35939836.pdf
9.2 MB
Документ от 2021г.
A review of threat modelling approaches for APT-style attacks
A review of threat modelling approaches for APT-style attacks
#technique
NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs. Whole project is based on the PoC shared by WithSecure Labs
https://github.com/frkngksl/NimicStack
NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs. Whole project is based on the PoC shared by WithSecure Labs
https://github.com/frkngksl/NimicStack
GitHub
GitHub - frkngksl/NimicStack: NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs
NimicStack is the pure Nim implementation of Call Stack Spoofing technique to mimic legitimate programs - frkngksl/NimicStack
#technique
A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.
https://github.com/janoglezcampos/DeathSleep
A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution.
https://github.com/janoglezcampos/DeathSleep
GitHub
GitHub - janoglezcampos/DeathSleep: A PoC implementation for an evasion technique to terminate the current thread and restore it…
A PoC implementation for an evasion technique to terminate the current thread and restore it before resuming execution, while implementing page protection changes during no execution. - janoglezcam...
#ParsedReport
02-08-2022
Word File Provided as External Link When Replying to Attackers Email (Kimsuky)
https://asec.ahnlab.com/en/37396
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean, American
IOCs:
File: 5
Url: 3
Path: 1
Hash: 2
02-08-2022
Word File Provided as External Link When Replying to Attackers Email (Kimsuky)
https://asec.ahnlab.com/en/37396
Actors/Campaigns:
Kimsuky
Geo:
Korea, Korean, American
IOCs:
File: 5
Url: 3
Path: 1
Hash: 2
ASEC BLOG
Word File Provided as External Link When Replying to Attacker's Email (Kimsuky) - ASEC BLOG
The ASEC analysis team has discovered the continuous distribution of malicious Word files with North Korea-related materials. The types of discovered Word files included the one discussed in the “Overall Organizational Analysis Report of 2021 Kimsuky Attack…
#ParsedReport
02-08-2022
Malicious CHM Being Distributed to Korean Universities
https://asec.ahnlab.com/en/37391
Threats:
Dll_hijacking_technique
Revbshell
Powershell_shell_tool
Trojan/vbs.generic
Industry:
Education
Geo:
Korean, Korea
IOCs:
File: 5
Hash: 3
Domain: 1
02-08-2022
Malicious CHM Being Distributed to Korean Universities
https://asec.ahnlab.com/en/37391
Threats:
Dll_hijacking_technique
Revbshell
Powershell_shell_tool
Trojan/vbs.generic
Industry:
Education
Geo:
Korean, Korea
IOCs:
File: 5
Hash: 3
Domain: 1
ASEC BLOG
Malicious CHM Being Distributed to Korean Universities - ASEC BLOG
The ASEC analysis team discovered that a malicious CHM file targeting certain Korean universities is distributed on a massive scale. The file that is being distributed is the same type as the one discussed in a post uploaded in May. Figure 1 shows the code…
#ParsedReport
02-08-2022
Banking Trojans Distributed on Google Play Store in DawDropper Campaign
https://socradar.io/banking-trojans-distributed-on-google-play-store-in-dawdropper-campaign
Actors/Campaigns:
Dawdropper
Killnet
Threats:
Octo
Hydra
Anatsa
Ermac
Industry:
Financial
IOCs:
Domain: 13
Url: 25
File: 1
Hash: 22
Softs:
confluence
02-08-2022
Banking Trojans Distributed on Google Play Store in DawDropper Campaign
https://socradar.io/banking-trojans-distributed-on-google-play-store-in-dawdropper-campaign
Actors/Campaigns:
Dawdropper
Killnet
Threats:
Octo
Hydra
Anatsa
Ermac
Industry:
Financial
IOCs:
Domain: 13
Url: 25
File: 1
Hash: 22
Softs:
confluence
SOCRadar® Cyber Intelligence Inc.
Banking Trojans Distributed on Google Play Store in DawDropper Campaign - SOCRadar
According to research by Trend Micro, software called DawDropper impersonates trusted apps to gain access to victims' mobile devices.
#ParsedReport
02-08-2022
Large-Scale AiTM Attack targeting enterprise users of Microsoft email services
https://www.zscaler.com/blogs/security-research/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services
Actors/Campaigns:
Bec
Threats:
Aitm_technique
Glitch
Fingerprintjs_tool
Evilginx2_tool
Pinkbot_botnet
Industry:
Financial, Energy
Geo:
Australia
IOCs:
Domain: 646
File: 1
Softs:
virtualbox, active directory
Languages:
javascript
Links:
02-08-2022
Large-Scale AiTM Attack targeting enterprise users of Microsoft email services
https://www.zscaler.com/blogs/security-research/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services
Actors/Campaigns:
Bec
Threats:
Aitm_technique
Glitch
Fingerprintjs_tool
Evilginx2_tool
Pinkbot_botnet
Industry:
Financial, Energy
Geo:
Australia
IOCs:
Domain: 646
File: 1
Softs:
virtualbox, active directory
Languages:
javascript
Links:
https://github.com/fingerprintjs/fingerprintjsZscaler
AITM Attack Targeting Microsoft Email Users | Zscaler
A ThreatLabz technical analysis of the latest variant of proxy-based AiTM attacks that are phishing enterprise users for their Microsoft credentials.
