#ParsedReport
25-08-2022
BleachGap Revamped
https://labs.k7computing.com/index.php/bleachgap-revamped
Threats:
Bleachgap
IOCs:
File: 2
Path: 1
Hash: 1
Softs:
discord
Algorithms:
xor, aes
Functions:
FindNextFileW, ReadFile, FindFirstFileExW, the
25-08-2022
BleachGap Revamped
https://labs.k7computing.com/index.php/bleachgap-revamped
Threats:
Bleachgap
IOCs:
File: 2
Path: 1
Hash: 1
Softs:
discord
Algorithms:
xor, aes
Functions:
FindNextFileW, ReadFile, FindFirstFileExW, the
K7 Labs
BleachGap Revamped - K7 Labs
BleachGap ransomware was first reported in Feb 2021 by a researcher named Petrovic on Twitter. This ransomware variant that we […]
#ParsedReport
25-08-2022
The Dark Side of Bumblebee Malware Loader
https://www.deepinstinct.com/blog/the-dark-side-of-bumblebee-malware-loader
Actors/Campaigns:
Exotic_lily
Threats:
Bumblebee
Conti
Diavol
Ramnit
Trickbot
Quantum_locker
Geo:
Usa
IOCs:
File: 3
Hash: 5
Algorithms:
gzip
Functions:
main
Links:
25-08-2022
The Dark Side of Bumblebee Malware Loader
https://www.deepinstinct.com/blog/the-dark-side-of-bumblebee-malware-loader
Actors/Campaigns:
Exotic_lily
Threats:
Bumblebee
Conti
Diavol
Ramnit
Trickbot
Quantum_locker
Geo:
Usa
IOCs:
File: 3
Hash: 5
Algorithms:
gzip
Functions:
main
Links:
https://github.com/LordNoteworthy/al-khaserDeep Instinct
Bumblebee Malware: Deep Instinct Prevents Attack Pre-Execution | Deep Instinct
Deep Instinct prevented a complicated Bumblebee malware loader attack pre-execution. Read more about the Bumblebee attack and how Deep Instinct can help your business.
#ParsedReport
25-08-2022
BlueSky Ransomware \| AD Lateral Movement, Evasion and Fast Encryption Puts Threat on the Radar
https://www.sentinelone.com/blog/bluesky-ransomware-ad-lateral-movement-evasion-and-fast-encryption-puts-threat-on-the-radar
Actors/Campaigns:
Bluesky
Threats:
Cobalt_strike
Brc4_tool
Juicypotato_tool
Industry:
Ics
CVEs:
CVE-2022-21882 [Vulners]
Vulners: Score: 7.2, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2019 (-)
- microsoft windows 10 (1809, 1809, 1809, 1909, 1909, 1909, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 21h2, 21h2, 21h2)
- microsoft windows 11 (-, -)
- microsoft windows server (20h2, 2022)
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
IOCs:
Domain: 2
Url: 15
File: 1
Path: 1
Hash: 18
Softs:
active directory
Functions:
GetLogicalDriveStringsW, NtSetInformationThread, NtQueryInformationProcess, TerminateProcess
25-08-2022
BlueSky Ransomware \| AD Lateral Movement, Evasion and Fast Encryption Puts Threat on the Radar
https://www.sentinelone.com/blog/bluesky-ransomware-ad-lateral-movement-evasion-and-fast-encryption-puts-threat-on-the-radar
Actors/Campaigns:
Bluesky
Threats:
Cobalt_strike
Brc4_tool
Juicypotato_tool
Industry:
Ics
CVEs:
CVE-2022-21882 [Vulners]
Vulners: Score: 7.2, CVSS: 3.8,
Vulners: Exploitation: True
X-Force: Risk: 7
X-Force: Patch: Official fix
Soft:
- microsoft windows server 2019 (-)
- microsoft windows 10 (1809, 1809, 1809, 1909, 1909, 1909, 20h2, 20h2, 20h2, 21h1, 21h1, 21h1, 21h2, 21h2, 21h2)
- microsoft windows 11 (-, -)
- microsoft windows server (20h2, 2022)
CVE-2021-1732 [Vulners]
Vulners: Score: 4.6, CVSS: 4.3,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (20h2, 1803, 1809, 1909, 2004)
- microsoft windows server 2016 (20h2, 1909, 2004)
- microsoft windows server 2019 (-)
CVE-2020-0796 [Vulners]
Vulners: Score: 7.5, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (1903, 1909)
- microsoft windows server 2016 (1903, 1909)
TTPs:
IOCs:
Domain: 2
Url: 15
File: 1
Path: 1
Hash: 18
Softs:
active directory
Functions:
GetLogicalDriveStringsW, NtSetInformationThread, NtQueryInformationProcess, TerminateProcess
SentinelOne
BlueSky Ransomware | AD Lateral Movement, Evasion and Fast Encryption Put Threat on the Radar
This new ransomware threat uses multi-threaded encryption and exploits known Windows vulnerabilities to infect hosts across Active Directory.
