#ParsedReport
31-08-2022
First Known Phishing Attack Against PyPi Users
https://checkmarx.com/blog/first-known-phishing-attack-against-pypi-users
Threats:
Typosquatting_technique
IOCs:
Domain: 3
Url: 6
File: 2
Hash: 2
Algorithms:
exhibit, zip
Languages:
python
Links:
31-08-2022
First Known Phishing Attack Against PyPi Users
https://checkmarx.com/blog/first-known-phishing-attack-against-pypi-users
Threats:
Typosquatting_technique
IOCs:
Domain: 3
Url: 6
File: 2
Hash: 2
Algorithms:
exhibit, zip
Languages:
python
Links:
https://gist.github.com/Aviadg/e10696f3a215a577585433b0854ccb31#file-pypi\_phishing-csvCheckmarx
First Known Phishing Attack Against PyPi Users
A few hours ago, PyPi disclose information on the first seen phishing attack aimed at a Python contributor. Right now, we are aware of hundreds of malicious packages that were related to this attack based on the known indicator.
#ParsedReport
31-08-2022
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github
https://asec.ahnlab.com/en/38150
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
Control_rat
IOCs:
File: 3
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
31-08-2022
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github
https://asec.ahnlab.com/en/38150
Threats:
Asyncrat_rat
Trojan/win.leonem.c5218555
Trojan/win.agent.c4526491
Vbinder
Smokeloader
Trojan/win.msilzilla.c5129545
Trojan/win.generic.c5198415
Malware/mdp.inject.m3037
Malware/mdp.autorun.m1037
Malware/mdp.inject.m1252
Control_rat
IOCs:
File: 3
Url: 4
Hash: 6
Softs:
windows explorer
Algorithms:
zip
ASEC
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github - ASEC
RAT Tool Disguised as Solution File (*.sln) Being Distributed on Github ASEC
#ParsedReport
31-08-2022
Malicious Word Files Targeting Specific Individuals Related to North Korea
https://asec.ahnlab.com/en/38182
Actors/Campaigns:
Kimsuky
Geo:
Korea, Gyeonggi-do, Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Url: 3
Path: 3
Registry: 7
Hash: 1
Platforms:
x86
31-08-2022
Malicious Word Files Targeting Specific Individuals Related to North Korea
https://asec.ahnlab.com/en/38182
Actors/Campaigns:
Kimsuky
Geo:
Korea, Gyeonggi-do, Korean
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 9
Url: 3
Path: 3
Registry: 7
Hash: 1
Platforms:
x86
ASEC
Malicious Word Files Targeting Specific Individuals Related to North Korea - ASEC
Malicious Word Files Targeting Specific Individuals Related to North Korea ASEC
#ParsedReport
01-09-2022
Malicious HWP File Disguised as a Happy Birthday Message (OLE Object)
https://asec.ahnlab.com/en/38203
Industry:
Education
Geo:
Korean, Korea
IOCs:
Url: 7
File: 2
Path: 3
Hash: 5
Softs:
task scheduler, curl
Platforms:
x64
01-09-2022
Malicious HWP File Disguised as a Happy Birthday Message (OLE Object)
https://asec.ahnlab.com/en/38203
Industry:
Education
Geo:
Korean, Korea
IOCs:
Url: 7
File: 2
Path: 3
Hash: 5
Softs:
task scheduler, curl
Platforms:
x64
ASEC
Malicious HWP File Disguised as a Happy Birthday Message (OLE Object) - ASEC