#ParsedReport
02-08-2022
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
https://www.trendmicro.com/en_us/research/22/h/solidbit-ransomware-enters-the-raas-scene-and-takes-aim-at-gamer.html
Threats:
Solidbit
Lockbit
Yashma
Ransom.win32.solidbitcrypt.thgabbb
Trojan.win32.solidbitcrypt.thgadbb
Trojan.win32.solidbitcrypt.thgahbb
IOCs:
File: 19
Path: 1
Hash: 12
Url: 1
Softs:
instagram, windows defender
Algorithms:
aes, exhibit
Platforms:
intel, x86
02-08-2022
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
https://www.trendmicro.com/en_us/research/22/h/solidbit-ransomware-enters-the-raas-scene-and-takes-aim-at-gamer.html
Threats:
Solidbit
Lockbit
Yashma
Ransom.win32.solidbitcrypt.thgabbb
Trojan.win32.solidbitcrypt.thgadbb
Trojan.win32.solidbitcrypt.thgahbb
IOCs:
File: 19
Path: 1
Hash: 12
Url: 1
Softs:
instagram, windows defender
Algorithms:
aes, exhibit
Platforms:
intel, x86
Trend Micro
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
This blog entry offers a technical analysis of a new SolidBit variant that is posing as different applications to lure gamers and social media users. The SolidBit ransomware group appears to be planning to expand its operations through these fraudulent apps…
#ParsedReport
02-08-2022
Fake Atomic Wallet Website Distributing Mars Stealer
https://blog.cyble.com/2022/08/02/fake-atomic-wallet-website-distributing-mars-stealer
Threats:
Mars_stealer
Cashback
Beacon
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 10
IOCs:
Url: 3
File: 3
Hash: 2
Softs:
atomic wallet, coinbase, android, discord
Algorithms:
zip , gzip, aes
02-08-2022
Fake Atomic Wallet Website Distributing Mars Stealer
https://blog.cyble.com/2022/08/02/fake-atomic-wallet-website-distributing-mars-stealer
Threats:
Mars_stealer
Cashback
Beacon
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 10
IOCs:
Url: 3
File: 3
Hash: 2
Softs:
atomic wallet, coinbase, android, discord
Algorithms:
zip , gzip, aes
Cyble
Cyble - Fake Atomic Wallet Website Distributing Mars Stealer
Cyble analyzes a fake Atomic Wallet website that is being used to distribute Mars Stealer to cryptocurrency users.
#ParsedReport
02-08-2022
APTGamaredon
http://blog.nsfocus.net/gamaredon
Actors/Campaigns:
Gamaredon
Industry:
Government, Telco
Geo:
Russian, Ukraine, Russia, Ukrainian
IOCs:
File: 17
Url: 25
Domain: 8
Hash: 70
02-08-2022
APTGamaredon
http://blog.nsfocus.net/gamaredon
Actors/Campaigns:
Gamaredon
Industry:
Government, Telco
Geo:
Russian, Ukraine, Russia, Ukrainian
IOCs:
File: 17
Url: 25
Domain: 8
Hash: 70
#ParsedReport
02-08-2022
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html
Actors/Campaigns:
Ice_fog
Threats:
Cobalt_strike
Sliver_tool
Beacon
Skeleton_operation
Metasploit_tool
Industry:
Education
Geo:
China, Chinese, Tibetan, Guangdong
IOCs:
Url: 8
File: 2
IP: 1
Path: 2
Domain: 1
Hash: 9
Softs:
opera, google chrome, mysql, microsoft edge, chrome, postgresql, vivaldi, microsoft word
Algorithms:
xor, base64
Functions:
RtlCreateUserThread, CreateRemoteThread, CreateThread, SetThreadContext
Languages:
rust, php, golang
Platforms:
x64, x86
Links:
02-08-2022
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html
Actors/Campaigns:
Ice_fog
Threats:
Cobalt_strike
Sliver_tool
Beacon
Skeleton_operation
Metasploit_tool
Industry:
Education
Geo:
China, Chinese, Tibetan, Guangdong
IOCs:
Url: 8
File: 2
IP: 1
Path: 2
Domain: 1
Hash: 9
Softs:
opera, google chrome, mysql, microsoft edge, chrome, postgresql, vivaldi, microsoft word
Algorithms:
xor, base64
Functions:
RtlCreateUserThread, CreateRemoteThread, CreateThread, SetThreadContext
Languages:
rust, php, golang
Platforms:
x64, x86
Links:
https://github.com/BishopFox/sliverhttps://github.com/gobuffalo/packrhttps://github.com/gin-gonic/ginCisco Talos Blog
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
* Cisco Talos recently discovered a new attack framework called "Manjusaka" being used in the wild that has the potential to become prevalent across the threat landscape. This framework is advertised as an imitation of the Cobalt Strike framework.