#ParsedReport
25-08-2022
MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations
https://www.microsoft.com/security/blog/2022/08/25/mercury-leveraging-log4j-2-vulnerabilities-in-unpatched-systems-to-target-israeli-organizations
Actors/Campaigns:
Muddywater
Threats:
Mercury_tool
Log4shell_vuln
Screenconnect_tool
Venom_proxy_tool
Ligolo
Mimikatz
Remcom_tool
Ehorus_tool
Lsadump_tool
Dumplsass_tool
Geo:
Iran, Irans, Iranian, Israel, Israeli
CVEs:
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 1.8,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel oneapi (-)
- intel audio development kit (-)
- intel datacenter manager (-)
- intel system debugger (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 4
Path: 1
Url: 1
IP: 2
Hash: 11
Softs:
apache log4j, microsoft 365 defender, microsoft sql, microsoft defender
Languages:
php
Links:
25-08-2022
MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations
https://www.microsoft.com/security/blog/2022/08/25/mercury-leveraging-log4j-2-vulnerabilities-in-unpatched-systems-to-target-israeli-organizations
Actors/Campaigns:
Muddywater
Threats:
Mercury_tool
Log4shell_vuln
Screenconnect_tool
Venom_proxy_tool
Ligolo
Mimikatz
Remcom_tool
Ehorus_tool
Lsadump_tool
Dumplsass_tool
Geo:
Iran, Irans, Iranian, Israel, Israeli
CVEs:
CVE-2021-45046 [Vulners]
Vulners: Score: 5.1, CVSS: 1.8,
Vulners: Exploitation: True
X-Force: Risk: 9
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.12.2, <2.16.0)
- intel oneapi (-)
- intel audio development kit (-)
- intel datacenter manager (-)
- intel system debugger (-)
have more...
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 4
Path: 1
Url: 1
IP: 2
Hash: 11
Softs:
apache log4j, microsoft 365 defender, microsoft sql, microsoft defender
Languages:
php
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/PotentialMercury\_Webshell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/powershell\_mercury.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Mercury\_Log4j\_August2022.yamlMicrosoft News
MERCURY leveraging Log4j 2 vulnerabilities in unpatched systems to target Israeli organizations
Microsoft detected an Iran-based threat actor the Microsoft Threat Intelligence Center (MSTIC) tracks as MERCURY leveraging exploitation of Log4j 2 vulnerabilities in SysAid applications against organizations located in Israel.
#ParsedReport
25-08-2022
SEARCH. Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels
https://www.proofpoint.com/us/newsroom/news/cybercrime-group-ta558-ramps-email-attacks-against-hotels
Actors/Campaigns:
Ta558 (motivation: cyber_criminal, information_theft)
Threats:
Revenge_rat
Loda_rat
Vjw0rm
Asyncrat_rat
Industry:
Financial, Healthcare
Geo:
America, Spanish, Portuguese
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
Languages:
javascript, autoit
25-08-2022
SEARCH. Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels
https://www.proofpoint.com/us/newsroom/news/cybercrime-group-ta558-ramps-email-attacks-against-hotels
Actors/Campaigns:
Ta558 (motivation: cyber_criminal, information_theft)
Threats:
Revenge_rat
Loda_rat
Vjw0rm
Asyncrat_rat
Industry:
Financial, Healthcare
Geo:
America, Spanish, Portuguese
CVEs:
CVE-2017-11882 [Vulners]
Vulners: Score: 9.3, CVSS: 4.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft office (2013, 2010, 2016, 2007)
Languages:
javascript, autoit
Decipher
Cybercrime Group TA558 Ramps Up Email Attacks Against Hotels
The small cybercrime actor is upping its operational tempo in 2022 against hospitality organizations like hotels and travel companies.
