#ParsedReport
02-08-2022
ASEC (20220725 \~ 20220731). ASEC Weekly Malware Statistics (20220725 \~ 20220731)
https://asec.ahnlab.com/ko/37351
Threats:
Agent_tesla
Azorult
Redline_stealer
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 36
Domain: 15
Email: 6
IP: 1
Url: 17
Softs:
discord, nsisinstaller
Algorithms:
zip
Languages:
visual_basic
02-08-2022
ASEC (20220725 \~ 20220731). ASEC Weekly Malware Statistics (20220725 \~ 20220731)
https://asec.ahnlab.com/ko/37351
Threats:
Agent_tesla
Azorult
Redline_stealer
Cloudeye
Formbook
Remcos_rat
Nanocore_rat
Smokeloader
Clipboard_grabbing_technique
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 36
Domain: 15
Email: 6
IP: 1
Url: 17
Softs:
discord, nsisinstaller
Algorithms:
zip
Languages:
visual_basic
ASEC BLOG
ASEC 주간 악성코드 통계 (20220725 ~ 20220731) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 7월 25일 월요일부터 7월 31일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 38.6%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 38.1%, 다운로더 23.3%로 집계되었다. Top 1 – Agent Tesla 인포스틸러 악성코드인 AgentTesla가…
Расценки в Darknet
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-price-cybercriminals-charge-for-stolen-data/
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-price-cybercriminals-charge-for-stolen-data/
Trustwave
The Price Cybercriminals Charge for Stolen Data | Trustwave
For the price of a Starbuck’s Caramel Frappuccino Grande and a cheese Danish, about $8, a cybercriminal can obtain all the information needed to max out a person’s stolen credit card and possibly steal their identity.
#technique
Creating Processes Using System Calls
https://www.coresecurity.com/core-labs/articles/creating-processes-using-system-calls
Creating Processes Using System Calls
https://www.coresecurity.com/core-labs/articles/creating-processes-using-system-calls
#ParsedReport
03-08-2022
Gwisin Ransomware Targeting Korean Companies
https://asec.ahnlab.com/en/37483
Threats:
Gwisin
Magniber
Geo:
Korean
IOCs:
Path: 1
File: 1
Softs:
bcdedit
03-08-2022
Gwisin Ransomware Targeting Korean Companies
https://asec.ahnlab.com/en/37483
Threats:
Gwisin
Magniber
Geo:
Korean
IOCs:
Path: 1
File: 1
Softs:
bcdedit
ASEC
Gwisin Ransomware Targeting Korean Companies - ASEC
Gwisin Ransomware Targeting Korean Companies ASEC
#ParsedReport
03-08-2022
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware. Attack Flow
https://checkmarx.com/blog/large-scale-campaign-created-fake-github-projects-clones-with-fake-commit-added-malware
IOCs:
File: 1
Softs:
curl
Languages:
golang
03-08-2022
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware. Attack Flow
https://checkmarx.com/blog/large-scale-campaign-created-fake-github-projects-clones-with-fake-commit-added-malware
IOCs:
File: 1
Softs:
curl
Languages:
golang
Checkmarx.com
Large Scale Campaign Created Fake GitHub Projects Clones with Fake Commit Added Malware
This attack vector is possibly trying to target what users type in search-engines-related code snippets and land into these malicious random GitHub repositories, as discovered by Stephen Lacy when accidentally browsing through one of the infected fake clones.
#ParsedReport
03-08-2022
LOLI Stealer Golang-based InfoStealer spotted in the wild
https://blog.cyble.com/2022/08/03/loli-stealer-golang-based-infostealer-spotted-in-the-wild
Threats:
Loli_stealer
Mars_stealer
Beacon
Industry:
E-commerce
TTPs:
Tactics: 5
Technics: 10
IOCs:
File: 4
Url: 1
Hash: 1
Softs:
steam, telegram, chrome, atomic wallet
Algorithms:
base64, zip
Functions:
BitBlt, wine_get_version, theGetProcAddress, DeleteFileW
Languages:
golang
03-08-2022
LOLI Stealer Golang-based InfoStealer spotted in the wild
https://blog.cyble.com/2022/08/03/loli-stealer-golang-based-infostealer-spotted-in-the-wild
Threats:
Loli_stealer
Mars_stealer
Beacon
Industry:
E-commerce
TTPs:
Tactics: 5
Technics: 10
IOCs:
File: 4
Url: 1
Hash: 1
Softs:
steam, telegram, chrome, atomic wallet
Algorithms:
base64, zip
Functions:
BitBlt, wine_get_version, theGetProcAddress, DeleteFileW
Languages:
golang
Cyble
LOLI Stealer – Golang-based InfoStealer spotted in the wild
Cyble analyzes LOLI Stealer - a Golang-based infostealer in the wild leveraging a Malware as a Service (MaaS) model.
