#ParsedReport
24-08-2022
Ransomware updates & 1-day exploits
https://securelist.com/ransomware-updates-1-day-exploits/107291
Threats:
Redalert
Monster
Industry:
Financial, Retail
Geo:
Indonesia, Singapore, Bolivia, Apac
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
Softs:
esxi
Algorithms:
aes
Languages:
rust, delphi
YARA: Found
24-08-2022
Ransomware updates & 1-day exploits
https://securelist.com/ransomware-updates-1-day-exploits/107291
Threats:
Redalert
Monster
Industry:
Financial, Retail
Geo:
Indonesia, Singapore, Bolivia, Apac
CVEs:
CVE-2022-24521 [Vulners]
Vulners: Score: 4.6, CVSS: 4.2,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 20h2, 21h1, 21h2, 1607, 1809, 1909)
- microsoft windows 11 (-, -)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
have more...
Softs:
esxi
Algorithms:
aes
Languages:
rust, delphi
YARA: Found
Securelist
Kaspersky crimeware report: new ransomware and 1-day exploits
In this report, we discuss the new multi-platform ransomware RedAlert (aka N13V) and Monster, as well as private 1-day exploits for the CVE-2022-24521 vulnerability.
#ParsedReport
24-08-2022
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
Threats:
Fire_chili_rootkit
Fivesys
Impacket_tool
Industry:
Entertainment
IOCs:
File: 10
Hash: 1
Softs:
psexec, windows installer
Functions:
NtOpenFile, ZwTerminateProcess
Languages:
python
Links:
24-08-2022
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
https://www.trendmicro.com/en_us/research/22/h/ransomware-actor-abuses-genshin-impact-anti-cheat-driver-to-kill-antivirus.html
Threats:
Fire_chili_rootkit
Fivesys
Impacket_tool
Industry:
Entertainment
IOCs:
File: 10
Hash: 1
Softs:
psexec, windows installer
Functions:
NtOpenFile, ZwTerminateProcess
Languages:
python
Links:
https://github.com/kagurazakasanae/Mhyprot2DrvControlhttps://github.com/kkent030315/evil-mhyprot-clihttps://github.com/SecureAuthCorp/impacket/blob/impacket\_0\_10\_0/examples/wmiexec.pyhttps://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.pyhttps://github.com/kkent030315Trend Micro
Ransomware Actor Abuses Genshin Impact Anti-Cheat Driver to Kill Antivirus
We investigate mhyprot2.sys, a vulnerable anti-cheat driver for the popular role-playing game Genshin Impact. The driver is currently being abused by a ransomware actor to kill antivirus processes and services for mass-deploying ransomware.
#ParsedReport
24-08-2022
ASEC (20220815 \~ 20220821). ASEC Weekly Malware Statistics (20220815 \~ 20220821)
https://asec.ahnlab.com/ko/37997
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
Postealer
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
TTPs:
IOCs:
File: 30
Domain: 3
IP: 11
Email: 6
Url: 15
Softs:
discord, nsis installer
Languages:
visual_basic
24-08-2022
ASEC (20220815 \~ 20220821). ASEC Weekly Malware Statistics (20220815 \~ 20220821)
https://asec.ahnlab.com/ko/37997
Threats:
Agent_tesla
Azorult
Formbook
Clipboard_grabbing_technique
Redline_stealer
Beamwinhttp_loader
Postealer
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer
Industry:
Transport, Financial
Geo:
Korea
TTPs:
IOCs:
File: 30
Domain: 3
IP: 11
Email: 6
Url: 15
Softs:
discord, nsis installer
Languages:
visual_basic
ASEC
ASEC 주간 악성코드 통계 (20220815 ~ 20220821) - ASEC
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 8월 15일 월요일부터 8월 21일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 57.8%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 24.2%, 다운로더 13.7%, 랜섬웨어 3.7%, 코인마이너 악성코드가 0.6%로 집계되었다. Top 1 – Agent…
#ParsedReport
24-08-2022
MagicWeb: NOBELIUMs post-compromise trick to authenticate as anyone
