CTT Report Hub
3.42K subscribers
9.85K photos
6 videos
67 files
13.5K links
Threat Intelligence Report Hub
Download Telegram
#ParsedReport
18-08-2022

Grandoreiro Banking Trojan with New TTPs Targeting Various Industry Verticals

https://www.zscaler.com/blogs/security-research/grandoreiro-banking-trojan-new-ttps-targeting-various-industry-verticals

Threats:
Grandoreiro
Latentbot
Beacon

Industry:
Logistic, Government, Financial, Chemical

Geo:
America, Brazil, Spain, Spanish, Mexico

TTPs:
Tactics: 1
Technics: 0

IOCs:
Url: 6
File: 19
Path: 1
Domain: 5
Registry: 1
Hash: 10

Softs:
electrum, coinomi

Algorithms:
xor, zip

Functions:
CreateMutexA, IsDebuggerPresent, URLDownloadToFile, GetUserNameW, Process32First, GetComputerNameW, Process32Next, GetWindowTextW, EnumWindows, CreateToolhelp32Snapshot, FindWindowW

Languages:
delphi

Platforms:
x86

Links:
https://github.com/SpiderLabs/Grandoreiro-decryptor/blob/main/grandoreiro\_string\_decryptor.py
#ParsedReport
19-08-2022

EvilCoder Project Selling Multiple Dangerous Tools Online

https://blog.cyble.com/2022/08/19/evilcoder-project-selling-multiple-dangerous-tools-online

Threats:
Evilcoder_project
Xworm_rat
Xbinder
Uac_bypass_technique
Process_injection_technique

Geo:
Dubai, India, Australia, Singapore, Georgia

TTPs:
Tactics: 6
Technics: 7

IOCs:
File: 1
Domain: 1
Hash: 27

Softs:
virtualbox, android, .net framework

Algorithms:
aes

Functions:
CheckRemoteDebuggerPresent, Read, SetWorkPath
#ParsedReport
19-08-2022

You Cant Audit Me: APT29 Continues Targeting Microsoft 365

https://www.mandiant.com/resources/apt29-continues-targeting-microsoft

Actors/Campaigns:
Duke (motivation: cyber_espionage)

Industry:
Government

Geo:
Russian

Softs:
active directory, azure ad

Links:
https://github.com/mandiant/Mandiant-Azure-AD-Investigator
#ParsedReport
19-08-2022

Honker Union: Has the grandfather of Chinese Hacktivism returned?

https://www.digitalshadows.com/blog-and-research/honker-union-has-the-grandfather-of-chinese-hacktivism-returned

Actors/Campaigns:
Honker_union (motivation: hacktivism)
Green_army (motivation: hacktivism)

Industry:
Education, Government

Geo:
Japan, Chinese, Indonesia, Taiwan, China, Japanese

Softs:
tiktok, weibo, wechat

Platforms:
intel
#ParsedReport
19-08-2022

Suspected Iranian Actor Targeting Israeli Shipping, Healthcare, Government and Energy Sectors

https://www.mandiant.com/resources/blog/suspected-iranian-actor-targeting-israeli-shipping

Actors/Campaigns:
Unc3890 (motivation: cyber_espionage)
Fox_kitten
Cleaver

Threats:
Watering_hole_technique
Sugarush
Sugardump
Metasploit_tool
Northstar_tool
Credential_harvesting_technique
Unicorn

Industry:
Maritime, Energy, Transport, Aerospace, Government, Healthcare

Geo:
Iran, Iranian, Israeli, Israel

IOCs:
Domain: 9
Url: 1
Hash: 1

Softs:
instagram

Algorithms:
zip
#ParsedReport
19-08-2022

Back in Black: Unlocking a LockBit 3.0 Ransomware Attack. Summary

https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack

Threats:
Lockbit
Socgholish_loader
Cobalt_strike
Beacon
Bloodhound_tool
Seatbelt_tool
Conti
Megasync_tool