#ParsedReport
03-08-2022
Woody RAT: A new feature-rich malware spotted in the wild
https://blog.malwarebytes.com/threat-intelligence/2022/08/woody-rat-a-new-feature-rich-malware-spotted-in-the-wild
Actors/Campaigns:
Tonto_team
Threats:
Woody_rat
Follina_vuln
Process_injection_technique
Process_hollowing_technique
Konni
Industry:
Aerospace
Geo:
Russia, Russian, Korea, Chinese
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Hash: 10
Domain: 4
Softs:
windows gdi+, powersession, microsoft office
Algorithms:
base64, aes-cbc, aes, zip , rsa-4096
Functions:
CreateProcess, SetErrorMode, ReadFile, NtWriteVirtualMemory, GetComputerNameA, WriteProcessMemory, CreateRemoteThread, GetVolumeInformationW, NtQuerySystemInformation, NtSetContextThread, GetAdaptersInfo
Languages:
python, csharp
Links:
03-08-2022
Woody RAT: A new feature-rich malware spotted in the wild
https://blog.malwarebytes.com/threat-intelligence/2022/08/woody-rat-a-new-feature-rich-malware-spotted-in-the-wild
Actors/Campaigns:
Tonto_team
Threats:
Woody_rat
Follina_vuln
Process_injection_technique
Process_hollowing_technique
Konni
Industry:
Aerospace
Geo:
Russia, Russian, Korea, Chinese
CVEs:
CVE-2022-30190 [Vulners]
Vulners: Score: 9.3, CVSS: PENDING,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2012 (r2, -)
- microsoft windows 10 (1607, -, 1809, 20h2, 21h1, 21h2)
- microsoft windows 8.1 (-)
- microsoft windows server 2016 (-)
- microsoft windows server 2008 (-, r2)
have more...
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 5
Hash: 10
Domain: 4
Softs:
windows gdi+, powersession, microsoft office
Algorithms:
base64, aes-cbc, aes, zip , rsa-4096
Functions:
CreateProcess, SetErrorMode, ReadFile, NtWriteVirtualMemory, GetComputerNameA, WriteProcessMemory, CreateRemoteThread, GetVolumeInformationW, NtQuerySystemInformation, NtSetContextThread, GetAdaptersInfo
Languages:
python, csharp
Links:
https://gist.github.com/kernelm0de/fd018d58ebe78f603a13b2eba7f01917ThreatDown by Malwarebytes
Woody RAT: A new feature-rich malware spotted in the wild - ThreatDown by Malwarebytes
This blog post was authored by Ankur Saini and Hossein Jazi The Malwarebytes Threat Intelligence team has identified a new Remote Access Trojan we are calling Woody Rat that has been in the wild for…
#ParsedReport
04-08-2022
Army of the Undone: Securing IoT Across Critical Sectors
https://www.nozominetworks.com/blog/army-of-the-undone-securing-iot-across-critical-sectors
Threats:
Quantum_tool
Industry:
Healthcare, Financial, Energy, Iot, Ics, Government
Languages:
java
Platforms:
arm
04-08-2022
Army of the Undone: Securing IoT Across Critical Sectors
https://www.nozominetworks.com/blog/army-of-the-undone-securing-iot-across-critical-sectors
Threats:
Quantum_tool
Industry:
Healthcare, Financial, Energy, Iot, Ics, Government
Languages:
java
Platforms:
arm
Nozomi Networks
Army of the Undone: Securing IoT Across Critical Sectors
To avoid hivemind thinking that IoT devices are secure by design and/or have security features enabled by default, compensating controls should map to the key challenges with IoT security today