https://www.microsoft.com/security/blog/2022/08/24/magicweb-nobeliums-post-compromise-trick-to-authenticate-as-anyone
Actors/Campaigns:
Darkhalo (motivation: information_theft)
Threats:
Magicweb
Foggyweb
Industry:
Government, Ngo
Geo:
Asia
IOCs:
File: 17
Path: 1
Softs:
microsoft defender, active directory, microsoft 365 defender, windows firewall, adfs, azure ad
Functions:
beginprocessclaims, GetClientCertificate, ValidateX509Extensions, begingetclientcertificate, MagicWebs, AddClaims, beginendpointconfiguration, Build, Initialize, ProcessClaims, GetType, MagicWeb, ComputeHash, EndpointConfiguration, beginbuild, OverloadMethod, GetClaims, AddClaim, Add
Links:
24-08-2022
MagicWeb: NOBELIUMs post-compromise trick to authenticate as anyone
https://www.microsoft.com/security/blog/2022/08/24/magicweb-nobeliums-post-compromise-trick-to-authenticate-as-anyone
Actors/Campaigns:
Darkhalo (motivation: information_theft)
Threats:
Magicweb
Foggyweb
Industry:
Government, Ngo
Geo:
Asia
IOCs:
File: 17
Path: 1
Softs:
microsoft defender, active directory, microsoft 365 defender, windows firewall, adfs, azure ad
Functions:
beginprocessclaims, GetClientCertificate, ValidateX509Extensions, begingetclientcertificate, MagicWebs, AddClaims, beginendpointconfiguration, Build, Initialize, ProcessClaims, GetType, MagicWeb, ComputeHash, EndpointConfiguration, beginbuild, OverloadMethod, GetClaims, AddClaim, Add
Links:
https://github.com/Azure/Azure-Sentinel/tree/master/Detections/SecurityEvent/ADFSAbnormalEnhancedKeyUsageAttribute-OID.yamlMicrosoft Security Blog
MagicWeb: NOBELIUM’s post-compromise trick to authenticate as anyone | Microsoft Security Blog
Microsoft security researchers have discovered a post-compromise capability we’re calling MagicWeb, which is used by a threat actor we track as NOBELIUM to maintain persistent access to compromised environments.
#ParsedReport
24-08-2022
The Anatomy of Wiper Malware, Part 2: Third-Party Drivers
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-2
Actors/Campaigns:
Turla
Agrius
Threats:
Sierras
Hermeticwiper
Disttrack
Dustman_wiper
Zerocleare_wiper
Alureon
Apostle
Killdisk
Doublezero
Isaacwiper
Israbye
Meteor_wiper
Ordinypt
Petya
Stonedrill_wiper
Whispergate
Industry:
Petroleum
Geo:
Ukraine, Tokyo
IOCs:
File: 3
Hash: 39
Softs:
windows service
Functions:
IoGetAttachedDeviceReference, WriteFile, SetFilePointer, IoBuildAsynchronousFsdRequest, DeviceIoControl, IoGetDeviceObjectPointer, CreateFile, IoBuildDeviceIoControlRequest
Links:
24-08-2022
The Anatomy of Wiper Malware, Part 2: Third-Party Drivers
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-2
Actors/Campaigns:
Turla
Agrius
Threats:
Sierras
Hermeticwiper
Disttrack
Dustman_wiper
Zerocleare_wiper
Alureon
Apostle
Killdisk
Doublezero
Isaacwiper
Israbye
Meteor_wiper
Ordinypt
Petya
Stonedrill_wiper
Whispergate
Industry:
Petroleum
Geo:
Ukraine, Tokyo
IOCs:
File: 3
Hash: 39
Softs:
windows service
Functions:
IoGetAttachedDeviceReference, WriteFile, SetFilePointer, IoBuildAsynchronousFsdRequest, DeviceIoControl, IoGetDeviceObjectPointer, CreateFile, IoBuildDeviceIoControlRequest
Links:
https://github.com/hfiref0x/TDL#ParsedReport
24-08-2022
The Anatomy of Wiper Malware, Part 1: Common Techniques
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-1
Actors/Campaigns:
Agrius
Threats:
Disttrack
Petya
Ordinypt
Stonedrill
Olympic_destroyer
Dustman
Israbye
Killdisk
Doublezero
Hermeticwiper
Isaacwiper
Whispergate
Apostle
Meteor_wiper
Sierras
Industry:
Government, Energy, Petroleum, Entertainment
Geo:
Israel, Germany, Ukraine, Russia, Tokyo, Israeli, Russian, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 39
