#ParsedReport
10-08-2022
ASEC (20220801 \~ 20220807). ASEC Weekly Malware Statistics (20220801 \~ 20220807)
https://asec.ahnlab.com/ko/37552
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Cloudeye
Postealer
Remcos_rat
Nanocore_rat
Redline_stealer
Beamwinhttp_loader
Vidar_stealer
Antefrigus
Revil
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 38
Domain: 3
IP: 3
Email: 5
Url: 25
Softs:
nsis installer, discord
Languages:
visual_basic
10-08-2022
ASEC (20220801 \~ 20220807). ASEC Weekly Malware Statistics (20220801 \~ 20220807)
https://asec.ahnlab.com/ko/37552
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Cloudeye
Postealer
Remcos_rat
Nanocore_rat
Redline_stealer
Beamwinhttp_loader
Vidar_stealer
Antefrigus
Revil
Industry:
Financial, Transport
Geo:
Korea
IOCs:
File: 38
Domain: 3
IP: 3
Email: 5
Url: 25
Softs:
nsis installer, discord
Languages:
visual_basic
ASEC BLOG
ASEC 주간 악성코드 통계 (20220801 ~ 20220807) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 8월 1일 월요일부터 8월 7일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 47.4%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 22.6%, 다운로더 20.0%, 랜섬웨어 6.8%, 뱅킹 2.6%, 코인마이너 악성코드가 0.5%로 집계되었다. Top…
#ParsedReport
11-08-2022
Cisco Talos shares insights related to recent cyber attack on Cisco
https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html
Actors/Campaigns:
Unc2447 (motivation: financially_motivated)
Lapsus
Threats:
Yanluowang
Silence
Cobalt_strike
Logmein_tool
Teamviewer_tool
Powersploit
Mimikatz
Impacket_tool
Fivehands
Hellokitty
Industry:
Education
Geo:
Russia
TTPs:
Tactics: 10
Technics: 21
IOCs:
File: 1
Path: 1
Hash: 10
IP: 71
Domain: 14
Email: 1
Softs:
active directory, google chrome
Languages:
php
Platforms:
x64
11-08-2022
Cisco Talos shares insights related to recent cyber attack on Cisco
https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html
Actors/Campaigns:
Unc2447 (motivation: financially_motivated)
Lapsus
Threats:
Yanluowang
Silence
Cobalt_strike
Logmein_tool
Teamviewer_tool
Powersploit
Mimikatz
Impacket_tool
Fivehands
Hellokitty
Industry:
Education
Geo:
Russia
TTPs:
Tactics: 10
Technics: 21
IOCs:
File: 1
Path: 1
Hash: 10
IP: 71
Domain: 14
Email: 1
Softs:
active directory, google chrome
Languages:
php
Platforms:
x64
Cisco Talos
Cisco Talos shares insights related to recent cyber attack on Cisco
Update History Aug. 10, 2022 Adding clarifying details on activity involving active directory. Aug. 10, 2022 Update made to the Cisco Response and Recommendations section related to MFA.
#ParsedReport
11-08-2022
BlueSky Ransomware: Fast Encryption via Multithreading
https://unit42.paloaltonetworks.com/bluesky-ransomware
Actors/Campaigns:
Bluesky
Threats:
Conti
Babuk
Redline_stealer
Juicypotato_tool
Api_obfuscation_technique
Smbghost_tool
Industry:
Ics
Geo:
America, Japan, Apac, Emea
CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
Tactics: 2
Technics: 6
IOCs:
Path: 2
Url: 11
File: 10
Domain: 1
Hash: 21
Algorithms:
chacha20, aes, rc4, curve25519
Functions:
PostQueuedCompletionStatus, GetQueuedCompletionPort, CreateIoCompletionPort, NetShareEnum
Platforms:
x86
Links:
11-08-2022
BlueSky Ransomware: Fast Encryption via Multithreading
https://unit42.paloaltonetworks.com/bluesky-ransomware
Actors/Campaigns:
Bluesky
Threats:
Conti
Babuk
Redline_stealer
Juicypotato_tool
Api_obfuscation_technique
Smbghost_tool
Industry:
Ics
Geo:
America, Japan, Apac, Emea
CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
Tactics: 2
Technics: 6
IOCs:
Path: 2
Url: 11
File: 10
Domain: 1
Hash: 21
Algorithms:
chacha20, aes, rc4, curve25519
Functions:
PostQueuedCompletionStatus, GetQueuedCompletionPort, CreateIoCompletionPort, NetShareEnum
Platforms:
x86
Links:
https://github.com/gharty03/Conti-Ransomwarehttps://github.com/ohpe/juicy-potatoUnit 42
BlueSky Ransomware: Fast Encryption via Multithreading
BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses. Read our technical analysis.