#ParsedReport
04-08-2022
IcedID leverages PrivateLoader. SmokeLoader Tasks
https://medium.com/walmartglobaltech/icedid-leverages-privateloader-7744771bf87f
Threats:
Icedid
Privateloader
Smokeloader
Stop
Redline_stealer
Raccoon_stealer
Trickbot
Qakbot
Danabot
Dridex
Industry:
Financial
IOCs:
Hash: 2
Domain: 1
File: 7
Email: 2
IP: 4
Languages:
php
Platforms:
x86, intel
04-08-2022
IcedID leverages PrivateLoader. SmokeLoader Tasks
https://medium.com/walmartglobaltech/icedid-leverages-privateloader-7744771bf87f
Threats:
Icedid
Privateloader
Smokeloader
Stop
Redline_stealer
Raccoon_stealer
Trickbot
Qakbot
Danabot
Dridex
Industry:
Financial
IOCs:
Hash: 2
Domain: 1
File: 7
Email: 2
IP: 4
Languages:
php
Platforms:
x86, intel
Medium
IcedID leverages PrivateLoader
By: Joshua Platt and Jason Reaves
#ParsedReport
04-08-2022
: APT31 ,. Flying in the "clouds": APT31 again uses the cloud storage, attacking Russian companies
https://www.ptsecurity.com/ru-ru/research/pt-esc-threat-intelligence/apt31-cloud-attacks
Actors/Campaigns:
Apt31
Taskmasters
Naikon
Threats:
Yarat
Vmprotect_tool
Dllsideloading_technique
Dll_hijacking_technique
Industry:
Energy, Petroleum
Geo:
Russian, Russia
TTPs:
Tactics: 8
Technics: 19
IOCs:
File: 21
Hash: 15
Softs:
curl, windows registry
Algorithms:
rc4, base64
Functions:
GETADAPTERSInfo
Languages:
java
YARA: Found
Links:
04-08-2022
: APT31 ,. Flying in the "clouds": APT31 again uses the cloud storage, attacking Russian companies
https://www.ptsecurity.com/ru-ru/research/pt-esc-threat-intelligence/apt31-cloud-attacks
Actors/Campaigns:
Apt31
Taskmasters
Naikon
Threats:
Yarat
Vmprotect_tool
Dllsideloading_technique
Dll_hijacking_technique
Industry:
Energy, Petroleum
Geo:
Russian, Russia
TTPs:
Tactics: 8
Technics: 19
IOCs:
File: 21
Hash: 15
Softs:
curl, windows registry
Algorithms:
rc4, base64
Functions:
GETADAPTERSInfo
Languages:
java
YARA: Found
Links:
https://github.com/nlohmann/jsonptsecurity.com
Блог PT ESC Threat Intelligence
В этом блоге вы можете найти информацию об актуальных атаках хакерских группировок по всему миру, разбор их инструментов, информацию об инцидентах, TTP группировок, индикаторы компрометации и названия детектов в наших продуктах
#ParsedReport
04-08-2022
So RapperBot, What Ya Bruting For?
https://www.fortinet.com/blog/threat-research/rapperbot-malware-discovery
Actors/Campaigns:
Keksec
Threats:
Rapperbot
Mirai
Bashlite
Industry:
Iot
Geo:
Taiwan, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 21
Hash: 26
IP: 4
Softs:
curl
Algorithms:
xor
Platforms:
arm, x86
04-08-2022
So RapperBot, What Ya Bruting For?
https://www.fortinet.com/blog/threat-research/rapperbot-malware-discovery
Actors/Campaigns:
Keksec
Threats:
Rapperbot
Mirai
Bashlite
Industry:
Iot
Geo:
Taiwan, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Url: 21
Hash: 26
IP: 4
Softs:
curl
Algorithms:
xor
Platforms:
arm, x86
Fortinet Blog
So RapperBot, What Ya Bruting For?
