_exploit
Proxyshell_vuln
Bazarbackdoor
Metasploit_tool
Netsupportmanager_rat
Gotoassist_tool
Beacon
Mosquito
Zerologon_vuln
Psexec_tool
Lolbas_technique
Industry:
Financial, Retail
Geo:
Polish, American
TTPs:
Tactics: 9
Technics: 0
IOCs:
File: 15
IP: 21
Domain: 2
Url: 3
Path: 7
Hash: 14
Softs:
microsoft defender, sysinternals, mysql
YARA: Found
Links:
31-07-2022
CUBA Ransomware Campaign Analysis. Key Takeaways
https://www.elastic.co/security-labs/cuba-ransomware-campaign-analysis
Actors/Campaigns:
Unc2596
Threats:
Cuba
Seth_locker
Credential_harvesting_technique
Process_injection_technique
Meterpreter_tool
Mimikatz
Cobalt_strike
Bughatch
Systembc
Proxylogon_exploit
Proxyshell_vuln
Bazarbackdoor
Metasploit_tool
Netsupportmanager_rat
Gotoassist_tool
Beacon
Mosquito
Zerologon_vuln
Psexec_tool
Lolbas_technique
Industry:
Financial, Retail
Geo:
Polish, American
TTPs:
Tactics: 9
Technics: 0
IOCs:
File: 15
IP: 21
Domain: 2
Url: 3
Path: 7
Hash: 14
Softs:
microsoft defender, sysinternals, mysql
YARA: Found
Links:
https://github.com/rapid7/metasploit-frameworkwww.elastic.co
CUBA Ransomware Campaign Analysis — Elastic Security Labs
Elastic Security observed a ransomware and extortion campaign leveraging a combination of offensive security tools, LOLBAS, and exploits to deliver the CUBA ransomware malware.
#ParsedReport
31-07-2022
QBOT Configuration Extractor. Getting Started
https://www.elastic.co/security-labs/qbot-configuration-extractor
Threats:
Qakbot
Seth_locker
Bpfdoor
IOCs:
File: 1
Softs:
docker
Languages:
python
31-07-2022
QBOT Configuration Extractor. Getting Started
https://www.elastic.co/security-labs/qbot-configuration-extractor
Threats:
Qakbot
Seth_locker
Bpfdoor
IOCs:
File: 1
Softs:
docker
Languages:
python
www.elastic.co
QBOT Configuration Extractor — Elastic Security Labs
Python script to extract the configuration from QBOT samples.
35939836.pdf
9.2 MB
Документ от 2021г.
A review of threat modelling approaches for APT-style attacks
A review of threat modelling approaches for APT-style attacks
#technique
NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs. Whole project is based on the PoC shared by WithSecure Labs
https://github.com/frkngksl/NimicStack
NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs. Whole project is based on the PoC shared by WithSecure Labs
https://github.com/frkngksl/NimicStack
GitHub
GitHub - frkngksl/NimicStack: NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs
NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs - frkngksl/NimicStack
#technique
A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.
https://github.com/janoglezcampos/DeathSleep
A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.
https://github.com/janoglezcampos/DeathSleep
GitHub
GitHub - janoglezcampos/DeathSleep: A PoC implementation for an evasion technique to terminate the current thread and restore it…
A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution. - janoglezcam...
#ParsedReport
02-08-2022
Word File Provided as External Link When Replying to Attackers Email (Kimsuky)
https://asec.ahnlab.com/en/37396
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean, American
IOCs:
File: 5
Url: 3
Path: 1
Hash: 2
02-08-2022
Word File Provided as External Link When Replying to Attackers Email (Kimsuky)
https://asec.ahnlab.com/en/37396
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean, American
IOCs:
File: 5
Url: 3
Path: 1
Hash: 2
ASEC BLOG
Word File Provided as External Link When Replying to Attacker's Email (Kimsuky) - ASEC BLOG
The ASEC analysis team has discovered the continuous distribution of malicious Word files with North Korea-related materials. The types of discovered Word files included the one discussed in the “Overall Organizational Analysis Report of 2021 Kimsuky Attack…
#ParsedReport
02-08-2022
Malicious CHM Being Distributed to Korean Universities
https://asec.ahnlab.com/en/37391
Threats:
Dll_hijacking_technique
Revbshell
Powershell_shell_tool
Trojan/vbs.generic
Industry:
Education
Geo:
Korean, Korea
IOCs:
File: 5
Hash: 3
Domain: 1
02-08-2022
Malicious CHM Being Distributed to Korean Universities
https://asec.ahnlab.com/en/37391
Threats:
Dll_hijacking_technique
Revbshell
Powershell_shell_tool
Trojan/vbs.generic
Industry:
Education
Geo:
Korean, Korea
IOCs:
File: 5
Hash: 3
Domain: 1
ASEC BLOG
Malicious CHM Being Distributed to Korean Universities - ASEC BLOG
The ASEC analysis team discovered that a malicious CHM file targeting certain Korean universities is distributed on a massive scale. The file that is being distributed is the same type as the one discussed in a post uploaded in May. Figure 1 shows the code…
#ParsedReport
02-08-2022
Banking Trojans Distributed on Google Play Store in DawDropper Campaign
https://socradar.io/banking-trojans-distributed-on-google-play-store-in-dawdropper-campaign
Actors/Campaigns:
Dawdropper
Killnet
Threats:
Octo
Hydra
Anatsa
Ermac
Industry:
Financial
IOCs:
Domain: 13
Url: 25
File: 1
Hash: 22
Softs:
confluence
02-08-2022
Banking Trojans Distributed on Google Play Store in DawDropper Campaign
https://socradar.io/banking-trojans-distributed-on-google-play-store-in-dawdropper-campaign
Actors/Campaigns:
Dawdropper
Killnet
Threats:
Octo
Hydra
Anatsa
Ermac
Industry:
Financial
IOCs:
Domain: 13
Url: 25
File: 1
Hash: 22
Softs:
confluence
SOCRadar® Cyber Intelligence Inc.