The ASEC analysis team has recently discovered a VBScript that downloads a malicious HWP file. The distribution path of malware is yet to be determined, but the VBScript is downloaded through curl. The commands discovered so far are as follows: curl -H ”user…
#ParsedReport
01-09-2022
ASEC Weekly Malware Statistics (August 22nd, 2022 August 28th, 2022)
https://asec.ahnlab.com/en/38379
Threats:
Agent_tesla
Redline_stealer
Beamwinhttp_loader
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat
Industry:
Energy, Financial, Transport
Geo:
Korea, Emirates
IOCs:
Domain: 16
IP: 3
Email: 6
File: 33
Url: 16
Softs:
nsis installer, discord
Languages:
visual_basic
01-09-2022
ASEC Weekly Malware Statistics (August 22nd, 2022 August 28th, 2022)
https://asec.ahnlab.com/en/38379
Threats:
Agent_tesla
Redline_stealer
Beamwinhttp_loader
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat
Industry:
Energy, Financial, Transport
Geo:
Korea, Emirates
IOCs:
Domain: 16
IP: 3
Email: 6
File: 33
Url: 16
Softs:
nsis installer, discord
Languages:
visual_basic
ASEC
ASEC Weekly Malware Statistics (August 22nd, 2022 – August 28th, 2022) - ASEC
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from August 22nd, 2022 (Monday) to August 28th, 2022 (Sunday). For the main category, info…
#ParsedReport
01-09-2022
ASEC Weekly Malware Statistics (August 15th, 2022 August 21st, 2022)
https://asec.ahnlab.com/en/38170
Threats:
Agent_tesla
Formbook
Redline_stealer
Clipboard_grabbing_technique
Beamwinhttp_loader
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer
Industry:
Financial
Geo:
Korea
TTPs:
IOCs:
Domain: 3
IP: 11
Email: 6
File: 20
Url: 15
Softs:
discord, nsis installer
Languages:
visual_basic
01-09-2022
ASEC Weekly Malware Statistics (August 15th, 2022 August 21st, 2022)
https://asec.ahnlab.com/en/38170
Threats:
Agent_tesla
Formbook
Redline_stealer
Clipboard_grabbing_technique
Beamwinhttp_loader
Cloudeye
Remcos_rat
Nanocore_rat
Avemaria_rat
Lokibot_stealer
Industry:
Financial
Geo:
Korea
TTPs:
IOCs:
Domain: 3
IP: 11
Email: 6
File: 20
Url: 15
Softs:
discord, nsis installer
Languages:
visual_basic
ASEC BLOG
ASEC Weekly Malware Statistics (August 15th, 2022 - August 21st, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from August 15th, 2022 (Monday) to August 21st, 2022 (Sunday). For the main category, info…
#ParsedReport
01-09-2022
ASEC (20220822 \~ 20220828). ASEC Weekly Malware Statistics (20220822 \~ 20220828)
https://asec.ahnlab.com/ko/38197
Threats:
Agent_tesla
Azorult
Redline_stealer
Beamwinhttp_loader
Postealer
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat
Industry:
Financial, Energy, Transport
Geo:
Emirates, Korea
IOCs:
File: 44
Domain: 16
IP: 3
Email: 6
Url: 16
Softs:
nsis installer, discord
Languages:
visual_basic
01-09-2022
ASEC (20220822 \~ 20220828). ASEC Weekly Malware Statistics (20220822 \~ 20220828)
https://asec.ahnlab.com/ko/38197
Threats:
Agent_tesla
Azorult
Redline_stealer
Beamwinhttp_loader
Postealer
Formbook
Clipboard_grabbing_technique
Cloudeye
Remcos_rat