#ParsedReport
25-08-2022
Roasting 0ktapus: The phishing campaign going after Okta identity credentials
https://blog.group-ib.com/0ktapus
Actors/Campaigns:
0ktapus (motivation: cyber_criminal)
Threats:
Dharma
Anydesk_tool
Blackcat
Industry:
Financial, Education, Telco
Geo:
Canada, Usa, Singapore
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Domain: 168
IP: 56
Softs:
django, telegram
25-08-2022
Roasting 0ktapus: The phishing campaign going after Okta identity credentials
https://blog.group-ib.com/0ktapus
Actors/Campaigns:
0ktapus (motivation: cyber_criminal)
Threats:
Dharma
Anydesk_tool
Blackcat
Industry:
Financial, Education, Telco
Geo:
Canada, Usa, Singapore
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 2
Domain: 168
IP: 56
Softs:
django, telegram
Group-IB
Roasting 0ktapus: The phishing campaign going after Okta identity credentials
All about the phishing campaign that compromised over 130 organizations and the resources involved.
#ParsedReport
22-08-2022
Raven Storm, the Multi-Threading Tool Employed by Hacktivists for DDoS Attacks
https://cloudsek.com/threatintelligence/raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks
22-08-2022
Raven Storm, the Multi-Threading Tool Employed by Hacktivists for DDoS Attacks
https://cloudsek.com/threatintelligence/raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks/?utm_source=rss&utm_medium=rss&utm_campaign=raven-storm-the-multi-threading-tool-employed-by-hacktivists-for-ddos-attacks
Cloudsek
Raven Storm, the Multi-Threading Tool Employed by Hacktivists for DDoS Attacks | Threat Intelligence | CloudSEK
CloudSEK’s contextual AI digital risk platform XVigil discovered a post by the Mysterious Team announcing the use of the Raven Storm tool DDoS attacks. The tool uses multi-threading for sending multiple packets at a single moment of time and getting the target…
#ParsedReport
25-08-2022
Scammers Impersonate Electricity Board Officials to Gain Device Access & Exfiltrate Funds
https://cloudsek.com/threatintelligence/scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds/?utm_source=rss&utm_medium=rss&utm_campaign=scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds
Industry:
Financial
25-08-2022
Scammers Impersonate Electricity Board Officials to Gain Device Access & Exfiltrate Funds
https://cloudsek.com/threatintelligence/scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds/?utm_source=rss&utm_medium=rss&utm_campaign=scammers-impersonate-electricity-board-officials-to-gain-device-access-exfiltrate-funds
Industry:
Financial
CloudSEK - Digital Risk Management Enterprise | Artificial Intelligence based Cybersecurity
Scammers Impersonate Electricity Board Officials to Gain Device Access & Exfiltrate Funds - CloudSEK
We discovered a social engineering campaign launched by threat actors impersonating the official employees of KSEB (Kerala State Electricity Board).The campaign was carried out via text messages which requested the customers to connect with a particular number…
#ParsedReport
25-08-2022
Moisha Ransomware In Action
https://blog.cyble.com/2022/08/25/moisha-ransomware-in-action
Threats:
Moisha
Industry:
Financial
Geo:
Georgia, India, Australia, Singapore, Dubai
TTPs:
Tactics: 3
Technics: 12
IOCs:
File: 2
Hash: 1
Softs:
vssadmin, microsoft defender
Algorithms:
base64, aes
Functions:
RecursePath, GetAllShares, OnItemArrived, GetComputerShares, NetWkstaGetInfo, WriteToFileThreadSafe, EnumNetShares, encryptor
25-08-2022
Moisha Ransomware In Action
https://blog.cyble.com/2022/08/25/moisha-ransomware-in-action
Threats:
Moisha
Industry:
Financial
Geo:
Georgia, India, Australia, Singapore, Dubai
TTPs:
Tactics: 3
Technics: 12
IOCs:
File: 2
Hash: 1
Softs:
vssadmin, microsoft defender
Algorithms:
base64, aes
Functions:
RecursePath, GetAllShares, OnItemArrived, GetComputerShares, NetWkstaGetInfo, WriteToFileThreadSafe, EnumNetShares, encryptor
Cyble
Moisha Ransomware In Action
Cyble analyzes Moisha Ransomware, a .Net-based ransomware that uses double-extortion techniques to force victims into paying ransom.