File: 1
Algorithms:
prng
Functions:
CreateFile, DeleteFile, FindFirstFile, NtFsControlFile, GetFileSize, FindNextFile, WriteFile
Platforms:
arm
24-08-2022
The Anatomy of Wiper Malware, Part 1: Common Techniques
https://www.crowdstrike.com/blog/the-anatomy-of-wiper-malware-part-1
Actors/Campaigns:
Agrius
Threats:
Disttrack
Petya
Ordinypt
Stonedrill
Olympic_destroyer
Dustman
Israbye
Killdisk
Doublezero
Hermeticwiper
Isaacwiper
Whispergate
Apostle
Meteor_wiper
Sierras
Industry:
Government, Energy, Petroleum, Entertainment
Geo:
Israel, Germany, Ukraine, Russia, Tokyo, Israeli, Russian, Korea
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 39
File: 1
Algorithms:
prng
Functions:
CreateFile, DeleteFile, FindFirstFile, NtFsControlFile, GetFileSize, FindNextFile, WriteFile
Platforms:
arm
#ParsedReport
25-08-2022
Kimsukys GoldDragon cluster and its C2 operations
https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/107258
Actors/Campaigns:
Kimsuky
Threats:
Gold_dragon
Industry:
Education, Government
Geo:
Korea, Asian, Australian, Korean
IOCs:
File: 35
Url: 51
Email: 7
Hash: 64
Domain: 6
Softs:
microsoft office, chrome, .net framework
Algorithms:
base64
Functions:
CreateObject, GetOfficeVersionNumber
Languages:
visual_basic, php
Platforms:
x64, x86
25-08-2022
Kimsukys GoldDragon cluster and its C2 operations
https://securelist.com/kimsukys-golddragon-cluster-and-its-c2-operations/107258
Actors/Campaigns:
Kimsuky
Threats:
Gold_dragon
Industry:
Education, Government
Geo:
Korea, Asian, Australian, Korean
IOCs:
File: 35
Url: 51
Email: 7
Hash: 64
Domain: 6
Softs:
microsoft office, chrome, .net framework
Algorithms:
base64
Functions:
CreateObject, GetOfficeVersionNumber
Languages:
visual_basic, php
Platforms:
x64, x86
Securelist
Kimsuky’s GoldDragon cluster and its C2 operations
Kimsuky is a prolific and active threat actor primarily targeting Korea-related entities. In early 2022, we observed this group was attacking the media and a think-tank in South Korea.
#ParsedReport
25-08-2022
BleachGap Revamped
https://labs.k7computing.com/index.php/bleachgap-revamped
Threats:
Bleachgap
IOCs:
File: 2
Path: 1
Hash: 1
Softs:
discord
Algorithms:
xor, aes
Functions:
FindNextFileW, ReadFile, FindFirstFileExW, the
25-08-2022
BleachGap Revamped
https://labs.k7computing.com/index.php/bleachgap-revamped
Threats:
Bleachgap
IOCs:
File: 2
Path: 1
Hash: 1
Softs:
discord
Algorithms:
xor, aes
Functions:
FindNextFileW, ReadFile, FindFirstFileExW, the
K7 Labs
BleachGap Revamped - K7 Labs
BleachGap ransomware was first reported in Feb 2021 by a researcher named Petrovic on Twitter. This ransomware variant that we […]
#ParsedReport
25-08-2022
The Dark Side of Bumblebee Malware Loader
https://www.deepinstinct.com/blog/the-dark-side-of-bumblebee-malware-loader
Actors/Campaigns:
Exotic_lily
Threats:
Bumblebee
Conti
Diavol
Ramnit
Trickbot
Quantum_locker
Geo:
Usa
IOCs:
File: 3
Hash: 5
Algorithms:
gzip
Functions:
main
Links:
25-08-2022
The Dark Side of Bumblebee Malware Loader
https://www.deepinstinct.com/blog/the-dark-side-of-bumblebee-malware-loader
Actors/Campaigns:
Exotic_lily
Threats:
Bumblebee
Conti
Diavol
Ramnit
Trickbot
Quantum_locker
Geo:
Usa
IOCs:
File: 3
Hash: 5
Algorithms:
gzip
Functions:
main
Links:
https://github.com/LordNoteworthy/al-khaserDeep Instinct
Bumblebee Malware: Deep Instinct Prevents Attack Pre-Execution | Deep Instinct
Deep Instinct prevented a complicated Bumblebee malware loader attack pre-execution. Read more about the Bumblebee attack and how Deep Instinct can help your business.