* The…
* The…
#ParsedReport
02-08-2022
Hackers Opting New Attack Methods After Microsoft Blocked Macros by Default
https://www.proofpoint.com/us/newsroom/news/hackers-opting-new-attack-methods-after-microsoft-blocked-macros-default
Threats:
Emotet
Icedid
Qakbot
Bumblebee
Softs:
microsoft excel, visual basic for applications
02-08-2022
Hackers Opting New Attack Methods After Microsoft Blocked Macros by Default
https://www.proofpoint.com/us/newsroom/news/hackers-opting-new-attack-methods-after-microsoft-blocked-macros-default
Threats:
Emotet
Icedid
Qakbot
Bumblebee
Softs:
microsoft excel, visual basic for applications
#ParsedReport
02-08-2022
ASEC (20220725 \~ 20220731). ASEC Weekly Malware Statistics (20220725 \~ 20220731)
https://asec.ahnlab.com/ko/37351
Threats:
Agent_tesla
Azorult
Redline_stealer
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 36
Domain: 15
Email: 6
IP: 1
Url: 17
Softs:
discord, nsisinstaller
Algorithms:
zip
Languages:
visual_basic
02-08-2022
ASEC (20220725 \~ 20220731). ASEC Weekly Malware Statistics (20220725 \~ 20220731)
https://asec.ahnlab.com/ko/37351
Threats:
Agent_tesla
Azorult
Redline_stealer
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 36
Domain: 15
Email: 6
IP: 1
Url: 17
Softs:
discord, nsisinstaller
Algorithms:
zip
Languages:
visual_basic
ASEC BLOG
ASEC 주간 악성코드 통계 (20220725 ~ 20220731) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 7월 25일 월요일부터 7월 31일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 38.6%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 38.1%, 다운로더 23.3%로 집계되었다. Top 1 – Agent Tesla 인포스틸러 악성코드인 AgentTesla가…
Расценки в Darknet
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-price-cybercriminals-charge-for-stolen-data/
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-price-cybercriminals-charge-for-stolen-data/
Trustwave
The Price Cybercriminals Charge for Stolen Data | Trustwave
For the price of a Starbuck’s Caramel Frappuccino Grande and a cheese Danish, about $8, a cybercriminal can obtain all the information needed to max out a person’s stolen credit card and possibly steal their identity.
#technique
Creating Processes Using System Calls
https://www.coresecurity.com/core-labs/articles/creating-processes-using-system-calls
Creating Processes Using System Calls
https://www.coresecurity.com/core-labs/articles/creating-processes-using-system-calls
#ParsedReport
03-08-2022
Gwisin Ransomware Targeting Korean Companies
https://asec.ahnlab.com/en/37483
Threats:
Gwisin
Magniber
Geo:
Korean
IOCs:
Path: 1
File: 1
Softs:
bcdedit
03-08-2022
Gwisin Ransomware Targeting Korean Companies
https://asec.ahnlab.com/en/37483
Threats:
Gwisin
Magniber
Geo:
Korean
IOCs:
Path: 1
File: 1
Softs:
bcdedit
ASEC
Gwisin Ransomware Targeting Korean Companies - ASEC
Gwisin Ransomware Targeting Korean Companies ASEC
#ParsedReport
03-08-2022
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware. Attack Flow
https://checkmarx.com/blog/large-scale-campaign-created-fake-github-projects-clones-with-fake-commit-added-malware
IOCs:
File: 1
Softs:
curl
Languages:
golang
03-08-2022
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware. Attack Flow
https://checkmarx.com/blog/large-scale-campaign-created-fake-github-projects-clones-with-fake-commit-added-malware
IOCs:
File: 1
Softs:
curl
Languages:
golang
Checkmarx.com
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware
This attack vector is possibly trying to target what users type in search-engines-related code snippets and land into these malicious random GitHub repositories, as discovered by Stephen Lacy when accidentally browsing through one of the infected fake clones.
