CTT Report Hub
3.42K subscribers
9.87K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
11-08-2022

Cisco Talos shares insights related to recent cyber attack on Cisco

https://blog.talosintelligence.com/2022/08/recent-cyber-attack.html

Actors/Campaigns:
Unc2447 (motivation: financially_motivated)
Lapsus

Threats:
Yanluowang
Silence
Cobalt_strike
Logmein_tool
Teamviewer_tool
Powersploit
Mimikatz
Impacket_tool
Fivehands
Hellokitty

Industry:
Education

Geo:
Russia

TTPs:
Tactics: 10
Technics: 21

IOCs:
File: 1
Path: 1
Hash: 10
IP: 71
Domain: 14
Email: 1

Softs:
active directory, google chrome

Languages:
php

Platforms:
x64
#ParsedReport
11-08-2022

BlueSky Ransomware: Fast Encryption via Multithreading

https://unit42.paloaltonetworks.com/bluesky-ransomware

Actors/Campaigns:
Bluesky

Threats:
Conti
Babuk
Redline_stealer
Juicypotato_tool
Api_obfuscation_technique
Smbghost_tool

Industry:
Ics

Geo:
America, Japan, Apac, Emea

CVEs:
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)

CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)


TTPs:
Tactics: 2
Technics: 6

IOCs:
Path: 2
Url: 11
File: 10
Domain: 1
Hash: 21

Algorithms:
chacha20, aes, rc4, curve25519

Functions:
PostQueuedCompletionStatus, GetQueuedCompletionPort, CreateIoCompletionPort, NetShareEnum

Platforms:
x86

Links:
https://github.com/gharty03/Conti-Ransomware
https://github.com/ohpe/juicy-potato
#ParsedReport
11-08-2022

MikuBot Spotted In The Wild

https://blog.cyble.com/2022/08/11/mikubot-spotted-in-the-wild

Threats:
Mikubot
Hiddenvnc_tool
Upx_tool
Beacon

Industry:
Financial

Geo:
India, Taiwan, Georgia, Dubai, Singapore, Australia

TTPs:
Tactics: 5
Technics: 9

IOCs:
Path: 1
Hash: 8

Softs:
task scheduler

Algorithms:
base64

Functions:
ShellExecuteW

Languages:
php
#ParsedReport
11-08-2022

A Comprehensive Analysis of the Zimbra Vulnerability CVE-2022-30333

https://cloudsek.com/threatintelligence/a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333/?utm_source=rss&utm_medium=rss&utm_campaign=a-comprehensive-analysis-of-the-zimbra-vulnerability-cve-2022-30333

Actors/Campaigns:
Emailthief

Industry:
Government

CVEs:
CVE-2022-30333 [Vulners]
Vulners: Score: 5.0, CVSS: 5.1,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- rarlab unrar (<6.12)


TTPs:
Tactics: 3
Technics: 0

IOCs:
Url: 5
IP: 4
Domain: 5

Softs:
unix

Functions:
DosSlashToUnix
#ParsedReport
11-08-2022

APT-C-35 Gets a New Upgrade

https://blog.morphisec.com/apt-c-35-new-windows-framework-revealed

Actors/Campaigns:
Donot

Threats:
Yty
Beacon

Industry:
Government

Geo:
Asia, Asian, India, Pakistan, Bangladesh

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 27
Path: 5
Url: 2
IP: 2
Hash: 17
Domain: 12

Softs:
android, virtualbox, google chrome, mozilla firefox, microsoft office

Algorithms:
base64, aes-256, xor

Functions:
ZwAllocateVirtualMemory

Languages:
python, php

Platforms:
x86
#ParsedReport
11-08-2022

BazarCall Advisory: Essential Guide to Attack Vector that Revolutionized Data Breaches

https://www.advintel.io/post/bazarcall-advisory-the-essential-guide-to-call-back-phishing-attacks-that-revolutionized-the-data

Actors/Campaigns:
Luna_moth

Threats:
Bazarbackdoor
Ryuk
Conti
Quantum_tool
Zeon
Emotet
Trickbot
Avaddon

Industry:
Foodtech, Financial

Geo:
Ukraine, Russian
#ParsedReport
11-08-2022

Detecting DNS implants: Old kitten, new tricks A Saitama Case Study

https://research.nccgroup.com/2022/08/11/detecting-dns-implants-old-kitten-new-tricks-a-saitama-case-study

Threats:
Saitama
Dnstunnelling_technique
Cobalt_strike
Sliver_tool

Industry:
Government

Geo:
Jordan

IOCs:
File: 2

Algorithms:
prng

Links:
https://github.com/fox-it/saitama-server
#ParsedReport
11-08-2022

CopperStealer Distributes Malicious Chromium-based Browser Extension to Steal Cryptocurrencies

https://www.trendmicro.com/en_us/research/22/h/copperstealer-distributes-malicious-chromium-browser-extension-steal-cryptocurrencies.html

Threats:
Copperstealer
Upx_tool
Tron

Industry:
Financial

Geo:
Turkish, Japanese, Italian, Polish, German, Portuguese, Indonesia, French, Spanish, Russian

IOCs:
File: 3
Hash: 30
Domain: 1

Softs:
zcash, centbrowser, orbitum, vivaldi, comodo dragon, opera, chromium, coinbase, chrome

Languages:
java, javascript, php
#ParsedReport
12-08-2022

Iron Tiger Compromises Chat Application Mimi, Targets Windows, Mac, and Linux Users

https://www.trendmicro.com/en_us/research/22/h/irontiger-compromises-chat-app-Mimi-targets-windows-mac-linux-users.html

Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Earth_berberoka
Drbcontrol

Threats:
Hyperbro
Rshell
Dll_sideloading_technique
Gh0st_rat
Plugx_rat
Shadowpad

Industry:
Entertainment

Geo:
Taiwan, Chinese, Philippines

IOCs:
File: 4
IP: 3
Domain: 4
Hash: 11

Softs:
windows installer, macos, node.js, mac os, android

Languages:
javascript

Links:
https://github.com/f0rb1dd3n/Reptile
#ParsedReport
13-08-2022

LuckyMouse uses a backdoored Electron app to target MacOS

https://blog.sekoia.io/luckymouse-uses-a-backdoored-electron-app-to-target-macos

Actors/Campaigns:
Emissary_panda (motivation: cyber_espionage)
Stealthytrident

Threats:
Hyberbro
Rshell
Plugx_rat
Tmanger
Hyperbro
Watering_hole_technique
Luckymouse

Geo:
Mongolia, China, Chinese

IOCs:
Domain: 1
File: 10
IP: 6
Url: 2
Hash: 9

Softs:
macos, android

Languages:
javascript

Platforms:
apple

YARA: Found
#ParsedReport
14-08-2022

Typosquatting Campaign Targeting Pythons Top Packages, Dropping GitHub Hosted Malware with DGA Capabilities. Attack Vector Typosquatting

https://checkmarx.com/blog/typosquatting-campaign-targeting-pythons-top-packages-dropping-github-hosted-malware-with-dga-capabilities

Threats:
Typosquatting_technique

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 3
Path: 2
Url: 10
Hash: 3

Algorithms:
xor

Languages:
python

Links:
https://github.com/jagermager999/8746465cdg78cdsxasy8a/commits/main
https://github.com/jagermager999
https://github.com/jagermager999/8746465cdg78cdsxasy8a
#ParsedReport
15-08-2022

Shuckworm: Russia-Linked Group Maintains Ukraine Focus

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/russia-ukraine-shuckworm

Actors/Campaigns:
Gamaredon (motivation: cyber_espionage)

Threats:
Giddome
Ammyy_admin_tool
Anydesk_tool
Decay

Geo:
Russian, Ukrainian, Ukraine, Russia

IOCs:
File: 14
Domain: 5
Hash: 43
Url: 10
Path: 1

Functions:
PowerShell, InternetExplorer

Languages:
php
#ParsedReport
15-08-2022

Patchwork APT. Analysis of the characteristics of new activities in Patchwork APT in South Asia

https://mp.weixin.qq.com/s/egG0nORZFvo_rCY_zmTgVQ

Actors/Campaigns:
Dropping_elephant

Threats:
Patchinfecter
Grat2_tool

Industry:
Government, Healthcare

Geo:
China, Asia, Asian, Pakistan

CVEs:
CVE-2021-40444 [Vulners]
Vulners: Score: 6.8, CVSS: 2.2,
Vulners: Exploitation: True
X-Force: Risk: 8.8
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2008 (r2, -)
- microsoft windows 10 (1607, -, 1809, 1909, 2004, 20h2, 21h1)
- microsoft windows server 2016 (-, 2004, 20h2)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2012 (-, -)
have more...

IOCs:
File: 11
Path: 1
IP: 1
Url: 1
Hash: 4

Softs:
microsoft office

Algorithms:
zip , xor, base64
#ParsedReport
15-08-2022

Disrupting SEABORGIUMs ongoing phishing operations

https://www.microsoft.com/security/blog/2022/08/15/disrupting-seaborgiums-ongoing-phishing-operations

Actors/Campaigns:
Coldriver
Gamaredon

Threats:
Seaborgium
Evilginx_tool
Credential_harvesting_technique
Aitm_technique

Industry:
Education, Financial, Government, Ngo

Geo:
Ukraine, Russia, Russian

IOCs:
Domain: 69

Softs:
microsoft 365 defender, microsoft defender

Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/SEABORGIUMDomainsAugust2022.yaml
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Campaigns/SEABORGIUMDomainIOCsAug2022.yaml
#ParsedReport
16-08-2022

Threat in your browser: what dangers innocent-looking extensions hold for users

https://securelist.com/threat-in-your-browser-extensions/107181

Threats:
Websearch
Dealply
Nullmixer
Fbstealer

Industry:
Government, E-commerce, Healthcare, Financial, Petroleum

IOCs:
Domain: 1
Coin: 3
Path: 1
Url: 1
Hash: 6

Softs:
chrome, windows registry, chromium, google chrome

Languages:
javascript
#ParsedReport
16-08-2022

Banking Trojan SOVA Has New Version with Updated Features

https://socradar.io/banking-trojan-sova-has-new-version-with-updated-features

Threats:
Sova

Industry:
Financial

Geo:
China, Taiwan

TTPs:
Tactics: 1
Technics: 2

IOCs:
File: 1
Hash: 6
Domain: 2
Url: 3

Softs:
android, chrome
#ParsedReport
16-08-2022

Two more malicious Python packages in the PyPI

https://securelist.com/two-more-malicious-python-packages-in-the-pypi/107218

Threats:
Junk_code_technique

Industry:
Financial

Geo:
French

IOCs:
File: 7
Url: 3
Path: 2
Registry: 1
Hash: 5

Softs:
discord

Languages:
python, javascript

Links:
https://github.com/billythegoat356/Hyperion