#ParsedReport
11-08-2022
MikuBot Spotted In The Wild
https://blog.cyble.com/2022/08/11/mikubot-spotted-in-the-wild
Threats:
Mikubot
Hiddenvnc_tool
Upx_tool
Beacon
Industry:
Financial
Geo:
India, Taiwan, Georgia, Dubai, Singapore, Australia
TTPs:
Tactics: 5
Technics: 9
IOCs:
Path: 1
Hash: 8
Softs:
task scheduler
Algorithms:
base64
Functions:
ShellExecuteW
Languages:
php
11-08-2022
MikuBot Spotted In The Wild
https://blog.cyble.com/2022/08/11/mikubot-spotted-in-the-wild
Threats:
Mikubot
Hiddenvnc_tool
Upx_tool
Beacon
Industry:
Financial
Geo:
India, Taiwan, Georgia, Dubai, Singapore, Australia
TTPs:
Tactics: 5
Technics: 9
IOCs:
Path: 1
Hash: 8
Softs:
task scheduler
Algorithms:
base64
Functions:
ShellExecuteW
Languages:
php
Cyble
MikuBot Spotted In The Wild
Cyble analyzes the newly discovered Mikubot and the spyware activities that it conducts using HVNCs.
#ParsedReport
11-08-2022
A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333
https://cloudsek.com/threatintelligence/a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333/?utm_source=rss&utm_medium=rss&utm_campaign=a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333
Actors/Campaigns:
Emailthief
Industry:
Government
CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)
TTPs:
Tactics: 3
Technics: 0
IOCs:
Url: 5
IP: 4
Domain: 5
Softs:
unix
Functions:
DosSlashToUnix
11-08-2022
A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333
https://cloudsek.com/threatintelligence/a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333/?utm_source=rss&utm_medium=rss&utm_campaign=a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333
Actors/Campaigns:
Emailthief
Industry:
Government
CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)
TTPs:
Tactics: 3
Technics: 0
IOCs:
Url: 5
IP: 4
Domain: 5
Softs:
unix
Functions:
DosSlashToUnix
Cloudsek
A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333 | Threat Intelligence | CloudSEK
An RCE vulnerability in Zimbra webmail servers being actively exploited to target multiple organizations worldwide. The exploit was used to launch a spear phishing campaign against Europe.
#ParsedReport
11-08-2022
APT-C-35 Gets a New Upgrade
https://blog.morphisec.com/apt-c-35-new-windows-framework-revealed
Actors/Campaigns:
Donot
Threats:
Yty
Beacon
Industry:
Government
Geo:
Asia, Asian, India, Pakistan, Bangladesh
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 27
Path: 5
Url: 2
IP: 2
Hash: 17
Domain: 12
Softs:
android, virtualbox, google chrome, mozilla firefox, microsoft office
Algorithms:
base64, aes-256, xor
Functions:
ZwAllocateVirtualMemory
Languages:
python, php
Platforms:
x86
11-08-2022
APT-C-35 Gets a New Upgrade
https://blog.morphisec.com/apt-c-35-new-windows-framework-revealed
Actors/Campaigns:
Donot
Threats:
Yty
Beacon
Industry:
Government
Geo:
Asia, Asian, India, Pakistan, Bangladesh
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 27
Path: 5
Url: 2
IP: 2
Hash: 17
Domain: 12
Softs:
android, virtualbox, google chrome, mozilla firefox, microsoft office
Algorithms:
base64, aes-256, xor
Functions:
ZwAllocateVirtualMemory
Languages:
python, php
Platforms:
x86
Morphisec
APT-C-35: New Windows Framework Revealed
Morphisec Labs exclusively details new updates to the Windows framework of the advanced persistent threat actors APT-C-35, a.k.a the DoNot Team.