#ParsedReport
25-08-2022
BlueSky Ransomware \| AD Lateral Movement, Evasion and Fast Encryption Puts Threat on the Radar
https://www.sentinelone.com/blog/bluesky-ransomware-ad-lateral-movement-evasion-and-fast-encryption-puts-threat-on-the-radar
Actors/Campaigns:
Bluesky
Threats:
Cobalt_strike
Brc4_tool
Juicypotato_tool
Industry:
Ics
CVEs:
CVE-2022-21882 [Vulners]
Vulners: Score: 7.2, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2019 (-)
- microsoft windows 10 (1809, 1809, 1809, 1909, 1909, 1909, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 21h2, 21h2, 21h2)
- microsoft windows 11 (-, -)
- microsoft windows server (20h2, 2022)
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
IOCs:
Domain: 2
Url: 15
File: 1
Path: 1
Hash: 18
Softs:
active directory
Functions:
GetLogicalDriveStringsW, NtSetInformationThread, NtQueryInformationProcess, TerminateProcess
25-08-2022
BlueSky Ransomware \| AD Lateral Movement, Evasion and Fast Encryption Puts Threat on the Radar
https://www.sentinelone.com/blog/bluesky-ransomware-ad-lateral-movement-evasion-and-fast-encryption-puts-threat-on-the-radar
Actors/Campaigns:
Bluesky
Threats:
Cobalt_strike
Brc4_tool
Juicypotato_tool
Industry:
Ics
CVEs:
CVE-2022-21882 [Vulners]
Vulners: Score: 7.2, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2019 (-)
- microsoft windows 10 (1809, 1809, 1809, 1909, 1909, 1909, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 21h2, 21h2, 21h2)
- microsoft windows 11 (-, -)
- microsoft windows server (20h2, 2022)
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
IOCs:
Domain: 2
Url: 15
File: 1
Path: 1
Hash: 18
Softs:
active directory
Functions:
GetLogicalDriveStringsW, NtSetInformationThread, NtQueryInformationProcess, TerminateProcess
SentinelOne
BlueSky Ransomware | AD Lateral Movement, Evasion and Fast Encryption Put Threat on the Radar
This new ransomware threat uses multi-threaded encryption and exploits known Windows vulnerabilities to infect hosts across Active Directory.
#ParsedReport
25-08-2022
MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations
https://www.microsoft.com/security/blog/2022/08/25/mercury-leveraging-log4j-2-vulnerabilities-in-unpatched-systems-to-target-israeli-organizations
Actors/Campaigns:
Muddywater
Threats:
Mercury_tool
Log4shell_vuln
Screenconnect_tool
Venom_proxy_tool
Ligolo
Mimikatz
Remcom_tool
Ehorus_tool
Lsadump_tool
Dumplsass_tool
Geo:
Iran, Irans, Iranian, Israel, Israeli
CVEs:
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 1.8,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel oneapi (-)
- intel audio development kit (-)
- intel datacenter manager (-)
- intel system debugger (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 4
Path: 1
Url: 1
IP: 2
Hash: 11
Softs:
apache log4j, microsoft 365 defender, microsoft sql, microsoft defender
Languages:
php
Links:
25-08-2022
MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations
https://www.microsoft.com/security/blog/2022/08/25/mercury-leveraging-log4j-2-vulnerabilities-in-unpatched-systems-to-target-israeli-organizations
Actors/Campaigns:
Muddywater
Threats:
Mercury_tool
Log4shell_vuln
Screenconnect_tool
Venom_proxy_tool
Ligolo
Mimikatz
Remcom_tool
Ehorus_tool
Lsadump_tool
Dumplsass_tool
Geo:
Iran, Irans, Iranian, Israel, Israeli
CVEs:
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 1.8,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel oneapi (-)
- intel audio development kit (-)
- intel datacenter manager (-)
- intel system debugger (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 4
Path: 1
Url: 1
IP: 2
Hash: 11
Softs:
apache log4j, microsoft 365 defender, microsoft sql, microsoft defender
Languages:
php
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/PotentialMercury\_Webshell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/powershell\_mercury.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Mercury\_Log4j\_August2022.yamlMicrosoft News
MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations
Microsoft detected an Iran-based threat actor the Microsoft Threat Intelligence Center (MSTIC) tracks as MERCURY leveraging exploitation of Log4j 2 vulnerabilities in SysAid applications against organizations located in Israel.