#ParsedReport
03-08-2022
LOLI Stealer Golang-based InfoStealer spotted in the wild
https://blog.cyble.com/2022/08/03/loli-stealer-golang-based-infostealer-spotted-in-the-wild
Threats:
Loli_stealer
Mars_stealer
Beacon
Industry:
E-commerce
TTPs:
Tactics: 5
Technics: 10
IOCs:
File: 4
Url: 1
Hash: 1
Softs:
steam, telegram, chrome, atomic wallet
Algorithms:
base64, zip
Functions:
BitBlt, wine_get_version, theGetProcAddress, DeleteFileW
Languages:
golang
03-08-2022
LOLI Stealer Golang-based InfoStealer spotted in the wild
https://blog.cyble.com/2022/08/03/loli-stealer-golang-based-infostealer-spotted-in-the-wild
Threats:
Loli_stealer
Mars_stealer
Beacon
Industry:
E-commerce
TTPs:
Tactics: 5
Technics: 10
IOCs:
File: 4
Url: 1
Hash: 1
Softs:
steam, telegram, chrome, atomic wallet
Algorithms:
base64, zip
Functions:
BitBlt, wine_get_version, theGetProcAddress, DeleteFileW
Languages:
golang
Cyble
LOLI Stealer – Golang-based InfoStealer spotted in the wild
Cyble analyzes LOLI Stealer - a Golang-based infostealer in the wild leveraging a Malware as a Service (MaaS) model.
#ParsedReport
03-08-2022
Woody RAT: A new feature-rich malware spotted in the wild
https://blog.malwarebytes.com/threat-intelligence/2022/08/woody-rat-a-new-feature-rich-malware-spotted-in-the-wild
Actors/Campaigns:
Tonto_team
Threats:
Woody_rat
Follina_vuln
Process_injection_technique
Process_hollowing_technique
Konni
Industry:
Aerospace
Geo:
Russia, Russian, Korea, Chinese
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Hash: 10
Domain: 4
Softs:
windows gdi+, powersession, microsoft office
Algorithms:
base64, aes-cbc, aes, zip , rsa-4096
Functions:
CreateProcess, SetErrorMode, ReadFile, NtWriteVirtualMemory, GetComputerNameA, WriteProcessMemory, CreateRemoteThread, GetVolumeInformationW, NtQuerySystemInformation, NtSetContextThread, GetAdaptersInfo
Languages:
python, csharp
Links:
03-08-2022
Woody RAT: A new feature-rich malware spotted in the wild
https://blog.malwarebytes.com/threat-intelligence/2022/08/woody-rat-a-new-feature-rich-malware-spotted-in-the-wild
Actors/Campaigns:
Tonto_team
Threats:
Woody_rat
Follina_vuln
Process_injection_technique
Process_hollowing_technique
Konni
Industry:
Aerospace
Geo:
Russia, Russian, Korea, Chinese
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Hash: 10
Domain: 4
Softs:
windows gdi+, powersession, microsoft office
Algorithms:
base64, aes-cbc, aes, zip , rsa-4096
Functions:
CreateProcess, SetErrorMode, ReadFile, NtWriteVirtualMemory, GetComputerNameA, WriteProcessMemory, CreateRemoteThread, GetVolumeInformationW, NtQuerySystemInformation, NtSetContextThread, GetAdaptersInfo
Languages:
python, csharp
Links:
https://gist.github.com/kernelm0de/fd018d58ebe78f603a13b2eba7f01917ThreatDown by Malwarebytes
Woody RAT: A new feature-rich malware spotted in the wild - ThreatDown by Malwarebytes
This blog post was authored by Ankur Saini and Hossein Jazi The Malwarebytes Threat Intelligence team has identified a new Remote Access Trojan we are calling Woody Rat that has been in the wild for…
#ParsedReport
04-08-2022
Army of the Undone: Securing IoT Across Critical Sectors
https://www.nozominetworks.com/blog/army-of-the-undone-securing-iot-across-critical-sectors
Threats:
Quantum_tool
Industry:
Healthcare, Financial, Energy, Iot, Ics, Government
Languages:
java
Platforms:
arm
04-08-2022
Army of the Undone: Securing IoT Across Critical Sectors
https://www.nozominetworks.com/blog/army-of-the-undone-securing-iot-across-critical-sectors
Threats:
Quantum_tool
Industry:
Healthcare, Financial, Energy, Iot, Ics, Government
Languages:
java
Platforms:
arm
Nozomi Networks
Army of the Undone: Securing IoT Across Critical Sectors
To avoid hivemind thinking that IoT devices are secure by design and/or have security features enabled by default, compensating controls should map to the key challenges with IoT security today