#ParsedReport
11-08-2022
BazarCall Advisory: Essential Guide to Attack Vector that Revolutionized Data Breaches
https://www.advintel.io/post/bazarcall-advisory-the-essential-guide-to-call-back-phishing-attacks-that-revolutionized-the-data
Actors/Campaigns:
Luna_moth
Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Emotet
Trickbot
Avaddon
Industry:
Foodtech, Financial
Geo:
Ukraine, Russian
11-08-2022
BazarCall Advisory: Essential Guide to Attack Vector that Revolutionized Data Breaches
https://www.advintel.io/post/bazarcall-advisory-the-essential-guide-to-call-back-phishing-attacks-that-revolutionized-the-data
Actors/Campaigns:
Luna_moth
Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Emotet
Trickbot
Avaddon
Industry:
Foodtech, Financial
Geo:
Ukraine, Russian
#ParsedReport
11-08-2022
SOVA malware is back and is evolving rapidly
https://www.cleafy.com/cleafy-labs/sova-malware-is-back-and-is-evolving-rapidly
Threats:
Sova
Anatsa
Oscorp
Brata
Industry:
Financial
Geo:
Philippine, Francesco, Ukraine, Russian
IOCs:
File: 1
Hash: 3
Domain: 2
Softs:
chrome, android
Algorithms:
aes
11-08-2022
SOVA malware is back and is evolving rapidly
https://www.cleafy.com/cleafy-labs/sova-malware-is-back-and-is-evolving-rapidly
Threats:
Sova
Anatsa
Oscorp
Brata
Industry:
Financial
Geo:
Philippine, Francesco, Ukraine, Russian
IOCs:
File: 1
Hash: 3
Domain: 2
Softs:
chrome, android
Algorithms:
aes
Cleafy
SOVA malware is back and is evolving rapidly | Cleafy Labs
SOVA, a new Android Banking Trojan, is spreading across Europe. Already appeared in different versions, this malware is now evolving, and it is targeting more than 200 mobile applications, ranging from banking apps to crypto exchanges/wallets. Here's the…
#ParsedReport
11-08-2022
Detecting DNS implants: Old kitten, new tricks A Saitama Case Study
https://research.nccgroup.com/2022/08/11/detecting-dns-implants-old-kitten-new-tricks-a-saitama-case-study
Threats:
Saitama
Dnstunnelling_technique
Cobalt_strike
Sliver_tool
Industry:
Government
Geo:
Jordan
IOCs:
File: 2
Algorithms:
prng
Links:
11-08-2022
Detecting DNS implants: Old kitten, new tricks A Saitama Case Study
https://research.nccgroup.com/2022/08/11/detecting-dns-implants-old-kitten-new-tricks-a-saitama-case-study
Threats:
Saitama
Dnstunnelling_technique
Cobalt_strike
Sliver_tool
Industry:
Government
Geo:
Jordan
IOCs:
File: 2
Algorithms:
prng
Links:
https://github.com/fox-it/saitama-server#ParsedReport
11-08-2022
CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies
https://www.trendmicro.com/en_us/research/22/h/copperstealer-distributes-malicious-chromium-browser-extension-steal-cryptocurrencies.html
Threats:
Copperstealer
Upx_tool
Tron
Industry:
Financial
Geo:
Turkish, Japanese, Italian, Polish, German, Portuguese, Indonesia, French, Spanish, Russian
IOCs:
File: 3
Hash: 30
Domain: 1
Softs:
zcash, centbrowser, orbitum, vivaldi, comodo dragon, opera, chromium, coinbase, chrome
Languages:
java, javascript, php
11-08-2022
CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies
https://www.trendmicro.com/en_us/research/22/h/copperstealer-distributes-malicious-chromium-browser-extension-steal-cryptocurrencies.html
Threats:
Copperstealer
Upx_tool
Tron
Industry:
Financial
Geo:
Turkish, Japanese, Italian, Polish, German, Portuguese, Indonesia, French, Spanish, Russian
IOCs:
File: 3
Hash: 30
Domain: 1
Softs:
zcash, centbrowser, orbitum, vivaldi, comodo dragon, opera, chromium, coinbase, chrome
Languages:
java, javascript, php
Trend Micro
CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies
We tracked the latest deployment of the group behind CopperStealer, this time stealing cryptocurrencies and users’ wallet account information via a malicious Chromium-based browser extension.