#ParsedReport
25-08-2022
Making victims pay, infostealer malwares mimick pirated-software download sites
https://www.zscaler.com/blogs/security-research/making-victims-pay-infostealer-malwares-mimick-pirated-software-download
Threats:
Redline_stealer
Recordbreaker_stealer
Themida_tool
Vmprotect_tool
Mpress_tool
Industry:
Financial
IOCs:
File: 3
Coin: 3
IP: 39
Domain: 124
Softs:
coin98, iconex, liquality, keplr, discord, solflare, cloverwallet, binancechain, coinbase, microsoft office, xdefi, polymeshwallet, tronlink, guildwallet, aurowallet, cyanowallet, rabby, waveskeeper, terrastation, neoline, sollet, tezbox, saturnwallet
Algorithms:
zip
Functions:
FindWindow
25-08-2022
Making victims pay, infostealer malwares mimick pirated-software download sites
https://www.zscaler.com/blogs/security-research/making-victims-pay-infostealer-malwares-mimick-pirated-software-download
Threats:
Redline_stealer
Recordbreaker_stealer
Themida_tool
Vmprotect_tool
Mpress_tool
Industry:
Financial
IOCs:
File: 3
Coin: 3
IP: 39
Domain: 124
Softs:
coin98, iconex, liquality, keplr, discord, solflare, cloverwallet, binancechain, coinbase, microsoft office, xdefi, polymeshwallet, tronlink, guildwallet, aurowallet, cyanowallet, rabby, waveskeeper, terrastation, neoline, sollet, tezbox, saturnwallet
Algorithms:
zip
Functions:
FindWindow
Zscaler
Making victims pay, infostealer malwares mimick pirated-software download sites | Zscaler
Zscaler ThreatLabz researchers discovered ongoing threat campaigns distributing info-stealer malware by targeting victims trying to download pirated software
#ParsedReport
25-08-2022
Timeline & TTPs of TeamTNT Cybercrime Group
https://cloudsek.com/threatintelligence/timeline-ttps-of-teamtnt-cybercrime-group/?utm_source=rss&utm_medium=rss&utm_campaign=timeline-ttps-of-teamtnt-cybercrime-group
Actors/Campaigns:
Teamtnt
Chimaera
Wayback
Threats:
Credential_stealing_technique
Hildegard
Pnscan_tool
Tsunami_botnet
Masscan_tool
Zgrab_scanner_tool
Diamorphine_rootkit
Mimipy
Mimipenguin_tool
Lazagne
Xmrig_miner
Upx_tool
Cetus
Geo:
Asian, German, Chinese, Germany, Deutschland
CVEs:
CVE-2019-5736 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.7
X-Force: Patch: Official fix
Soft:
- docker (<18.09.2)
- linuxfoundation runc (le0.1.1, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0)
- redhat container development kit (3.7)
- redhat openshift (3.4, 3.5, 3.6, 3.7)
- redhat enterprise linux (8.0)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
Url: 1
Hash: 29
Domain: 2
Email: 1
File: 2
IP: 7
Softs:
unix, postgresql, curl, redis, ubuntu, docker
Links:
25-08-2022
Timeline & TTPs of TeamTNT Cybercrime Group
https://cloudsek.com/threatintelligence/timeline-ttps-of-teamtnt-cybercrime-group/?utm_source=rss&utm_medium=rss&utm_campaign=timeline-ttps-of-teamtnt-cybercrime-group
Actors/Campaigns:
Teamtnt
Chimaera
Wayback
Threats:
Credential_stealing_technique
Hildegard
Pnscan_tool
Tsunami_botnet
Masscan_tool
Zgrab_scanner_tool