#ParsedReport
25-08-2022
SEARCH. Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels
https://www.proofpoint.com/us/newsroom/news/cybercrime-group-ta558-ramps-email-attacks-against-hotels
Actors/Campaigns:
Ta558 (motivation: cyber_criminal, information_theft)
Threats:
Revenge_rat
Loda_rat
Vjw0rm
Asyncrat_rat
Industry:
Financial, Healthcare
Geo:
America, Spanish, Portuguese
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
Languages:
javascript, autoit
25-08-2022
SEARCH. Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels
https://www.proofpoint.com/us/newsroom/news/cybercrime-group-ta558-ramps-email-attacks-against-hotels
Actors/Campaigns:
Ta558 (motivation: cyber_criminal, information_theft)
Threats:
Revenge_rat
Loda_rat
Vjw0rm
Asyncrat_rat
Industry:
Financial, Healthcare
Geo:
America, Spanish, Portuguese
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
Languages:
javascript, autoit
Decipher
Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels
The small cybercrime actor is upping its operational tempo in 2022 against hospitality organizations like hotels and travel companies.
#ParsedReport
25-08-2022
Roasting 0ktapus: The phishing campaign going after Okta identity credentials
https://blog.group-ib.com/0ktapus
Actors/Campaigns:
0ktapus (motivation: cyber_criminal)
Threats:
Dharma
Anydesk_tool
Blackcat
Industry:
Financial, Education, Telco
Geo:
Canada, Usa, Singapore
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Domain: 168
IP: 56
Softs:
django, telegram
25-08-2022
Roasting 0ktapus: The phishing campaign going after Okta identity credentials
https://blog.group-ib.com/0ktapus
Actors/Campaigns:
0ktapus (motivation: cyber_criminal)
Threats:
Dharma
Anydesk_tool
Blackcat
Industry:
Financial, Education, Telco
Geo:
Canada, Usa, Singapore
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Domain: 168
IP: 56
Softs:
django, telegram
Group-IB
Roasting 0ktapus: The phishing campaign going after Okta identity credentials
All about the phishing campaign that compromised over 130 organizations and the resources involved.
