#ParsedReport
02-08-2022
Malicious CHM Being Distributed to Korean Universities
https://asec.ahnlab.com/en/37391
Threats:
Dll_hijacking_technique
Revbshell
Powershell_shell_tool
Trojan/vbs.generic
Industry:
Education
Geo:
Korean, Korea
IOCs:
File: 5
Hash: 3
Domain: 1
02-08-2022
Malicious CHM Being Distributed to Korean Universities
https://asec.ahnlab.com/en/37391
Threats:
Dll_hijacking_technique
Revbshell
Powershell_shell_tool
Trojan/vbs.generic
Industry:
Education
Geo:
Korean, Korea
IOCs:
File: 5
Hash: 3
Domain: 1
ASEC BLOG
Malicious CHM Being Distributed to Korean Universities - ASEC BLOG
The ASEC analysis team discovered that a malicious CHM file targeting certain Korean universities is distributed on a massive scale. The file that is being distributed is the same type as the one discussed in a post uploaded in May. Figure 1 shows the code…
#ParsedReport
02-08-2022
Banking Trojans Distributed on Google Play Store in DawDropper Campaign
https://socradar.io/banking-trojans-distributed-on-google-play-store-in-dawdropper-campaign
Actors/Campaigns:
Dawdropper
Killnet
Threats:
Octo
Hydra
Anatsa
Ermac
Industry:
Financial
IOCs:
Domain: 13
Url: 25
File: 1
Hash: 22
Softs:
confluence
02-08-2022
Banking Trojans Distributed on Google Play Store in DawDropper Campaign
https://socradar.io/banking-trojans-distributed-on-google-play-store-in-dawdropper-campaign
Actors/Campaigns:
Dawdropper
Killnet
Threats:
Octo
Hydra
Anatsa
Ermac
Industry:
Financial
IOCs:
Domain: 13
Url: 25
File: 1
Hash: 22
Softs:
confluence
SOCRadar® Cyber Intelligence Inc.
Banking Trojans Distributed on Google Play Store in DawDropper Campaign - SOCRadar
According to research by Trend Micro, software called DawDropper impersonates trusted apps to gain access to victims' mobile devices.
#ParsedReport
02-08-2022
Large-Scale AiTM Attack targeting enterprise users of Microsoft email services
https://www.zscaler.com/blogs/security-research/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services
Actors/Campaigns:
Bec
Threats:
Aitm_technique
Glitch
Fingerprintjs_tool
Evilginx2_tool
Pinkbot_botnet
Industry:
Financial, Energy
Geo:
Australia
IOCs:
Domain: 646
File: 1
Softs:
virtualbox, active directory
Languages:
javascript
Links:
02-08-2022
Large-Scale AiTM Attack targeting enterprise users of Microsoft email services
https://www.zscaler.com/blogs/security-research/large-scale-aitm-attack-targeting-enterprise-users-microsoft-email-services
Actors/Campaigns:
Bec
Threats:
Aitm_technique
Glitch
Fingerprintjs_tool
Evilginx2_tool
Pinkbot_botnet
Industry:
Financial, Energy
Geo:
Australia
IOCs:
Domain: 646
File: 1
Softs:
virtualbox, active directory
Languages:
javascript
Links:
https://github.com/fingerprintjs/fingerprintjsZscaler
AITM Attack Targeting Microsoft Email Users | Zscaler
A ThreatLabz technical analysis of the latest variant of proxy-based AiTM attacks that are phishing enterprise users for their Microsoft credentials.