Diamorphine_rootkit
Mimipy
Mimipenguin_tool
Lazagne
Xmrig_miner
Upx_tool
Cetus
Geo:
Asian, German, Chinese, Germany, Deutschland
CVEs:
CVE-2019-5736 [Vulners]
Vulners: Score: 9.3, CVSS: 4.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.7
X-Force: Patch: Official fix
Soft:
- docker (<18.09.2)
- linuxfoundation runc (le0.1.1, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0, 1.0.0)
- redhat container development kit (3.7)
- redhat openshift (3.4, 3.5, 3.6, 3.7)
- redhat enterprise linux (8.0)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
Url: 1
Hash: 29
Domain: 2
Email: 1
File: 2
IP: 7
Softs:
unix, postgresql, curl, redis, ubuntu, docker
Links:
https://github.com/zmap/zgrab2https://github.com/AlessandroZ/LaZagnehttps://github.com/n1nj4sec/mimipyhttps://github.com/guitmz/ezurihttps://github.com/PercussiveElbow/docker-escape-toolhttps://github.com/Bendr0id/xmrigCChttps://github.com/isdrupter/ziggystartuxhttps://github.com/robertdavidgraham/masscanhttps://github.com/r3vn/punk.pyhttps://github.com/upx/upxhttps://github.com/weaveworks/scopehttps://github.com/huntergregal/mimipenguinhttps://github.com/HildeTeamTNThttps://github.com/ptrrkssn/pnscanhttps://github.com/brompwnie/botbhttps://github.com/IncSTK/ratholehttps://github.com/m0nad/Diamorphinehttps://github.com/gianlucaborello/libprocesshiderhttps://github.com/inguardians/peiratesCloudsek
Timeline & TTPs of TeamTNT Cybercrime Group | Threat Intelligence | CloudSEK
The threat actor group, TeamTNT, compromised multiple cloud instances and containerized environments.The target list includes Docker, Redis server, AWS, and Kubernetes.
#ParsedReport
25-08-2022
New Golang Ransomware Agenda Customizes Attacks
https://www.trendmicro.com/en_us/research/22/h/new-golang-ransomware-agenda-customizes-attacks.html
Actors/Campaigns:
Qilin
Threats:
Mauicrypt
Blackbasta
Revil
Process_injection_technique
Trojan.win64.agenda.svt
Industry:
Healthcare, Financial, Education
Geo:
Africa, Asia, Thailand, Indonesia
IOCs:
Path: 2
File: 31
Registry: 2
Softs:
ntrtscan, bcdedit, active directory, vssadmin, winlogon
Algorithms:
rsa-2048, aes-256
Functions:
rand_read, CreateProcessAsUserW
Languages:
golang
25-08-2022
New Golang Ransomware Agenda Customizes Attacks
https://www.trendmicro.com/en_us/research/22/h/new-golang-ransomware-agenda-customizes-attacks.html
Actors/Campaigns:
Qilin
Threats:
Mauicrypt
Blackbasta
Revil
Process_injection_technique
Trojan.win64.agenda.svt
Industry:
Healthcare, Financial, Education
Geo:
Africa, Asia, Thailand, Indonesia
IOCs:
Path: 2
File: 31
Registry: 2
Softs:
ntrtscan, bcdedit, active directory, vssadmin, winlogon
Algorithms:
rsa-2048, aes-256
Functions:
rand_read, CreateProcessAsUserW
Languages:
golang
Trend Micro
New Golang Ransomware Agenda Customizes Attacks
A new piece of ransomware written in the Go language has been targeting healthcare and education enterprises in Asia and Africa. This ransomware is called Agenda and is customized per victim.