Nanocore_rat
Industry:
Financial, Energy, Transport
Geo:
Emirates, Korea
IOCs:
File: 44
Domain: 16
IP: 3
Email: 6
Url: 16
Softs:
nsis installer, discord
Languages:
visual_basic
ASEC BLOG
ASEC 주간 악성코드 통계 (20220822 ~ 20220828) - ASEC BLOG
ASEC 분석팀에서는 ASEC 자동 분석 시스템 RAPIT 을 활용하여 알려진 악성코드들에 대한 분류 및 대응을 진행하고 있다. 본 포스팅에서는 2022년 8월 22일 월요일부터 8월 28일 일요일까지 한 주간 수집된 악성코드의 통계를 정리한다. 대분류 상으로는 인포스틸러가 41.0%로 1위를 차지하였으며, 그 다음으로는 백도어 악성코드가 31.8%, 다운로더 21.4%, 랜섬웨어 5.8%로 집계되었다. Top 1 – Agent Tesla 인포스틸러…
#ParsedReport
01-09-2022
ERMAC 2.0: Perfecting the Account Takeover
https://intel471.com/blog/rmac-2-0-perfecting-the-art-of-account-takeover
Actors/Campaigns:
Dukeeugene
Threats:
Ermac
Cerberus
Blackrock
Industry:
Financial, E-commerce
Geo:
China, Russia
IOCs:
File: 1
Softs:
android, telegram
Platforms:
intel
01-09-2022
ERMAC 2.0: Perfecting the Account Takeover
https://intel471.com/blog/rmac-2-0-perfecting-the-art-of-account-takeover
Actors/Campaigns:
Dukeeugene
Threats:
Ermac
Cerberus
Blackrock
Industry:
Financial, E-commerce
Geo:
China, Russia
IOCs:
File: 1
Softs:
android, telegram
Platforms:
intel
#ParsedReport
01-09-2022
THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector
https://www.cybereason.com/blog/threat-analysis-report-ragnar-locker-ransomware-targeting-the-energy-sector
Threats:
Ragnarlocker
Blackcat
Clop
Logmein_tool
Splashtop_tool
Industry:
Petroleum, Government, Energy, Financial
Geo:
Kazakhstan, Israel, Kyrgyzstan, Belarus, Tajikistan, Russia, Azerbaijan, Uzbekistan, Luxembourg, Ukraine, Greece, Moldova, Georgia, Armenia, Turkmenistan, China
TTPs:
Tactics: 3
Technics: 7
IOCs:
File: 17
Path: 2
Hash: 35
Softs:
hyper-v, opera, internet explorer, mozilla firefox, vssadmin
Algorithms:
salsa20, rc4
Functions:
Locker
Win API:
CryptBinaryToStringA, GetComputerNameW, CreateFileW, CreateEventW, CreateProcessAsUserW, FindFirstVolumeA, FindNextVolumeA, GetLocaleInfoW, DeviceIoControl, GetUserNameW
01-09-2022
THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector
https://www.cybereason.com/blog/threat-analysis-report-ragnar-locker-ransomware-targeting-the-energy-sector
Threats:
Ragnarlocker
Blackcat
Clop
Logmein_tool
Splashtop_tool
Industry:
Petroleum, Government, Energy, Financial
Geo:
Kazakhstan, Israel, Kyrgyzstan, Belarus, Tajikistan, Russia, Azerbaijan, Uzbekistan, Luxembourg, Ukraine, Greece, Moldova, Georgia, Armenia, Turkmenistan, China
TTPs:
Tactics: 3
Technics: 7
IOCs:
File: 17
Path: 2
Hash: 35
Softs:
hyper-v, opera, internet explorer, mozilla firefox, vssadmin
Algorithms:
salsa20, rc4
Functions:
Locker
Win API:
CryptBinaryToStringA, GetComputerNameW, CreateFileW, CreateEventW, CreateProcessAsUserW, FindFirstVolumeA, FindNextVolumeA, GetLocaleInfoW, DeviceIoControl, GetUserNameW
Cybereason
THREAT ANALYSIS REPORT: Ragnar Locker Ransomware Targeting the Energy Sector
Ragnar Locker is a ransomware family with security evasion capabilities which is targeting the energy sector and recently claimed to have breached DESFA, a Greek pipeline company...