Banking Trojans Distributed on Google Play Store in DawDropper Campaign - SOCRadar
According to research by Trend Micro, software called DawDropper impersonates trusted apps to gain access to victims' mobile devices.
#ParsedReport
02-08-2022
Large-Scale AiTM Attack targeting enterprise users of Microsoft email services
https://www.zscaler.com/blogs/security-research/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services
Actors/Campaigns:
Bec
Threats:
Aitm_technique
Glitch
Fingerprintjs_tool
Evilginx2_tool
Pinkbot_botnet
Industry:
Financial, Energy
Geo:
Australia
IOCs:
Domain: 646
File: 1
Softs:
virtualbox, active directory
Languages:
javascript
Links:
02-08-2022
Large-Scale AiTM Attack targeting enterprise users of Microsoft email services
https://www.zscaler.com/blogs/security-research/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services
Actors/Campaigns:
Bec
Threats:
Aitm_technique
Glitch
Fingerprintjs_tool
Evilginx2_tool
Pinkbot_botnet
Industry:
Financial, Energy
Geo:
Australia
IOCs:
Domain: 646
File: 1
Softs:
virtualbox, active directory
Languages:
javascript
Links:
https://github.com/fingerprintjs/fingerprintjsZscaler
AITM Attack Targeting Microsoft Email Users | Zscaler
A ThreatLabz technical analysis of the latest variant of proxy-based AiTM attacks that are phishing enterprise users for their Microsoft credentials.
#ParsedReport
02-08-2022
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
https://www.trendmicro.com/en_us/research/22/h/solidbit-ransomware-enters-the-raas-scene-and-takes-aim-at-gamer.html
Threats:
Solidbit
Lockbit
Yashma
Ransom.win32.solidbitcrypt.thgabbb
Trojan.win32.solidbitcrypt.thgadbb
Trojan.win32.solidbitcrypt.thgahbb
IOCs:
File: 19
Path: 1
Hash: 12
Url: 1
Softs:
instagram, windows defender
Algorithms:
aes, exhibit
Platforms:
intel, x86
02-08-2022
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
https://www.trendmicro.com/en_us/research/22/h/solidbit-ransomware-enters-the-raas-scene-and-takes-aim-at-gamer.html
Threats:
Solidbit
Lockbit
Yashma
Ransom.win32.solidbitcrypt.thgabbb
Trojan.win32.solidbitcrypt.thgadbb
Trojan.win32.solidbitcrypt.thgahbb
IOCs:
File: 19
Path: 1
Hash: 12
Url: 1
Softs:
instagram, windows defender
Algorithms:
aes, exhibit
Platforms:
intel, x86
Trend Micro
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
This blog entry offers a technical analysis of a new SolidBit variant that is posing as different applications to lure gamers and social media users. The SolidBit ransomware group appears to be planning to expand its operations through these fraudulent apps…
#ParsedReport
02-08-2022
Fake Atomic Wallet Website Distributing Mars Stealer
https://blog.cyble.com/2022/08/02/fake-atomic-wallet-website-distributing-mars-stealer
Threats:
Mars_stealer
Cashback
Beacon
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 10
IOCs:
Url: 3
File: 3
Hash: 2
Softs:
atomic wallet, coinbase, android, discord
Algorithms:
zip , gzip, aes
02-08-2022
Fake Atomic Wallet Website Distributing Mars Stealer
https://blog.cyble.com/2022/08/02/fake-atomic-wallet-website-distributing-mars-stealer
Threats:
Mars_stealer
Cashback
Beacon
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 10
IOCs:
Url: 3
File: 3
Hash: 2
Softs:
atomic wallet, coinbase, android, discord
Algorithms:
zip , gzip, aes
Cyble
Cyble - Fake Atomic Wallet Website Distributing Mars Stealer
Cyble analyzes a fake Atomic Wallet website that is being used to distribute Mars Stealer to cryptocurrency users.