#ParsedReport
22-08-2022
Raven Storm, the Multi-Threading Tool Employed by Hacktivists for DDoS Attacks
https://cloudsek.com/threatintelligence/raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks
22-08-2022
Raven Storm, the Multi-Threading Tool Employed by Hacktivists for DDoS Attacks
https://cloudsek.com/threatintelligence/raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks
Cloudsek
Raven Storm, the Multi-Threading Tool Employed by Hacktivists for DDoS Attacks | Threat Intelligence | CloudSEK
CloudSEK’s contextual AI digital risk platform XVigil discovered a post by the Mysterious Team announcing the use of the Raven Storm tool DDoS attacks. The tool uses multi-threading for sending multiple packets at a single moment of time and getting the target…
#ParsedReport
25-08-2022
Scammers Impersonate Electricity Board Officials to Gain Device Access & Exfiltrate Funds
https://cloudsek.com/threatintelligence/scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds/?utm_source=rss&utm_medium=rss&utm_campaign=scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds
Industry:
Financial
25-08-2022
Scammers Impersonate Electricity Board Officials to Gain Device Access & Exfiltrate Funds
https://cloudsek.com/threatintelligence/scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds/?utm_source=rss&utm_medium=rss&utm_campaign=scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds
Industry:
Financial
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
Scammers Impersonate Electricity Board Officials to Gain Device Access & Exfiltrate Funds - CloudSEK
We discovered a social engineering campaign launched by threat actors impersonating the official employees of KSEB (Kerala State Electricity Board).The campaign was carried out via text messages which requested the customers to connect with a particular number…
#ParsedReport
25-08-2022
Moisha Ransomware In Action
https://blog.cyble.com/2022/08/25/moisha-ransomware-in-action
Threats:
Moisha
Industry:
Financial
Geo:
Georgia, India, Australia, Singapore, Dubai
TTPs:
Tactics: 3
Technics: 12
IOCs:
File: 2
Hash: 1
Softs:
vssadmin, microsoft defender
Algorithms:
base64, aes
Functions:
RecursePath, GetAllShares, OnItemArrived, GetComputerShares, NetWkstaGetInfo, WriteToFileThreadSafe, EnumNetShares, encryptor
25-08-2022
Moisha Ransomware In Action
https://blog.cyble.com/2022/08/25/moisha-ransomware-in-action
Threats:
Moisha
Industry:
Financial
Geo:
Georgia, India, Australia, Singapore, Dubai
TTPs:
Tactics: 3
Technics: 12
IOCs:
File: 2
Hash: 1
Softs:
vssadmin, microsoft defender
Algorithms:
base64, aes
Functions:
RecursePath, GetAllShares, OnItemArrived, GetComputerShares, NetWkstaGetInfo, WriteToFileThreadSafe, EnumNetShares, encryptor
Cyble
Moisha Ransomware In Action
Cyble analyzes Moisha Ransomware, a .Net-based ransomware that uses double-extortion techniques to force victims into paying ransom.
#ParsedReport
25-08-2022
Making victims pay, infostealer malwares mimick pirated-software download sites
https://www.zscaler.com/blogs/security-research/making-victims-pay-infostealer-malwares-mimick-pirated-software-download
Threats:
Redline_stealer
Recordbreaker_stealer
Themida_tool
Vmprotect_tool
Mpress_tool
Industry:
Financial
IOCs:
File: 3
Coin: 3
IP: 39
Domain: 124
Softs:
coin98, iconex, liquality, keplr, discord, solflare, cloverwallet, binancechain, coinbase, microsoft office, xdefi, polymeshwallet, tronlink, guildwallet, aurowallet, cyanowallet, rabby, waveskeeper, terrastation, neoline, sollet, tezbox, saturnwallet
Algorithms:
zip
Functions:
FindWindow
25-08-2022
Making victims pay, infostealer malwares mimick pirated-software download sites
https://www.zscaler.com/blogs/security-research/making-victims-pay-infostealer-malwares-mimick-pirated-software-download
Threats:
Redline_stealer
Recordbreaker_stealer
Themida_tool
Vmprotect_tool
Mpress_tool
Industry:
Financial
IOCs:
File: 3
Coin: 3
IP: 39
Domain: 124
Softs:
coin98, iconex, liquality, keplr, discord, solflare, cloverwallet, binancechain, coinbase, microsoft office, xdefi, polymeshwallet, tronlink, guildwallet, aurowallet, cyanowallet, rabby, waveskeeper, terrastation, neoline, sollet, tezbox, saturnwallet
Algorithms:
zip
Functions:
FindWindow
Zscaler
Making victims pay, infostealer malwares mimick pirated-software download sites | Zscaler