#ParsedReport
01-09-2022
Raspberry Robin and Dridex: Two Birds of a Feather
https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware
Actors/Campaigns:
Evil_corp (motivation: cyber_criminal)
Fakeupdates
Threats:
Raspberry_robin
Dridex
Socgholish_loader
Dopplepaymer
Lockbit
Wastedlocker
Lolbin
Industry:
Transport, Petroleum
Geo:
Russia
IOCs:
Hash: 3
File: 10
Algorithms:
xor, rc4, crc
Functions:
GetPrcAddress, LdrLoadDll, bytearray, the, LdrGetProcedureAddress
Win API:
LoadLibraryA, VirtualAlloc, wglGetProcAddress, VirtualProtect
Languages:
python
01-09-2022
Raspberry Robin and Dridex: Two Birds of a Feather
https://securityintelligence.com/posts/raspberry-robin-worm-dridex-malware
Actors/Campaigns:
Evil_corp (motivation: cyber_criminal)
Fakeupdates
Threats:
Raspberry_robin
Dridex
Socgholish_loader
Dopplepaymer
Lockbit
Wastedlocker
Lolbin
Industry:
Transport, Petroleum
Geo:
Russia
IOCs:
Hash: 3
File: 10
Algorithms:
xor, rc4, crc
Functions:
GetPrcAddress, LdrLoadDll, bytearray, the, LdrGetProcedureAddress
Win API:
LoadLibraryA, VirtualAlloc, wglGetProcAddress, VirtualProtect
Languages:
python
Security Intelligence
Raspberry Robin and Dridex: Two Birds of a Feather
Explore in-depth analysis on the Raspberry Robin worm, tying it to Russia-based cybercriminal group 'Evil Corp' — the same group behind the Dridex Malware.
#ParsedReport
01-09-2022
Highly evasive Magecart JavaScript Skimmer active in the wild
https://blog.cyble.com/2022/09/01/highly-evasive-magecart-javascript-skimmer-active-in-the-wild
Actors/Campaigns:
Magecart
Threats:
Beacon
Industry:
E-commerce, Financial
Geo:
Dubai, Georgia, Singapore, Australia, India
TTPs:
Tactics: 6
Technics: 6
IOCs:
File: 1
Hash: 1
Languages:
javascript, php
01-09-2022
Highly evasive Magecart JavaScript Skimmer active in the wild
https://blog.cyble.com/2022/09/01/highly-evasive-magecart-javascript-skimmer-active-in-the-wild
Actors/Campaigns:
Magecart
Threats:
Beacon
Industry:
E-commerce, Financial
Geo:
Dubai, Georgia, Singapore, Australia, India
TTPs:
Tactics: 6
Technics: 6
IOCs:
File: 1
Hash: 1
Languages:
javascript, php
Cyble
Cyble - Highly Evasive Magecart JavaScript Skimmer Active In The Wild
Cyble Research and Intelligence Labs analyzes a highly-evasive Magecart Javascript skimmer that is active in the wild.
#ParsedReport
01-09-2022
Threat Actor "Robin Banks" Phishing Kit Revisions
https://www.wmcglobal.com/blog/robin-banks-phishing-kit-revisions
Threats:
Robin_banks_tool
IOCs:
Hash: 1
Languages:
php
Platforms:
intel
01-09-2022
Threat Actor "Robin Banks" Phishing Kit Revisions
https://www.wmcglobal.com/blog/robin-banks-phishing-kit-revisions
Threats:
Robin_banks_tool
IOCs:
Hash: 1
Languages:
php
Platforms:
intel
Wmcglobal
Threat Actor "Robin Banks" Phishing Kit Revisions
In July, a report was released spotlighting a threat actor known as Robin Banks. WMC Global was tracking this threat actor and noticed the scammer's...