FortiGuard Labs is tracking a rapidly evolving IoT malware family known as RapperBot. Read to learn how this threat infects and persists on a victim’s device.…
#ParsedReport
04-08-2022
Stegomalware Identifying possible attack vectors
https://blog.cyble.com/2022/08/04/stegomalware-identifying-possible-attack-vectors
Actors/Campaigns:
Knotweed
Threats:
Loli_stealer
Mimikatz
Rubeus_tool
Nanocore_rat
Agent_tesla
Formbook
Corelump
Beacon
Industry:
Ics
TTPs:
Tactics: 2
Technics: 5
IOCs:
File: 1
Languages:
golang
04-08-2022
Stegomalware Identifying possible attack vectors
https://blog.cyble.com/2022/08/04/stegomalware-identifying-possible-attack-vectors
Actors/Campaigns:
Knotweed
Threats:
Loli_stealer
Mimikatz
Rubeus_tool
Nanocore_rat
Agent_tesla
Formbook
Corelump
Beacon
Industry:
Ics
TTPs:
Tactics: 2
Technics: 5
IOCs:
File: 1
Languages:
golang
Cyble
Cyble - Stegomalware - Identifying Possible Attack Vectors
Cyble Research Labs analyzes the rise of Stegomalware and the reason behind it's popularity through careful testing.
👍1
#ParsedReport
04-08-2022
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware
https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra
Actors/Campaigns:
Projector_libra
Exotic_lily
Shathak
Ta578
Threats:
Bumblebee
Cobalt_strike
Conti
Bazarbackdoor
Trickbot
Icedid
Diavol
Industry:
Petroleum
Geo:
Japan, Emea, Apac, America
IOCs:
File: 4
Path: 2
IP: 2
Domain: 1
Hash: 6
Url: 1
Softs:
active directory
Algorithms:
zip
04-08-2022
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware
https://unit42.paloaltonetworks.com/bumblebee-malware-projector-libra
Actors/Campaigns:
Projector_libra
Exotic_lily
Shathak
Ta578
Threats:
Bumblebee
Cobalt_strike
Conti
Bazarbackdoor
Trickbot
Icedid
Diavol
Industry:
Petroleum
Geo:
Japan, Emea, Apac, America
IOCs:
File: 4
Path: 2
IP: 2
Domain: 1
Hash: 6
Url: 1
Softs:
active directory
Algorithms:
zip
Unit 42
Flight of the Bumblebee: Email Lures and File Sharing Services Lead to Malware
We provide a case study of how the criminal group Projector Libra uses legitimate file sharing services to distribute Bumblebee malware.
#ParsedReport
04-08-2022
Dark Web Profile: Vice Society
https://socradar.io/dark-web-profile-vice-society
Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Killnet
Threats:
Printnightmare_vuln
Industry:
Retail, Healthcare, Education, Ngo, Financial
Geo:
Brazil, Germany, Vietnam, Israeli, Indiana, Thailand, Indianapolis, America
Softs:
confluence, esxi
04-08-2022
Dark Web Profile: Vice Society
https://socradar.io/dark-web-profile-vice-society
Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Killnet
Threats:
Printnightmare_vuln
Industry:
Retail, Healthcare, Education, Ngo, Financial
Geo:
Brazil, Germany, Vietnam, Israeli, Indiana, Thailand, Indianapolis, America
Softs:
confluence, esxi
SOCRadar® Cyber Intelligence Inc.
Dark Web Profile: Vice Society Ransomware Group - SOCRadar® Cyber Intelligence Inc.