#ParsedReport
25-08-2022
Luca Stealer Targets Password Managers and Cryptocurrency Wallets
https://blogs.blackberry.com/en/2022/08/luca-stealer-targets-password-managers-and-cryptocurrency-wallets
Threats:
Luca_stealer
Screengrab
Zingo_stealer
Industry:
E-commerce, Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 5
Hash: 2
Softs:
coccoc, onekey, iconex, google chrome, coinomi, byone, jaxx, 7star, coin98, chrome, microsoft edge, coowoo, macos, sleipnir, binancechain, torch, discord, vivaldi, telegram, bitwarden, zcash, steem, liebao, kometa, orbitum, lastpass, terra, opera, tronlink, chedot, brave-browser, sollet, neoline, keychain, amigo, dappplay, keplr, chromium, iwallet, wombat, bitclip, electrum, tezbox, centbrowser
Algorithms:
zip
Languages:
rust
YARA: Found
25-08-2022
Luca Stealer Targets Password Managers and Cryptocurrency Wallets
https://blogs.blackberry.com/en/2022/08/luca-stealer-targets-password-managers-and-cryptocurrency-wallets
Threats:
Luca_stealer
Screengrab
Zingo_stealer
Industry:
E-commerce, Financial
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 5
Hash: 2
Softs:
coccoc, onekey, iconex, google chrome, coinomi, byone, jaxx, 7star, coin98, chrome, microsoft edge, coowoo, macos, sleipnir, binancechain, torch, discord, vivaldi, telegram, bitwarden, zcash, steem, liebao, kometa, orbitum, lastpass, terra, opera, tronlink, chedot, brave-browser, sollet, neoline, keychain, amigo, dappplay, keplr, chromium, iwallet, wombat, bitclip, electrum, tezbox, centbrowser
Algorithms:
zip
Languages:
rust
YARA: Found
BlackBerry
Luca Stealer Targets Password Managers and Cryptocurrency Wallets
Luca Stealer contains much of the functionality expected from a typical infostealer, with an added focus on crypto-wallets and password management software. This malware is likely to continue to see a steady rise in use, as more and more threat actors get…
#ParsedReport
26-08-2022
Dark Web Profile: BlackCat (ALPHV)
https://socradar.io/dark-web-profile-blackcat-alphv
Actors/Campaigns:
Blackcat
Darkside
Threats:
Blackcat
Revil
Lockbit
Industry:
Aerospace, Financial, E-commerce
Geo:
Austrian, Spain, Kuwait, Russian, Thailand, America
IOCs:
Hash: 21
Softs:
lastpass
Languages:
rust
26-08-2022
Dark Web Profile: BlackCat (ALPHV)
https://socradar.io/dark-web-profile-blackcat-alphv
Actors/Campaigns:
Blackcat
Darkside
Threats:
Blackcat
Revil
Lockbit
Industry:
Aerospace, Financial, E-commerce
Geo:
Austrian, Spain, Kuwait, Russian, Thailand, America
IOCs:
Hash: 21
Softs:
lastpass
Languages:
rust
SOCRadar® Cyber Intelligence Inc.
Dark Web Profile: BlackCat (ALPHV) - SOCRadar® Cyber Intelligence Inc.
December 19, 2023: As we speculated recently, law enforcement agencies have successfully taken control of the official site of the ALPHV.** Read more under
#ParsedReport
26-08-2022
Twilio and MailChimp Attackers Hit 130 Organizations with Okta Phishing Campaign
https://socradar.io/twilio-and-mailchimp-attackers-hit-130-organizations-with-okta-phishing-campaign
Actors/Campaigns:
0ktapus
Industry:
Education, Retail, Telco, Logistic, E-commerce, Financial
Geo:
Usa, Australia, India, Canada, France, Spain, Sweden
IOCs:
Domain: 168
Softs:
coinbase, slack, telegram, lastpass
26-08-2022
Twilio and MailChimp Attackers Hit 130 Organizations with Okta Phishing Campaign
https://socradar.io/twilio-and-mailchimp-attackers-hit-130-organizations-with-okta-phishing-campaign
Actors/Campaigns:
0ktapus
Industry:
Education, Retail, Telco, Logistic, E-commerce, Financial
Geo:
Usa, Australia, India, Canada, France, Spain, Sweden
IOCs:
Domain: 168
Softs:
coinbase, slack, telegram, lastpass
SOCRadar® Cyber Intelligence Inc.