#ParsedReport
30-08-2022
[ \] Appleseed v2.1. [Threat Analysis\] Appleseed V2.1 running on JavaScript
https://stic.secui.com/main/main/threatInfo?id=69
Threats:
Appleseed
IOCs:
File: 15
Algorithms:
zip, rc4, xor, base64
Win API:
Compress
Languages:
javascript, python
Platforms:
x86
30-08-2022
[ \] Appleseed v2.1. [Threat Analysis\] Appleseed V2.1 running on JavaScript
https://stic.secui.com/main/main/threatInfo?id=69
Threats:
Appleseed
IOCs:
File: 15
Algorithms:
zip, rc4, xor, base64
Win API:
Compress
Languages:
javascript, python
Platforms:
x86
#ParsedReport
01-09-2022
PyPI Phishing Campaign \| JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks
https://www.sentinelone.com/labs/pypi-phishing-campaign-juiceledger-threat-actor-pivots-from-fake-apps-to-supply-chain-attacks
Actors/Campaigns:
Juiceledger
Threats:
Juicestealer
Typosquatting_technique
Agent_tesla
Cratedepression
IOCs:
Domain: 14
Hash: 45
File: 11
Path: 1
Url: 1
IP: 1
Email: 1
Softs:
chrome, discord
Algorithms:
zip
Languages:
python, rust
01-09-2022
PyPI Phishing Campaign \| JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks
https://www.sentinelone.com/labs/pypi-phishing-campaign-juiceledger-threat-actor-pivots-from-fake-apps-to-supply-chain-attacks
Actors/Campaigns:
Juiceledger
Threats:
Juicestealer
Typosquatting_technique
Agent_tesla
Cratedepression
IOCs:
Domain: 14
Hash: 45
File: 11
Path: 1
Url: 1
IP: 1
Email: 1
Softs:
chrome, discord
Algorithms:
zip
Languages:
python, rust
SentinelOne
PyPI Phishing Campaign | JuiceLedger Threat Actor Pivots From Fake Apps to Supply Chain Attacks
A new threat actor is spreading infostealer malware through targeted attacks on developers and fraudulent cryptotrading applications.
#ParsedReport
01-09-2022
No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points
https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed
Threats:
Prynt_stealer
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool
Industry:
Entertainment, Financial
IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1
Softs:
telegram
Win API:
RtlSetProcessIsCritical, SetThreadExecutionState
Languages:
autoit
Links:
01-09-2022
No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points
https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed
Threats:
Prynt_stealer
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool
Industry:
Entertainment, Financial
IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1
Softs:
telegram
Win API:
RtlSetProcessIsCritical, SetThreadExecutionState
Languages:
autoit
Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealerhttps://github.com/NYAN-x-CAT/AsyncRAT-C-Sharphttps://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cshttps://github.com/swagkarna/StormKitty/Zscaler
Prynt Stealer’s Backdoor Exposed | Zscaler Blog
Prynt Stealer shares codebase with AsyncRAT and StormKitty. DarkEye and WorldWind are virtually identical to Prynt Stealer.
#ParsedReport
02-09-2022
Buzzing in the Background: BumbleBee, a New Modular Backdoor Evolved From BookWorm. Introduction
https://www.trendmicro.com/en_us/research/22/i/buzzing-in-the-background-bumblebee-a-new-modular-backdoor-evolv.html
Threats:
Bumblebee
Bookworm
Beacon
Trojan.win32.multicom.ztic
Trojan.win32.regload.zti
Backdoor.win32.bumbleb.ztic
Dll_sideloading_technique
Process_injection_technique
Industry:
Government
Geo:
Asia, Taiwan, Chinese, China, Asian
TTPs:
Tactics: 7
Technics: 15
IOCs:
File: 11
Path: 2
Registry: 2
Hash: 9
Url: 2
Softs:
windows service
Algorithms:
crc, rc4, xor
02-09-2022
Buzzing in the Background: BumbleBee, a New Modular Backdoor Evolved From BookWorm. Introduction
https://www.trendmicro.com/en_us/research/22/i/buzzing-in-the-background-bumblebee-a-new-modular-backdoor-evolv.html
Threats:
Bumblebee
Bookworm
Beacon
Trojan.win32.multicom.ztic
Trojan.win32.regload.zti
Backdoor.win32.bumbleb.ztic
Dll_sideloading_technique
Process_injection_technique
Industry:
Government
Geo:
Asia, Taiwan, Chinese, China, Asian
TTPs:
Tactics: 7
Technics: 15
IOCs:
File: 11
Path: 2
Registry: 2
Hash: 9
Url: 2
Softs:
windows service
Algorithms:
crc, rc4, xor
Trend Micro
BumbleBee a New Modular Backdoor Evolved From BookWorm
In March 2021, we investigated a backdoor with a unique modular architecture and called it BumbleBee due to a string embedded in the malware. However, in our recent investigations, we have discovered a controller application that expands its capabilities.