Zscaler ThreatLabz researchers discovered ongoing threat campaigns distributing info-stealer malware by targeting victims trying to download pirated software
#ParsedReport
25-08-2022
Timeline & TTPs of TeamTNT Cybercrime Group
https://cloudsek.com/threatintelligence/timeline-ttps-of-teamtnt-cybercrime-group/?utm_source=rss&utm_medium=rss&utm_campaign=timeline-ttps-of-teamtnt-cybercrime-group
Actors/Campaigns:
Teamtnt
Chimaera
Wayback
Threats:
Credential_stealing_technique
Hildegard
Pnscan_tool
Tsunami_botnet
Masscan_tool
Zgrab_scanner_tool
Diamorphine_rootkit
Mimipy
Mimipenguin_tool
Lazagne
Xmrig_miner
Upx_tool
Cetus
Geo:
Asian, German, Chinese, Germany, Deutschland
CVEs:
CVE-2019-5736 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.7
X-Force: Patch: Official fix
Soft:
- docker (<18.09.2)
- linuxfoundation runc (le0.1.1, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0)
- redhat container development kit (3.7)
- redhat openshift (3.4, 3.5, 3.6, 3.7)
- redhat enterprise linux (8.0)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
Url: 1
Hash: 29
Domain: 2
Email: 1
File: 2
IP: 7
Softs:
unix, postgresql, curl, redis, ubuntu, docker
Links:
25-08-2022
Timeline & TTPs of TeamTNT Cybercrime Group
https://cloudsek.com/threatintelligence/timeline-ttps-of-teamtnt-cybercrime-group/?utm_source=rss&utm_medium=rss&utm_campaign=timeline-ttps-of-teamtnt-cybercrime-group
Actors/Campaigns:
Teamtnt
Chimaera
Wayback
Threats:
Credential_stealing_technique
Hildegard
Pnscan_tool
Tsunami_botnet
Masscan_tool
Zgrab_scanner_tool
Diamorphine_rootkit
Mimipy
Mimipenguin_tool
Lazagne
Xmrig_miner
Upx_tool
Cetus
Geo:
Asian, German, Chinese, Germany, Deutschland
CVEs:
CVE-2019-5736 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.7
X-Force: Patch: Official fix
Soft:
- docker (<18.09.2)
- linuxfoundation runc (le0.1.1, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0)
- redhat container development kit (3.7)
- redhat openshift (3.4, 3.5, 3.6, 3.7)
- redhat enterprise linux (8.0)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
Url: 1
Hash: 29
Domain: 2
Email: 1
File: 2
IP: 7
Softs:
unix, postgresql, curl, redis, ubuntu, docker
Links:
https://github.com/zmap/zgrab2https://github.com/AlessandroZ/LaZagnehttps://github.com/n1nj4sec/mimipyhttps://github.com/guitmz/ezurihttps://github.com/PercussiveElbow/docker-escape-toolhttps://github.com/Bendr0id/xmrigCChttps://github.com/isdrupter/ziggystartuxhttps://github.com/robertdavidgraham/masscanhttps://github.com/r3vn/punk.pyhttps://github.com/upx/upxhttps://github.com/weaveworks/scopehttps://github.com/huntergregal/mimipenguinhttps://github.com/HildeTeamTNThttps://github.com/ptrrkssn/pnscanhttps://github.com/brompwnie/botbhttps://github.com/IncSTK/ratholehttps://github.com/m0nad/Diamorphinehttps://github.com/gianlucaborello/libprocesshiderhttps://github.com/inguardians/peiratesCloudsek
Timeline & TTPs of TeamTNT Cybercrime Group | Threat Intelligence | CloudSEK
The threat actor group, TeamTNT, compromised multiple cloud instances and containerized environments.The target list includes Docker, Redis server, AWS, and Kubernetes.
#ParsedReport
25-08-2022
New Golang Ransomware Agenda Customizes Attacks
https://www.trendmicro.com/en_us/research/22/h/new-golang-ransomware-agenda-customizes-attacks.html
Actors/Campaigns:
Qilin
Threats:
Mauicrypt
Blackbasta
Revil
Process_injection_technique
Trojan.win64.agenda.svt
Industry:
Healthcare, Financial, Education
Geo:
Africa, Asia, Thailand, Indonesia
IOCs:
Path: 2
File: 31
Registry: 2
Softs:
ntrtscan, bcdedit, active directory, vssadmin, winlogon
Algorithms:
rsa-2048, aes-256
Functions:
rand_read, CreateProcessAsUserW
Languages:
golang
25-08-2022
New Golang Ransomware Agenda Customizes Attacks
https://www.trendmicro.com/en_us/research/22/h/new-golang-ransomware-agenda-customizes-attacks.html
Actors/Campaigns:
Qilin
Threats:
Mauicrypt
Blackbasta
Revil
Process_injection_technique
Trojan.win64.agenda.svt
Industry:
Healthcare, Financial, Education
Geo:
Africa, Asia, Thailand, Indonesia
IOCs:
Path: 2
File: 31
Registry: 2
Softs:
ntrtscan, bcdedit, active directory, vssadmin, winlogon
Algorithms:
rsa-2048, aes-256
Functions:
rand_read, CreateProcessAsUserW
Languages:
golang
Trend Micro
New Golang Ransomware Agenda Customizes Attacks
A new piece of ransomware written in the Go language has been targeting healthcare and education enterprises in Asia and Africa. This ransomware is called Agenda and is customized per victim.