#ParsedReport
11-08-2022
SolidBit Ransomware Group Actively Recruiting Affiliates
https://cloudsek.com/threatintelligence/solidbit-ransomware-group-actively-recruiting-affiliates/?utm_source=rss&utm_medium=rss&utm_campaign=solidbit-ransomware-group-actively-recruiting-affiliates
Threats:
Solidbit
Lockbit
Industry:
Financial
Geo:
America
CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 1
Hash: 2
File: 1
Softs:
windows defender
11-08-2022
SolidBit Ransomware Group Actively Recruiting Affiliates
https://cloudsek.com/threatintelligence/solidbit-ransomware-group-actively-recruiting-affiliates/?utm_source=rss&utm_medium=rss&utm_campaign=solidbit-ransomware-group-actively-recruiting-affiliates
Threats:
Solidbit
Lockbit
Industry:
Financial
Geo:
America
CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)
TTPs:
Tactics: 1
Technics: 0
IOCs:
Path: 1
Hash: 2
File: 1
Softs:
windows defender
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
SolidBit Ransomware Group Actively Recruiting Affiliates - CloudSEK
CloudSEK discovered a threat actor group named SolidBit, offering RaaS (Ransom-as-a-Service) on an underground forum. The group is actively looking for partners to gain access to companies’ private networks in order to spread the ransomware called SolidBit.
#ParsedReport
12-08-2022
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
https://www.trendmicro.com/en_us/research/22/h/irontiger-compromises-chat-app-Mimi-targets-windows-mac-linux-users.html
Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Earth_berberoka
Drbcontrol
Threats:
Hyperbro
Rshell
Dll_sideloading_technique
Gh0st_rat
Plugx_rat
Shadowpad
Industry:
Entertainment
Geo:
Taiwan, Chinese, Philippines
IOCs:
File: 4
IP: 3
Domain: 4
Hash: 11
Softs:
windows installer, macos, node.js, mac os, android
Languages:
javascript
Links:
12-08-2022
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
https://www.trendmicro.com/en_us/research/22/h/irontiger-compromises-chat-app-Mimi-targets-windows-mac-linux-users.html
Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Earth_berberoka
Drbcontrol
Threats:
Hyperbro
Rshell
Dll_sideloading_technique
Gh0st_rat
Plugx_rat
Shadowpad
Industry:
Entertainment
Geo:
Taiwan, Chinese, Philippines
IOCs:
File: 4
IP: 3
Domain: 4
Hash: 11
Softs:
windows installer, macos, node.js, mac os, android
Languages:
javascript
Links:
https://github.com/f0rb1dd3n/ReptileTrend Micro
Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users
https://www.trendmicro.com/en_no/research/21/d/iron-tiger-apt-updates-toolkit-with-evolved-sysupdate-malware-va.html
#ParsedReport
13-08-2022
LuckyMouse uses a backdoored Electron app to target MacOS
https://blog.sekoia.io/luckymouse-uses-a-backdoored-electron-app-to-target-macos
Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Stealthytrident
Threats:
Hyberbro
Rshell
Plugx_rat
Tmanger
Hyperbro
Watering_hole_technique
Luckymouse
Geo:
Mongolia, China, Chinese
IOCs:
Domain: 1
File: 10
IP: 6
Url: 2
Hash: 9
Softs:
macos, android
Languages:
javascript
Platforms:
apple
YARA: Found
13-08-2022
LuckyMouse uses a backdoored Electron app to target MacOS
https://blog.sekoia.io/luckymouse-uses-a-backdoored-electron-app-to-target-macos
Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Stealthytrident
Threats:
Hyberbro
Rshell
Plugx_rat
Tmanger
Hyperbro
Watering_hole_technique
Luckymouse
Geo:
Mongolia, China, Chinese
IOCs:
Domain: 1
File: 10
IP: 6
Url: 2
Hash: 9
Softs:
macos, android
Languages:
javascript
Platforms:
apple
YARA: Found
Sekoia.io Blog
LuckyMouse uses a backdoored Electron app to target MacOS
This is the first time that SEKOIA observed LuckyMouse targeting MacOS.