#ParsedReport
02-08-2022
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
https://www.trendmicro.com/en_us/research/22/h/solidbit-ransomware-enters-the-raas-scene-and-takes-aim-at-gamer.html
Threats:
Solidbit
Lockbit
Yashma
Ransom.win32.solidbitcrypt.thgabbb
Trojan.win32.solidbitcrypt.thgadbb
Trojan.win32.solidbitcrypt.thgahbb
IOCs:
File: 19
Path: 1
Hash: 12
Url: 1
Softs:
instagram, windows defender
Algorithms:
aes, exhibit
Platforms:
intel, x86
02-08-2022
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
https://www.trendmicro.com/en_us/research/22/h/solidbit-ransomware-enters-the-raas-scene-and-takes-aim-at-gamer.html
Threats:
Solidbit
Lockbit
Yashma
Ransom.win32.solidbitcrypt.thgabbb
Trojan.win32.solidbitcrypt.thgadbb
Trojan.win32.solidbitcrypt.thgahbb
IOCs:
File: 19
Path: 1
Hash: 12
Url: 1
Softs:
instagram, windows defender
Algorithms:
aes, exhibit
Platforms:
intel, x86
Trend Micro
SolidBit Ransomware Enters the RaaS Scene and Takes Aim at Gamers and Social Media Users With New Variant
This blog entry offers a technical analysis of a new SolidBit variant that is posing as different applications to lure gamers and social media users. The SolidBit ransomware group appears to be planning to expand its operations through these fraudulent apps…
#ParsedReport
02-08-2022
Fake Atomic Wallet Website Distributing Mars Stealer
https://blog.cyble.com/2022/08/02/fake-atomic-wallet-website-distributing-mars-stealer
Threats:
Mars_stealer
Cashback
Beacon
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 10
IOCs:
Url: 3
File: 3
Hash: 2
Softs:
atomic wallet, coinbase, android, discord
Algorithms:
zip , gzip, aes
02-08-2022
Fake Atomic Wallet Website Distributing Mars Stealer
https://blog.cyble.com/2022/08/02/fake-atomic-wallet-website-distributing-mars-stealer
Threats:
Mars_stealer
Cashback
Beacon
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 10
IOCs:
Url: 3
File: 3
Hash: 2
Softs:
atomic wallet, coinbase, android, discord
Algorithms:
zip , gzip, aes
Cyble
Cyble - Fake Atomic Wallet Website Distributing Mars Stealer
Cyble analyzes a fake Atomic Wallet website that is being used to distribute Mars Stealer to cryptocurrency users.
#ParsedReport
02-08-2022
APTGamaredon
http://blog.nsfocus.net/gamaredon
Actors/Campaigns:
Gamaredon
Industry:
Government, Telco
Geo:
Russian, Ukraine, Russia, Ukrainian
IOCs:
File: 17
Url: 25
Domain: 8
Hash: 70
02-08-2022
APTGamaredon
http://blog.nsfocus.net/gamaredon
Actors/Campaigns:
Gamaredon
Industry:
Government, Telco
Geo:
Russian, Ukraine, Russia, Ukrainian
IOCs:
File: 17
Url: 25
Domain: 8
Hash: 70
#ParsedReport
02-08-2022
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html
Actors/Campaigns:
Ice_fog
Threats:
Cobalt_strike
Sliver_tool
Beacon
Skeleton_operation
Metasploit_tool
Industry:
Education
Geo:
China, Chinese, Tibetan, Guangdong
IOCs:
Url: 8
File: 2
IP: 1
Path: 2
Domain: 1
Hash: 9
Softs:
opera, google chrome, mysql, microsoft edge, chrome, postgresql, vivaldi, microsoft word
Algorithms:
xor, base64
Functions:
RtlCreateUserThread, CreateRemoteThread, CreateThread, SetThreadContext
Languages:
rust, php, golang
Platforms:
x64, x86
Links:
02-08-2022
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
https://blog.talosintelligence.com/2022/08/manjusaka-offensive-framework.html
Actors/Campaigns:
Ice_fog
Threats:
Cobalt_strike
Sliver_tool
Beacon
Skeleton_operation
Metasploit_tool
Industry:
Education
Geo:
China, Chinese, Tibetan, Guangdong
IOCs:
Url: 8
File: 2
IP: 1
Path: 2
Domain: 1
Hash: 9
Softs:
opera, google chrome, mysql, microsoft edge, chrome, postgresql, vivaldi, microsoft word
Algorithms:
xor, base64
Functions:
RtlCreateUserThread, CreateRemoteThread, CreateThread, SetThreadContext
Languages:
rust, php, golang
Platforms:
x64, x86
Links:
https://github.com/BishopFox/sliverhttps://github.com/gobuffalo/packrhttps://github.com/gin-gonic/ginCisco Talos Blog
Manjusaka: A Chinese sibling of Sliver and Cobalt Strike
* Cisco Talos recently discovered a new attack framework called "Manjusaka" being used in the wild that has the potential to become prevalent across the threat landscape. This framework is advertised as an imitation of the Cobalt Strike framework.