#ParsedReport
25-08-2022
Luca Stealer Targets Password Managers and Cryptocurrency Wallets
https://blogs.blackberry.com/en/2022/08/luca-stealer-targets-password-managers-and-cryptocurrency-wallets
Threats:
Luca_stealer
Screengrab
Zingo_stealer
Industry:
E-commerce, Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 5
Hash: 2
Softs:
coccoc, onekey, iconex, google chrome, coinomi, byone, jaxx, 7star, coin98, chrome, microsoft edge, coowoo, macos, sleipnir, binancechain, torch, discord, vivaldi, telegram, bitwarden, zcash, steem, liebao, kometa, orbitum, lastpass, terra, opera, tronlink, chedot, brave-browser, sollet, neoline, keychain, amigo, dappplay, keplr, chromium, iwallet, wombat, bitclip, electrum, tezbox, centbrowser
Algorithms:
zip
Languages:
rust
YARA: Found
25-08-2022
Luca Stealer Targets Password Managers and Cryptocurrency Wallets
https://blogs.blackberry.com/en/2022/08/luca-stealer-targets-password-managers-and-cryptocurrency-wallets
Threats:
Luca_stealer
Screengrab
Zingo_stealer
Industry:
E-commerce, Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 5
Hash: 2
Softs:
coccoc, onekey, iconex, google chrome, coinomi, byone, jaxx, 7star, coin98, chrome, microsoft edge, coowoo, macos, sleipnir, binancechain, torch, discord, vivaldi, telegram, bitwarden, zcash, steem, liebao, kometa, orbitum, lastpass, terra, opera, tronlink, chedot, brave-browser, sollet, neoline, keychain, amigo, dappplay, keplr, chromium, iwallet, wombat, bitclip, electrum, tezbox, centbrowser
Algorithms:
zip
Languages:
rust
YARA: Found
BlackBerry
Luca Stealer Targets Password Managers and Cryptocurrency Wallets
Luca Stealer contains much of the functionality expected from a typical infostealer, with an added focus on crypto-wallets and password management software. This malware is likely to continue to see a steady rise in use, as more and more threat actors get…
#ParsedReport
26-08-2022
Dark Web Profile: BlackCat (ALPHV)
https://socradar.io/dark-web-profile-blackcat-alphv
Actors/Campaigns:
Blackcat
Darkside
Threats:
Blackcat
Revil
Lockbit
Industry:
Aerospace, Financial, E-commerce
Geo:
Austrian, Spain, Kuwait, Russian, Thailand, America
IOCs:
Hash: 21
Softs:
lastpass
Languages:
rust
26-08-2022
Dark Web Profile: BlackCat (ALPHV)
https://socradar.io/dark-web-profile-blackcat-alphv
Actors/Campaigns:
Blackcat
Darkside
Threats:
Blackcat
Revil
Lockbit
Industry:
Aerospace, Financial, E-commerce
Geo:
Austrian, Spain, Kuwait, Russian, Thailand, America
IOCs:
Hash: 21
Softs:
lastpass
Languages:
rust
SOCRadar® Cyber Intelligence Inc.
Dark Web Profile: BlackCat (ALPHV) - SOCRadar® Cyber Intelligence Inc.
December 19, 2023: As we speculated recently, law enforcement agencies have successfully taken control of the official site of the ALPHV.** Read more under