#ParsedReport
14-08-2022
Typosquatting Campaign Targeting Pythons Top Packages, Dropping GitHub Hosted Malware with DGA Capabilities. Attack Vector Typosquatting
https://checkmarx.com/blog/typosquatting-campaign-targeting-pythons-top-packages-dropping-github-hosted-malware-with-dga-capabilities
Threats:
Typosquatting_technique
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 3
Path: 2
Url: 10
Hash: 3
Algorithms:
xor
Languages:
python
Links:
14-08-2022
Typosquatting Campaign Targeting Pythons Top Packages, Dropping GitHub Hosted Malware with DGA Capabilities. Attack Vector Typosquatting
https://checkmarx.com/blog/typosquatting-campaign-targeting-pythons-top-packages-dropping-github-hosted-malware-with-dga-capabilities
Threats:
Typosquatting_technique
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 3
Path: 2
Url: 10
Hash: 3
Algorithms:
xor
Languages:
python
Links:
https://github.com/jagermager999/8746465cdg78cdsxasy8a/commits/mainhttps://github.com/jagermager999https://github.com/jagermager999/8746465cdg78cdsxasy8aCheckmarx.com
Typosquatting Campaign Targeting Python's Top Packages, Dropping GitHub Hosted Malware with DGA Capabilities
Right after Checkmarx’s automatic engines detected the malicious packages we started an analysis process involving our security researchers analyzing this campaign and reverse engineering the dropped embedded malware to understand the full picture.
#ParsedReport
15-08-2022
Shuckworm: Russia-Linked Group Maintains Ukraine Focus
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/russia-ukraine-shuckworm
Actors/Campaigns:
Gamaredon (motivation: cyber_espionage)
Threats:
Giddome
Ammyy_admin_tool
Anydesk_tool
Decay
Geo:
Russian, Ukrainian, Ukraine, Russia
IOCs:
File: 14
Domain: 5
Hash: 43
Url: 10
Path: 1
Functions:
PowerShell, InternetExplorer
Languages:
php
15-08-2022
Shuckworm: Russia-Linked Group Maintains Ukraine Focus
https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/russia-ukraine-shuckworm
Actors/Campaigns:
Gamaredon (motivation: cyber_espionage)
Threats:
Giddome
Ammyy_admin_tool
Anydesk_tool
Decay
Geo:
Russian, Ukrainian, Ukraine, Russia
IOCs:
File: 14
Domain: 5
Hash: 43
Url: 10
Path: 1
Functions:
PowerShell, InternetExplorer
Languages:
php
Security
Shuckworm: Russia-Linked Group Maintains Ukraine Focus
Infostealer appears to be payload in recent activity aimed at Ukrainian organizations.
#ParsedReport
15-08-2022
Patchwork APT. Analysis of the characteristics of new activities in Patchwork APT in South Asia
https://mp.weixin.qq.com/s/egG0nORZFvo_rCY_zmTgVQ
Actors/Campaigns:
Dropping_elephant
Threats:
Patchinfecter
Grat2_tool
Industry:
Government, Healthcare
Geo:
China, Asia, Asian, Pakistan
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
IOCs:
File: 11
Path: 1
IP: 1
Url: 1
Hash: 4
Softs:
microsoft office
Algorithms:
zip , xor, base64
15-08-2022
Patchwork APT. Analysis of the characteristics of new activities in Patchwork APT in South Asia
https://mp.weixin.qq.com/s/egG0nORZFvo_rCY_zmTgVQ
Actors/Campaigns:
Dropping_elephant
Threats:
Patchinfecter
Grat2_tool
Industry:
Government, Healthcare
Geo:
China, Asia, Asian, Pakistan
CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...
IOCs:
File: 11
Path: 1
IP: 1
Url: 1
Hash: 4
Softs:
microsoft office
Algorithms:
zip , xor, base64
Weixin Official Accounts Platform
南亚Patchwork APT组织新活动特点分析
PatchWork APT在近期攻击活动中应用了跟以往不同的攻击工具。
#ParsedReport
15-08-2022
Ransomware Gangs Adopt Callback Phishing Techniques for Gaining Initial Network Access
https://www.hipaajournal.com/ransomware-gangs-adopt-callback-phishing-techniques-for-gaining-initial-network-access
Actors/Campaigns:
Luna_moth
Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Industry:
Healthcare, Financial
Languages:
javascript
15-08-2022
Ransomware Gangs Adopt Callback Phishing Techniques for Gaining Initial Network Access
https://www.hipaajournal.com/ransomware-gangs-adopt-callback-phishing-techniques-for-gaining-initial-network-access
Actors/Campaigns:
Luna_moth
Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Industry:
Healthcare, Financial
Languages:
javascript
HIPAA Journal
Ransomware Gangs Adopt Callback Phishing Techniques for Gaining Initial Network Access