* The…
* The…
#ParsedReport
02-08-2022
Hackers Opting New Attack Methods After Microsoft Blocked Macros by Default
https://www.proofpoint.com/us/newsroom/news/hackers-opting-new-attack-methods-after-microsoft-blocked-macros-default
Threats:
Emotet
Icedid
Qakbot
Bumblebee
Softs:
microsoft excel, visual basic for applications
02-08-2022
Hackers Opting New Attack Methods After Microsoft Blocked Macros by Default
https://www.proofpoint.com/us/newsroom/news/hackers-opting-new-attack-methods-after-microsoft-blocked-macros-default
Threats:
Emotet
Icedid
Qakbot
Bumblebee
Softs:
microsoft excel, visual basic for applications
#ParsedReport
02-08-2022
ASEC (20220725 \~ 20220731). ASEC Weekly Malware Statistics (20220725 \~ 20220731)
https://asec.ahnlab.com/ko/37351
Threats:
Agent_tesla
Azorult
Redline_stealer
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 36
Domain: 15
Email: 6
IP: 1
Url: 17
Softs:
discord, nsisinstaller
Algorithms:
zip
Languages:
visual_basic
02-08-2022
ASEC (20220725 \~ 20220731). ASEC Weekly Malware Statistics (20220725 \~ 20220731)
https://asec.ahnlab.com/ko/37351
Threats:
Agent_tesla
Azorult
Redline_stealer
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 36
Domain: 15
Email: 6
IP: 1
Url: 17
Softs:
discord, nsisinstaller
Algorithms:
zip
Languages:
visual_basic
ASEC BLOG
ASEC 주간 악성코드 통계 (20220725 ~ 20220731) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 7월 25일 월요일부터 7월 31일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 38.6%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 38.1%, 다운로더 23.3%로 집계되었다. Top 1 – Agent Tesla 인포스틸러 악성코드인 AgentTesla가…
Расценки в Darknet
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-price-cybercriminals-charge-for-stolen-data/
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-price-cybercriminals-charge-for-stolen-data/
Trustwave
The Price Cybercriminals Charge for Stolen Data | Trustwave
For the price of a Starbuck’s Caramel Frappuccino Grande and a cheese Danish, about $8, a cybercriminal can obtain all the information needed to max out a person’s stolen credit card and possibly steal their identity.
#technique
Creating Processes Using System Calls
https://www.coresecurity.com/core-labs/articles/creating-processes-using-system-calls
Creating Processes Using System Calls
https://www.coresecurity.com/core-labs/articles/creating-processes-using-system-calls
#ParsedReport
03-08-2022
Gwisin Ransomware Targeting Korean Companies
https://asec.ahnlab.com/en/37483
Threats:
Gwisin
Magniber
Geo:
Korean
IOCs:
Path: 1
File: 1
Softs:
bcdedit
03-08-2022
Gwisin Ransomware Targeting Korean Companies
https://asec.ahnlab.com/en/37483
Threats:
Gwisin
Magniber
Geo:
Korean
IOCs:
Path: 1
File: 1
Softs:
bcdedit
ASEC
Gwisin Ransomware Targeting Korean Companies - ASEC
Gwisin Ransomware Targeting Korean Companies ASEC
#ParsedReport
03-08-2022
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware. Attack Flow
https://checkmarx.com/blog/large-scale-campaign-created-fake-github-projects-clones-with-fake-commit-added-malware
IOCs:
File: 1
Softs:
curl
Languages:
golang
03-08-2022
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware. Attack Flow
https://checkmarx.com/blog/large-scale-campaign-created-fake-github-projects-clones-with-fake-commit-added-malware
IOCs:
File: 1
Softs:
curl
Languages:
golang
Checkmarx.com
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware
This attack vector is possibly trying to target what users type in search-engines-related code snippets and land into these malicious random GitHub repositories, as discovered by Stephen Lacy when accidentally browsing through one of the infected fake clones.