TTPs:
Tactics: 9
Technics: 15

IOCs:
Path: 12
File: 5
Email: 1
Domain: 1
IP: 1
Hash: 1

Softs:
psexec, windows defender

Algorithms:
zip

Links:
https://github.com/GhostPack/Seatbelt
#ParsedReport
22-08-2022

LockBit Allegedly DDoSed After Leaking Entrusts Data

https://socradar.io/lockbit-is-allegedly-ddosed-after-leaking-entrust-data

Actors/Campaigns:
Blackmatter

Threats:
Lockbit
Sova
Process_injection_technique

Industry:
Financial

Geo:
China, Taiwan

TTPs:
Tactics: 2
Technics: 9

IOCs:
Hash: 13

Platforms:
apple
#ParsedReport
#technique
22-08-2022

Is Tox The New C&C Method For Coinminers?

https://www.uptycs.com/blog/is-tox-the-new-cc-method-for-coinminers

Threats:
Helloxd

IOCs:
Hash: 1

Softs:
curl, crontab

Functions:
main

Links:
https://github.com/irungentoo/toxcore/blob/master/docs/updates/DHT.md
https://github.com/TokTok/c-toxcore
#ParsedReport
22-08-2022

Escanor Malware delivered in Weaponized Microsoft Office Documents

https://resecurity.com/blog/article/escanor-malware-delivered-in-weaponized-microsoft-office-documents

Actors/Campaigns:
Aridviper

Threats:
Escanor_rat
Venomrat
Pandora

Geo:
Israeli, Bahrain, Canada, Kuwait, Singapore, Asia, Egypt, Israel, Mexico

IOCs:
Domain: 1

Softs:
microsoft office, android, telegram
#ParsedReport
22-08-2022

XCSSET Malware Update \| macOS Threat Actors Prepare for Life Without Python

https://www.sentinelone.com/blog/xcsset-malware-update-macos-threat-actors-prepare-for-life-without-python

Threats:
Xcsset
Xcssset
Applescript

Industry:
Financial

Geo:
Chinese, China

IOCs:
Hash: 37
File: 7
Domain: 8

Softs:
chrome, macos, opera, telegram, wechat

Functions:
check_loop, runme

Languages:
python

Platforms:
apple

Links:
https://github.com/ydkhatri/mac\_apt/blob/master/plugins/notes.py
https://github.com/neurobin/shc
#ParsedReport
22-08-2022

Anatomy of a Solidbit Ransomware Attack

https://www.varonis.com/blog/anatomy-of-a-solidbit-ransomware-attack

Threats:
Solidbit
Lockbit
Yashma
Deepsea_obfuscator_tool
Chaos
Redline_stealer
Teamviewer_tool

Industry:
Financial

Geo:
Israeli, Syria

TTPs:
Tactics: 2
Technics: 0

IOCs:
File: 14

Softs:
telegram, windows service, windows registry, defwatch, microsoft visual studio

Algorithms:
aes-256, cbc

Platforms:
x86, intel
#ParsedReport
23-08-2022

New Iranian APT data extraction tool

https://blog.google/threat-analysis-group/new-iranian-apt-data-extraction-tool

Actors/Campaigns:
Cleaver (motivation: government_sponsored)

Threats:
Hyperscrape_tool
Pwcs_tool

Industry:
Government

Geo:
Iran, Iranian

IOCs:
File: 14
IP: 2
Hash: 9
Path: 2

Softs:
microsoft outlook, telegram

Algorithms:
crc, gzip, base64

Functions:
ManageTakeOut, IsThereAnyEMail

Languages:
php
#ParsedReport
23-08-2022

Dissecting IBAN Clipper

https://blog.cyble.com/2022/08/22/dissecting-iban-clipper

Threats:
Iban_clipper
Beacon

Industry:
Financial

Geo:
Singapore, India, Australia, Georgia, Dubai

TTPs:
Tactics: 6
Technics: 9

IOCs:
File: 2
Hash: 1

Softs:
microsoft store

Functions:
getexecutingassembly
#ParsedReport
23-08-2022

THREAT ALERT: HavanaCrypt Ransomware Masquerading as Google Update

https://www.cybereason.com/blog/threat-alert-havanacrypt-ransomware-masquerading-as-google-update

Threats:
Havanacrypt

Industry:
Government

TTPs:
Tactics: 1
Technics: 0

IOCs:
Hash: 2
File: 7
IP: 1
Path: 1

Softs:
thebat, keepass, onenote, defwatch, dbsnmp, windows defender, microsoft word, thebat64, sqlagent, vssadmin, mssql, google chrome, powerpnt, wordpad, sqlbrowser, encsvc

Algorithms:
aes

Languages:
php

Links:
https://github.com/obfuscar/obfuscar