#ParsedReport
04-08-2022
Attackers leveraging Dark Utilities "C2aaS" platform in malware campaigns
http://blog.talosintelligence.com/2022/08/dark-utilities.html
Actors/Campaigns:
Lapsus
Threats:
Darkutilities_tool
Smartbot_tool
Kinsing_miner
Xmrig_miner
Industry:
Iot, Entertainment, Healthcare
Geo:
France, Germany, French
IOCs:
Path: 3
Url: 2
Domain: 6
File: 1
Hash: 52
Softs:
telegram, fivem, teamspeak3, systemd, curl, crontab, teamspeak, gmod, discord, steam
Languages:
python
Platforms:
arm
Links:
04-08-2022
Attackers leveraging Dark Utilities "C2aaS" platform in malware campaigns
http://blog.talosintelligence.com/2022/08/dark-utilities.html
Actors/Campaigns:
Lapsus
Threats:
Darkutilities_tool
Smartbot_tool
Kinsing_miner
Xmrig_miner
Industry:
Iot, Entertainment, Healthcare
Geo:
France, Germany, French
IOCs:
Path: 3
Url: 2
Domain: 6
File: 1
Hash: 52
Softs:
telegram, fivem, teamspeak3, systemd, curl, crontab, teamspeak, gmod, discord, steam
Languages:
python
Platforms:
arm
Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2022/08Cisco Talos
Attackers leveraging Dark Utilities "C2aaS" platform in malware campaigns
By Edmund Brumaghin, Azim Khodjibaev and Matt Thaxton, with contributions from Arnaud Zobec. Executive Summary * Dark Utilities, released in early 2022, is a platform that provides full-featured C2 capabilities to adversaries. * It is marketed as a means…
#ParsedReport
04-08-2022
Ousaban: LATAM Banking Malware Abusing Cloud Services
https://www.netskope.com/blog/ousaban-latam-banking-malware-abusing-cloud-services
Threats:
Ousaban
Javali
Astaroth
Metamorfo
Grandoreiro
Dll_hijacking_technique
Upx_tool
Enigma_tool
Aitm_technique
Industry:
Financial
Geo:
Brazilian, Latam, Brazil
IOCs:
File: 8
Softs:
telegram
Algorithms:
zip , xor
Languages:
python, delphi, javascript
Links:
04-08-2022
Ousaban: LATAM Banking Malware Abusing Cloud Services
https://www.netskope.com/blog/ousaban-latam-banking-malware-abusing-cloud-services
Threats:
Ousaban
Javali
Astaroth
Metamorfo
Grandoreiro
Dll_hijacking_technique
Upx_tool
Enigma_tool
Aitm_technique
Industry:
Financial
Geo:
Brazilian, Latam, Brazil
IOCs:
File: 8
Softs:
telegram
Algorithms:
zip , xor
Languages:
python, delphi, javascript
Links:
https://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/Ousaban/scripthttps://github.com/netskopeoss/NetskopeThreatLabsIOCs/tree/main/OusabanNetskope
Ousaban: LATAM Banking Malware Abusing Cloud Services
Summary Ousaban (a.k.a. Javali) is a banking malware that emerged between 2017 and 2018, with the primary goal of stealing sensitive data from financial
#ParsedReport
04-08-2022
Who Needs Macros? \| Threat Actors Pivot to Abusing Explorer and Other LOLBins via Windows Shortcuts
https://www.sentinelone.com/labs/who-needs-macros-threat-actors-pivot-to-abusing-explorer-and-other-lolbins-via-windows-shortcuts
Actors/Campaigns:
Exotic_lily
Gamaredon
Threats:
Lolbin
Mlnk_tool
Quantumbuilder_tool
Qakbot
Emotet
Icedid
Bumblebee
Raspberry_robin
Glowsand
Geo:
Russian, Ukraine, Ukrainian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 12
Hash: 1
Path: 7
Softs:
microsoft defender, windows shell, windows explorer
Algorithms:
exhibit
Functions:
LinkTargetIDList, CreateProcessW
Links:
04-08-2022
Who Needs Macros? \| Threat Actors Pivot to Abusing Explorer and Other LOLBins via Windows Shortcuts
https://www.sentinelone.com/labs/who-needs-macros-threat-actors-pivot-to-abusing-explorer-and-other-lolbins-via-windows-shortcuts
Actors/Campaigns:
Exotic_lily
Gamaredon
Threats:
Lolbin
Mlnk_tool
Quantumbuilder_tool
Qakbot
Emotet
Icedid
Bumblebee
Raspberry_robin
Glowsand
Geo:
Russian, Ukraine, Ukrainian
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 12
Hash: 1
Path: 7
Softs:
microsoft defender, windows shell, windows explorer
Algorithms:
exhibit
Functions:
LinkTargetIDList, CreateProcessW
Links:
https://github.com/EricZimmerman/LECmdSentinelOne
Who Needs Macros? | Threat Actors Pivot to Abusing Explorer and Other LOLBins via Windows Shortcuts
Crimeware vendors say 'macros are dead', but they have a new weapon to help threat actors successfully deploy malware.