#ParsedReport
03-08-2022
LOLI Stealer Golang-based InfoStealer spotted in the wild
https://blog.cyble.com/2022/08/03/loli-stealer-golang-based-infostealer-spotted-in-the-wild
Threats:
Loli_stealer
Mars_stealer
Beacon
Industry:
E-commerce
TTPs:
Tactics: 5
Technics: 10
IOCs:
File: 4
Url: 1
Hash: 1
Softs:
steam, telegram, chrome, atomic wallet
Algorithms:
base64, zip
Functions:
BitBlt, wine_get_version, theGetProcAddress, DeleteFileW
Languages:
golang
03-08-2022
LOLI Stealer Golang-based InfoStealer spotted in the wild
https://blog.cyble.com/2022/08/03/loli-stealer-golang-based-infostealer-spotted-in-the-wild
Threats:
Loli_stealer
Mars_stealer
Beacon
Industry:
E-commerce
TTPs:
Tactics: 5
Technics: 10
IOCs:
File: 4
Url: 1
Hash: 1
Softs:
steam, telegram, chrome, atomic wallet
Algorithms:
base64, zip
Functions:
BitBlt, wine_get_version, theGetProcAddress, DeleteFileW
Languages:
golang
Cyble
LOLI Stealer – Golang-based InfoStealer spotted in the wild
Cyble analyzes LOLI Stealer - a Golang-based infostealer in the wild leveraging a Malware as a Service (MaaS) model.
#ParsedReport
03-08-2022
Woody RAT: A new feature-rich malware spotted in the wild
https://blog.malwarebytes.com/threat-intelligence/2022/08/woody-rat-a-new-feature-rich-malware-spotted-in-the-wild
Actors/Campaigns:
Tonto_team
Threats:
Woody_rat
Follina_vuln
Process_injection_technique
Process_hollowing_technique
Konni
Industry:
Aerospace
Geo:
Russia, Russian, Korea, Chinese
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Hash: 10
Domain: 4
Softs:
windows gdi+, powersession, microsoft office
Algorithms:
base64, aes-cbc, aes, zip , rsa-4096
Functions:
CreateProcess, SetErrorMode, ReadFile, NtWriteVirtualMemory, GetComputerNameA, WriteProcessMemory, CreateRemoteThread, GetVolumeInformationW, NtQuerySystemInformation, NtSetContextThread, GetAdaptersInfo
Languages:
python, csharp
Links:
03-08-2022
Woody RAT: A new feature-rich malware spotted in the wild
https://blog.malwarebytes.com/threat-intelligence/2022/08/woody-rat-a-new-feature-rich-malware-spotted-in-the-wild
Actors/Campaigns:
Tonto_team
Threats:
Woody_rat
Follina_vuln
Process_injection_technique
Process_hollowing_technique
Konni
Industry:
Aerospace
Geo:
Russia, Russian, Korea, Chinese
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Hash: 10
Domain: 4
Softs:
windows gdi+, powersession, microsoft office
Algorithms:
base64, aes-cbc, aes, zip , rsa-4096
Functions:
CreateProcess, SetErrorMode, ReadFile, NtWriteVirtualMemory, GetComputerNameA, WriteProcessMemory, CreateRemoteThread, GetVolumeInformationW, NtQuerySystemInformation, NtSetContextThread, GetAdaptersInfo
Languages:
python, csharp
Links:
https://gist.github.com/kernelm0de/fd018d58ebe78f603a13b2eba7f01917ThreatDown by Malwarebytes
Woody RAT: A new feature-rich malware spotted in the wild - ThreatDown by Malwarebytes
This blog post was authored by Ankur Saini and Hossein Jazi The Malwarebytes Threat Intelligence team has identified a new Remote Access Trojan we are calling Woody Rat that has been in the wild for…
#ParsedReport
04-08-2022