Twilio and MailChimp Attackers Hit 130 Organizations with Okta Phishing Campaign
A larger phishing campaign that targeted 136 organizations and resulted in the theft of 9,931 account login credentials has been linked to...
#ParsedReport
26-08-2022
Threat Assessment: Black Basta Ransomware
https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware
Threats:
Blackbasta
Conti
Qakbot
Megacortex
Prolock
Doppelpaymer
Egregor
Antidebugging_technique
Mimikatz
Teamviewer_tool
Cobalt_strike
Industry:
E-commerce, Energy, Financial, Foodtech, Government, Transport
Geo:
Japanese, Australia, Germany, Japan, France, Canada, Switzerland, Emea, Netherlands, America, Italy, Apac
TTPs:
Tactics: 12
Technics: 28
IOCs:
File: 8
Path: 2
Softs:
windows service, esxi, psexec, windows defender, bcdedit, vssadmin
Algorithms:
zip , chacha20, rsa-4096
Functions:
GetComputerName, North
26-08-2022
Threat Assessment: Black Basta Ransomware
https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware
Threats:
Blackbasta
Conti
Qakbot
Megacortex
Prolock
Doppelpaymer
Egregor
Antidebugging_technique
Mimikatz
Teamviewer_tool
Cobalt_strike
Industry:
E-commerce, Energy, Financial, Foodtech, Government, Transport
Geo:
Japanese, Australia, Germany, Japan, France, Canada, Switzerland, Emea, Netherlands, America, Italy, Apac
TTPs:
Tactics: 12
Technics: 28
IOCs:
File: 8
Path: 2
Softs:
windows service, esxi, psexec, windows defender, bcdedit, vssadmin
Algorithms:
zip , chacha20, rsa-4096
Functions:
GetComputerName, North
Unit 42
Threat Assessment: Black Basta Ransomware
Black Basta is ransomware as a service (RaaS) that first emerged in April 2022. However, evidence suggests that it has been in development since February. The Black Basta operator(s) use the double extortion technique, meaning that in addition to encrypting…
#ParsedReport
26-08-2022
ISaPWN research on the security of ISaGRAF Runtime
https://ics-cert.kaspersky.com/publications/reports/2022/05/23/isapwn-research-on-the-security-of-isagraf-runtime
Industry:
Energy, Ics, Transport
CVEs:
CVE-2020-25180 [Vulners]
Vulners: Score: 4.3, CVSS: 3.1,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25182 [Vulners]
Vulners: Score: 4.6, CVSS: 6.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.7
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25176 [Vulners]
Vulners: Score: 9.3, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
IOCs:
File: 6
Algorithms:
crc
Languages:
python
26-08-2022
ISaPWN research on the security of ISaGRAF Runtime
https://ics-cert.kaspersky.com/publications/reports/2022/05/23/isapwn-research-on-the-security-of-isagraf-runtime
Industry:
Energy, Ics, Transport
CVEs:
CVE-2020-25180 [Vulners]
Vulners: Score: 4.3, CVSS: 3.1,
Vulners: Exploitation: Unknown
X-Force: Risk: Unknown
X-Force: Patch: Unknown
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25182 [Vulners]
Vulners: Score: 4.6, CVSS: 6.7,
Vulners: Exploitation: Unknown
X-Force: Risk: 6.7
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
CVE-2020-25176 [Vulners]
Vulners: Score: 9.3, CVSS: 5.3,
Vulners: Exploitation: Unknown
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- schneider-electric easergy t300 firmware (le2.7.1)
- schneider-electric easergy c5 firmware (<1.1.0)
- schneider-electric micom c264 firmware (<d6.1)
- schneider-electric pacis gtw firmware (5.1, 5.2, 6.1, 6.3, 6.3)
- schneider-electric saitel dp firmware (le11.06.21)
have more...