#ParsedReport
02-09-2022
Zanubis: New Android Banking Trojan spotted in the wild
https://blog.cyble.com/2022/09/02/zanubis-new-android-banking-trojan
Threats:
Zanubis
Hydra
Ermac
Bratarat
Industry:
Financial
Geo:
Dubai, Georgia, India, Peruvian, Australia, Peru, Singapore
TTPs:
Tactics: 3
Technics: 9
IOCs:
File: 18
Url: 1
Hash: 3
Softs:
android
Functions:
onAccessibilityEvent
02-09-2022
Zanubis: New Android Banking Trojan spotted in the wild
https://blog.cyble.com/2022/09/02/zanubis-new-android-banking-trojan
Threats:
Zanubis
Hydra
Ermac
Bratarat
Industry:
Financial
Geo:
Dubai, Georgia, India, Peruvian, Australia, Peru, Singapore
TTPs:
Tactics: 3
Technics: 9
IOCs:
File: 18
Url: 1
Hash: 3
Softs:
android
Functions:
onAccessibilityEvent
#ParsedReport
03-09-2022
No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points
https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed
Threats:
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool
Industry:
Financial, Entertainment
IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1
Softs:
telegram
Win API:
RtlSetProcessIsCritical, SetThreadExecutionState
Languages:
autoit
Links:
03-09-2022
No Honor Among Thieves - Prynt Stealers Backdoor Exposed. Key Points
https://www.zscaler.com/blogs/security-research/no-honor-among-thieves-prynt-stealers-backdoor-exposed
Threats:
Asyncrat_rat
Stormkitty_stealer
Loda_rat
Njrat_rat
Quasar_rat
Cobian_rat
Binder
Netstat_tool
Industry:
Financial, Entertainment
IOCs:
IP: 1
Url: 4
Domain: 6
File: 9
Hash: 10
Path: 1
Softs:
telegram
Win API:
RtlSetProcessIsCritical, SetThreadExecutionState
Languages:
autoit
Links:
https://github.com/threatlabz/iocs/tree/main/pryntstealerhttps://github.com/NYAN-x-CAT/AsyncRAT-C-Sharp/blob/master/AsyncRAT-C%23/Client/Settings.cshttps://github.com/NYAN-x-CAT/AsyncRAT-C-Sharphttps://github.com/swagkarna/StormKitty/Zscaler
Prynt Stealer’s Backdoor Exposed | Zscaler Blog
Prynt Stealer shares codebase with AsyncRAT and StormKitty. DarkEye and WorldWind are virtually identical to Prynt Stealer.
#ParsedReport
03-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
Media, Government, E-commerce
Geo:
Iranian, Tehran, Irans, Iran
IOCs:
File: 9
Hash: 5
Softs:
microsoft powerpoint, microsoft word, windows media player, android, egram grou, microsoft office, visual studio, ram.org/bo, instagram, telegram
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
03-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
Media, Government, E-commerce
Geo:
Iranian, Tehran, Irans, Iran
IOCs:
File: 9
Hash: 5
Softs:
microsoft powerpoint, microsoft word, windows media player, android, egram grou, microsoft office, visual studio, ram.org/bo, instagram, telegram
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
https://github.com/MrModed/DWMSafeBreach
SafeBreach Uncovers New Remote Access Trojan (RAT)
Dubbed CodeRAT, the new RAT is used in attacks targeting Farsi-speaking code developers using a Microsoft Dynamic Data Exchange (DDE) exploit.
#ParsedReport
03-09-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
windows service, microsoft excel, windows defender
Win API:
CmRccService, CmRcService
03-09-2022
Crypto miners latest techniques
https://cybersecurity.att.com/blogs/labs-research/crypto-miners-latest-techniques
Threats:
Alien
Industry:
Iot
Geo:
Mexican
TTPs:
Tactics: 8
Technics: 22
IOCs:
Registry: 3
Path: 10
Domain: 3
File: 5
Hash: 7
Softs:
windows service, microsoft excel, windows defender
Win API:
CmRccService, CmRcService
LevelBlue
Crypto miners’ latest techniques
An exploration of the newest methods used by crypto miners to exploit systems, enhancing threat awareness.