Army of the Undone: Securing IoT Across Critical Sectors
https://www.nozominetworks.com/blog/army-of-the-undone-securing-iot-across-critical-sectors
Threats:
Quantum_tool
Industry:
Healthcare, Financial, Energy, Iot, Ics, Government
Languages:
java
Platforms:
arm
04-08-2022
Army of the Undone: Securing IoT Across Critical Sectors
https://www.nozominetworks.com/blog/army-of-the-undone-securing-iot-across-critical-sectors
Threats:
Quantum_tool
Industry:
Healthcare, Financial, Energy, Iot, Ics, Government
Languages:
java
Platforms:
arm
Nozomi Networks
Army of the Undone: Securing IoT Across Critical Sectors
To avoid hivemind thinking that IoT devices are secure by design and/or have security features enabled by default, compensating controls should map to the key challenges with IoT security today
#ParsedReport
04-08-2022
IcedID leverages PrivateLoader. SmokeLoader Tasks
https://medium.com/walmartglobaltech/icedid-leverages-privateloader-7744771bf87f
Threats:
Icedid
Privateloader
Smokeloader
Stop
Redline_stealer
Raccoon_stealer
Trickbot
Qakbot
Danabot
Dridex
Industry:
Financial
IOCs:
Hash: 2
Domain: 1
File: 7
Email: 2
IP: 4
Languages:
php
Platforms:
x86, intel
04-08-2022
IcedID leverages PrivateLoader. SmokeLoader Tasks
https://medium.com/walmartglobaltech/icedid-leverages-privateloader-7744771bf87f
Threats:
Icedid
Privateloader
Smokeloader
Stop
Redline_stealer
Raccoon_stealer
Trickbot
Qakbot
Danabot
Dridex
Industry:
Financial
IOCs:
Hash: 2
Domain: 1
File: 7
Email: 2
IP: 4
Languages:
php
Platforms:
x86, intel
Medium
IcedID leverages PrivateLoader
By: Joshua Platt and Jason Reaves
#ParsedReport
04-08-2022
: APT31 ,. Flying in the "clouds": APT31 again uses the cloud storage, attacking Russian companies
https://www.ptsecurity.com/ru-ru/research/pt-esc-threat-intelligence/apt31-cloud-attacks
Actors/Campaigns:
Apt31
Taskmasters
Naikon
Threats:
Yarat
Vmprotect_tool
Dllsideloading_technique
Dll_hijacking_technique
Industry:
Energy, Petroleum
Geo:
Russian, Russia
TTPs:
Tactics: 8
Technics: 19
IOCs:
File: 21
Hash: 15
Softs:
curl, windows registry
Algorithms:
rc4, base64
Functions:
GETADAPTERSInfo
Languages:
java
YARA: Found
Links:
04-08-2022
: APT31 ,. Flying in the "clouds": APT31 again uses the cloud storage, attacking Russian companies
https://www.ptsecurity.com/ru-ru/research/pt-esc-threat-intelligence/apt31-cloud-attacks
Actors/Campaigns:
Apt31
Taskmasters
Naikon
Threats:
Yarat
Vmprotect_tool
Dllsideloading_technique
Dll_hijacking_technique
Industry:
Energy, Petroleum
Geo:
Russian, Russia
TTPs:
Tactics: 8
Technics: 19
IOCs:
File: 21
Hash: 15
Softs:
curl, windows registry
Algorithms:
rc4, base64
Functions:
GETADAPTERSInfo
Languages:
java
YARA: Found
Links:
https://github.com/nlohmann/jsonptsecurity.com
Блог PT ESC Threat Intelligence
В этом блоге вы можете найти информацию об актуальных атаках хакерских группировок по всему миру, разбор их инструментов, информацию об инцидентах, TTP группировок, индикаторы компрометации и названия детектов в наших продуктах
#ParsedReport
04-08-2022
So RapperBot, What Ya Bruting For?