Multiple ransomware groups have adopted the BazarCall callback phishing technique to gain initial access to victims’ networks, including threat actors More ransomware gangs have adopted the BazarCall callback phishing technique to gain initial access to victims’…
#ParsedReport
15-08-2022
Disrupting SEABORGIUMs ongoing phishing operations
https://www.microsoft.com/security/blog/2022/08/15/disrupting-seaborgiums-ongoing-phishing-operations
Actors/Campaigns:
Coldriver
Gamaredon
Threats:
Seaborgium
Evilginx_tool
Credential_harvesting_technique
Aitm_technique
Industry:
Education, Financial, Government, Ngo
Geo:
Ukraine, Russia, Russian
IOCs:
Domain: 69
Softs:
microsoft 365 defender, microsoft defender
Links:
15-08-2022
Disrupting SEABORGIUMs ongoing phishing operations
https://www.microsoft.com/security/blog/2022/08/15/disrupting-seaborgiums-ongoing-phishing-operations
Actors/Campaigns:
Coldriver
Gamaredon
Threats:
Seaborgium
Evilginx_tool
Credential_harvesting_technique
Aitm_technique
Industry:
Education, Financial, Government, Ngo
Geo:
Ukraine, Russia, Russian
IOCs:
Domain: 69
Softs:
microsoft 365 defender, microsoft defender
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/SEABORGIUMDomainsAugust2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Campaigns/SEABORGIUMDomainIOCsAug2022.yamlMicrosoft News
Disrupting SEABORGIUM’s ongoing phishing operations
The Microsoft Threat Intelligence Center (MSTIC) has observed and taken actions to disrupt campaigns launched by SEABORGIUM in campaigns involve persistent phishing and credential theft campaigns leading to intrusions and data theft.
#ParsedReport
16-08-2022
Threat in your browser: what dangers innocent-looking extensions hold for users
https://securelist.com/threat-in-your-browser-extensions/107181
Threats:
Websearch
Dealply
Nullmixer
Fbstealer
Industry:
Government, E-commerce, Healthcare, Financial, Petroleum
IOCs:
Domain: 1
Coin: 3
Path: 1
Url: 1
Hash: 6
Softs:
chrome, windows registry, chromium, google chrome
Languages:
javascript
16-08-2022
Threat in your browser: what dangers innocent-looking extensions hold for users
https://securelist.com/threat-in-your-browser-extensions/107181
Threats:
Websearch
Dealply
Nullmixer
Fbstealer
Industry:
Government, E-commerce, Healthcare, Financial, Petroleum
IOCs:
Domain: 1
Coin: 3
Path: 1
Url: 1
Hash: 6
Softs:
chrome, windows registry, chromium, google chrome
Languages:
javascript
Securelist
Threat in your browser: what dangers innocent-looking extensions hold for users
In this research, we observed various types of threats that mimic useful web browser extensions, and the number of users attacked by them.
#ParsedReport
16-08-2022
Banking Trojan SOVA Has New Version with Updated Features
https://socradar.io/banking-trojan-sova-has-new-version-with-updated-features
Threats:
Sova
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 1
Technics: 2
IOCs:
File: 1
Hash: 6
Domain: 2
Url: 3
Softs:
android, chrome
16-08-2022
Banking Trojan SOVA Has New Version with Updated Features
https://socradar.io/banking-trojan-sova-has-new-version-with-updated-features
Threats:
Sova
Industry:
Financial
Geo:
China, Taiwan
TTPs:
Tactics: 1
Technics: 2
IOCs:
File: 1
Hash: 6
Domain: 2
Url: 3
Softs:
android, chrome
SOCRadar® Cyber Intelligence Inc.
Banking Trojan SOVA Has New Version with Updated Features - SOCRadar® Cyber Intelligence Inc.
#ParsedReport
16-08-2022
Two more malicious Python packages in the PyPI
https://securelist.com/two-more-malicious-python-packages-in-the-pypi/107218
Threats:
Junk_code_technique
Industry:
Financial
Geo:
French
IOCs:
File: 7
Url: 3
Path: 2
Registry: 1
Hash: 5
Softs:
discord
Languages:
python, javascript
Links:
16-08-2022
Two more malicious Python packages in the PyPI
https://securelist.com/two-more-malicious-python-packages-in-the-pypi/107218
Threats:
Junk_code_technique
Industry:
Financial
Geo:
French
IOCs:
File: 7
Url: 3
Path: 2
Registry: 1
Hash: 5
Softs:
discord
Languages:
python, javascript
Links:
https://github.com/billythegoat356/HyperionSecurelist
Two more malicious Python packages in the PyPI
We used our internal automated system for monitoring open-source repositories and discovered two other malicious Python packages in the PyPI.