IOCs:
File: 6
Algorithms:
crc
Languages:
python
Kaspersky ICS CERT | Kaspersky Industrial Control Systems Cyber Emergency Response Team
ISaPWN – research on the security of ISaGRAF Runtime | Kaspersky ICS CERT
This report includes an analysis of the ISaGRAF framework, its architecture, the IXL and SNCP protocols and the description of several vulnerabilities the Kaspersky ICS CERT team had identified.
#ParsedReport
26-08-2022
QBOT Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/qbot-malware-analysis
Threats:
Qakbot
Process_injection_technique
Dll_injection_technique
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 12
IOCs:
File: 31
Path: 2
Registry: 1
IP: 150
Softs:
windows defender
Algorithms:
xor, crc, prng
Functions:
GetString, GetStringAux, WriteProcessMemory, GetApi, CreateProcess
Platforms:
x64, x86
YARA: Found
Links:
26-08-2022
QBOT Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/qbot-malware-analysis
Threats:
Qakbot
Process_injection_technique
Dll_injection_technique
Industry:
Financial, Government
TTPs:
Tactics: 6
Technics: 12
IOCs:
File: 31
Path: 2
Registry: 1
IP: 150
Softs:
windows defender
Algorithms:
xor, crc, prng
Functions:
GetString, GetStringAux, WriteProcessMemory, GetApi, CreateProcess
Platforms:
x64, x86
YARA: Found
Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Qbot.yarwww.elastic.co
QBOT Malware Analysis — Elastic Security Labs
Elastic Security Labs releases a QBOT malware analysis report covering the execution chain. From this research, the team has produced a YARA rule, configuration-extractor, and indicators of compromises (IOCs).
#technique
https://github.com/Markakd/DirtyCred
DirtyCred is a kernel exploitation concept that swaps unprivileged kernel credentials with privileged ones to escalate privilege. Instead of overwriting any critical data fields on kernel heap, DirtyCred abuses the heap memory reuse mechanism to get privileged. Although the concept is simple, it is effective.
https://github.com/Markakd/DirtyCred
DirtyCred is a kernel exploitation concept that swaps unprivileged kernel credentials with privileged ones to escalate privilege. Instead of overwriting any critical data fields on kernel heap, DirtyCred abuses the heap memory reuse mechanism to get privileged. Although the concept is simple, it is effective.
GitHub
GitHub - Markakd/DirtyCred: Kernel exploitation technique
Kernel exploitation technique. Contribute to Markakd/DirtyCred development by creating an account on GitHub.
#technique
https://github.com/KiFilterFiberContext/warbird-hook
On Windows 10 21H2, PatchGuard does not (afaik) verify the integrity of pointers of nt!g_kernelCallbacks, unlike nt!SeCiCallbacks. The callback table contains pointers to an image named ClipSp.sys, which is a signed driver protected by Microsoft Warbird used for licensing checks (called from nt!SPCall2ServerInternal).
The interesting thing about it is that PatchGuard does not verify the integrity of several image sections, including PAGEwx, which the driver contains in order to decrypt and re-encrypt its own code during runtime.
https://github.com/KiFilterFiberContext/warbird-hook
On Windows 10 21H2, PatchGuard does not (afaik) verify the integrity of pointers of nt!g_kernelCallbacks, unlike nt!SeCiCallbacks. The callback table contains pointers to an image named ClipSp.sys, which is a signed driver protected by Microsoft Warbird used for licensing checks (called from nt!SPCall2ServerInternal).
The interesting thing about it is that PatchGuard does not verify the integrity of several image sections, including PAGEwx, which the driver contains in order to decrypt and re-encrypt its own code during runtime.
GitHub
GitHub - KiFilterFiberContext/warbird-hook: Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in…
Using Microsoft Warbird to automatically unpack and execute encrypted shellcode in ClipSp.sys without triggering PatchGuard - KiFilterFiberContext/warbird-hook