https://www.fortinet.com/blog/threat-research/rapperbot-malware-discovery
Actors/Campaigns:
Keksec
Threats:
Rapperbot
Mirai
Bashlite
Industry:
Iot
Geo:
Taiwan, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 21
Hash: 26
IP: 4
Softs:
curl
Algorithms:
xor
Platforms:
arm, x86
04-08-2022
So RapperBot, What Ya Bruting For?
https://www.fortinet.com/blog/threat-research/rapperbot-malware-discovery
Actors/Campaigns:
Keksec
Threats:
Rapperbot
Mirai
Bashlite
Industry:
Iot
Geo:
Taiwan, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 21
Hash: 26
IP: 4
Softs:
curl
Algorithms:
xor
Platforms:
arm, x86
Fortinet Blog
So RapperBot, What Ya Bruting For?
FortiGuard Labs is tracking a rapidly evolving IoT malware family known as RapperBot. Read to learn how this threat infects and persists on a victim’s device.…
#ParsedReport
04-08-2022
Stegomalware Identifying possible attack vectors
https://blog.cyble.com/2022/08/04/stegomalware-identifying-possible-attack-vectors
Actors/Campaigns:
Knotweed
Threats:
Loli_stealer
Mimikatz
Rubeus_tool
Nanocore_rat
Agent_tesla
Formbook
Corelump
Beacon
Industry:
Ics
TTPs:
Tactics: 2
Technics: 5
IOCs:
File: 1
Languages:
golang
04-08-2022
Stegomalware Identifying possible attack vectors
https://blog.cyble.com/2022/08/04/stegomalware-identifying-possible-attack-vectors
Actors/Campaigns:
Knotweed
Threats:
Loli_stealer
Mimikatz
Rubeus_tool
Nanocore_rat
Agent_tesla
Formbook
Corelump
Beacon
Industry:
Ics
TTPs:
Tactics: 2
Technics: 5
IOCs:
File: 1
Languages:
golang
Cyble
Cyble - Stegomalware - Identifying Possible Attack Vectors
Cyble Research Labs analyzes the rise of Stegomalware and the reason behind it's popularity through careful testing.
👍1
#ParsedReport
04-08-2022
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware
https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra
Actors/Campaigns:
Projector_libra
Exotic_lily
Shathak
Ta578
Threats:
Bumblebee
Cobalt_strike
Conti
Bazarbackdoor
Trickbot
Icedid
Diavol
Industry:
Petroleum
Geo:
Japan, Emea, Apac, America
IOCs:
File: 4
Path: 2
IP: 2
Domain: 1
Hash: 6
Url: 1
Softs:
active directory
Algorithms:
zip
04-08-2022
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware
https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra
Actors/Campaigns:
Projector_libra
Exotic_lily
Shathak
Ta578
Threats:
Bumblebee
Cobalt_strike
Conti
Bazarbackdoor
Trickbot
Icedid
Diavol
Industry:
Petroleum
Geo:
Japan, Emea, Apac, America
IOCs:
File: 4
Path: 2
IP: 2
Domain: 1
Hash: 6
Url: 1
Softs:
active directory
Algorithms:
zip
Unit 42
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware
We provide a case study of how the criminal group Projector Libra uses legitimate file sharing services to distribute Bumblebee malware.