#ParsedReport
04-08-2022
Active Phishing Campaign Alert
https://zvelo.com/active-phishing-campaign-alert
IOCs:
Url: 4
Softs:
electrum
04-08-2022
Active Phishing Campaign Alert
https://zvelo.com/active-phishing-campaign-alert
IOCs:
Url: 4
Softs:
electrum
Zvelo
Active Phishing Campaign Alert
Active Threat Alert: Protect against active phishing campaigns serving up personalized and uniquely randomized URL paths or subdomains.
#ParsedReport
04-08-2022
GwisinLocker ransomwaretargets South Korean industrial and pharma firms. GwisinLocker ransomware targets South Korean industrial and pharma firms
https://blog.reversinglabs.com/blog/gwisinlocker-ransomware-targets-south-korean-industrial-and-pharmaceutical-companies
Threats:
Gwisin
Kisa
Gozi
Industry:
Government, Financial, Healthcare
Geo:
Korean, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Hash: 2
Softs:
esxi, unix, active directory
Algorithms:
rc4, aes
Languages:
java
04-08-2022
GwisinLocker ransomwaretargets South Korean industrial and pharma firms. GwisinLocker ransomware targets South Korean industrial and pharma firms
https://blog.reversinglabs.com/blog/gwisinlocker-ransomware-targets-south-korean-industrial-and-pharmaceutical-companies
Threats:
Gwisin
Kisa
Gozi
Industry:
Government, Financial, Healthcare
Geo:
Korean, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Hash: 2
Softs:
esxi, unix, active directory
Algorithms:
rc4, aes
Languages:
java
ReversingLabs
GwisinLocker ransomware targets South Korean industrial and pharma firms
GwisinLocker is a new ransomware family that targets Linux in industrial and pharma companies with sophisticated "double extortion" ransomware campaigns.
#ParsedReport
05-08-2022
Minerva Labs Blog
http://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Threats:
Lockbit
Blackcat
Uac_bypass_technique
Geo:
Russian, Moldova, Belarusian, Ukrainian, Romanian, Syria
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Softs:
thebat, dbsnmp, onenote, windows defender, msexchange, powerpnt, steam, wordpad
Algorithms:
xor
Functions:
NtSetInformationThread, GetSystemDefaultUILanguage, GetUserDefaultUILanguage
05-08-2022
Minerva Labs Blog
http://blog.minerva-labs.com/lockbit-3.0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness
Threats:
Lockbit
Blackcat
Uac_bypass_technique
Geo:
Russian, Moldova, Belarusian, Ukrainian, Romanian, Syria
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 1
Softs:
thebat, dbsnmp, onenote, windows defender, msexchange, powerpnt, steam, wordpad
Algorithms:
xor
Functions:
NtSetInformationThread, GetSystemDefaultUILanguage, GetUserDefaultUILanguage
Minerva-Labs
Lockbit 3.0 AKA Lockbit Black is here, with a new icon, new ransom note, new wallpaper, but less evasiveness?
Lockbit 3.0, also known as Lockbit Black was recently released and has already claimed its first victims. We dive into how it works and how you can protect yourselves
#ParsedReport
05-08-2022
Dark Utilities Platform Provides C2 Server for Threat Actors
https://socradar.io/dark-utilities-platform-provides-c2-server-for-threat-actors
Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Lapsus
Threats:
Darkutilities_tool
Industry:
Entertainment, Financial, Iot
IOCs:
Hash: 52
Domain: 5
Softs:
confluence, crontab, gmod, discord, fivem, systemd, teamspeak3, telegram
Platforms:
arm
Links:
05-08-2022
Dark Utilities Platform Provides C2 Server for Threat Actors
https://socradar.io/dark-utilities-platform-provides-c2-server-for-threat-actors
Actors/Campaigns:
Vice_society
Dawdropper
Knotweed
Lapsus
Threats:
Darkutilities_tool
Industry:
Entertainment, Financial, Iot
IOCs:
Hash: 52
Domain: 5
Softs:
confluence, crontab, gmod, discord, fivem, systemd, teamspeak3, telegram
Platforms:
arm
Links:
https://github.com/Cisco-Talos/IOCs/tree/main/2022/08SOCRadar® Cyber Intelligence Inc.
Dark Utilities Platform Provides C2 Server for Threat Actors - SOCRadar
Cybercriminals can now use a new service called Dark Utilities to build up a command and control (C2) center for their malicious activities.