#ParsedReport
08-09-2022
Microsoft investigates Iranian attacks against the Albanian government
https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government
Actors/Campaigns:
Dev-0861
Dev-0166
Siamesekitten
Europium
Threats:
Zerocleare_wiper
Hostile
Credential_harvesting_technique
Mimikatz
Impacket_tool
Trojan:win32/batrungoxml
Ransom:win32/eagle!msr
Trojan:win32/debitom.a
Proxylogon_exploit
Industry:
Ngo, Aerospace, Transport, Petroleum, Government, Healthcare, Telco, Energy
Geo:
Kuwait, Turkey, Irans, Albania, Tehrans, Tehran, American, Iranians, Jordan, Iran, Iranian, Israel
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2019-0604 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft sharepoint foundation (2013)
- microsoft sharepoint server (2019, 2010)
- microsoft sharepoint enterprise server (2016)
TTPs:
Tactics: 3
Technics: 0
IOCs:
IP: 8
File: 11
Hash: 21
Path: 8
Coin: 1
Registry: 1
Softs:
microsoft exchange, winlogon, microsoft defender, microsoft 365 defender, microsoft defender for endpoint, sharepoint server
Algorithms:
base64, zip, rc4
Functions:
rand
Win API:
SeDebugPrivilege, FindFirstVolumeW, GetOpenFileNameA, GetVolumePathNamesForVolumeNameW, CreateMutexA, SeImpersonatePrivilege, GetTokenInformation, CreateProcessWithTokenW, FindNextVolumeW, SetVolumeMountPointW, CreateDirectoryW
YARA: Found
08-09-2022
Microsoft investigates Iranian attacks against the Albanian government
https://www.microsoft.com/security/blog/2022/09/08/microsoft-investigates-iranian-attacks-against-the-albanian-government
Actors/Campaigns:
Dev-0861
Dev-0166
Siamesekitten
Europium
Threats:
Zerocleare_wiper
Hostile
Credential_harvesting_technique
Mimikatz
Impacket_tool
Trojan:win32/batrungoxml
Ransom:win32/eagle!msr
Trojan:win32/debitom.a
Proxylogon_exploit
Industry:
Ngo, Aerospace, Transport, Petroleum, Government, Healthcare, Telco, Energy
Geo:
Kuwait, Turkey, Irans, Albania, Tehrans, Tehran, American, Iranians, Jordan, Iran, Iranian, Israel
CVEs:
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2019-0604 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.8
X-Force: Patch: Official fix
Soft:
- microsoft sharepoint foundation (2013)
- microsoft sharepoint server (2019, 2010)
- microsoft sharepoint enterprise server (2016)
TTPs:
Tactics: 3
Technics: 0
IOCs:
IP: 8
File: 11
Hash: 21
Path: 8
Coin: 1
Registry: 1
Softs:
microsoft exchange, winlogon, microsoft defender, microsoft 365 defender, microsoft defender for endpoint, sharepoint server
Algorithms:
base64, zip, rc4
Functions:
rand
Win API:
SeDebugPrivilege, FindFirstVolumeW, GetOpenFileNameA, GetVolumePathNamesForVolumeNameW, CreateMutexA, SeImpersonatePrivilege, GetTokenInformation, CreateProcessWithTokenW, FindNextVolumeW, SetVolumeMountPointW, CreateDirectoryW
YARA: Found
Microsoft News
Microsoft investigates Iranian attacks against the Albanian government
Shortly after the destructive cyberattacks on the Albanian government in mid-July, the Microsoft Detection and Response Team (DART) was engaged to lead an investigation into the attacks.
#ParsedReport
08-09-2022
Raccoon Stealer 2.0 Malware analysis
https://any.run/cybersecurity-blog/raccoon-stealer-v2-malware-analysis/?utm_source=linkedin
Threats:
Raccoon_stealer
Recordbreaker_stealer
Follina_vuln
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 17
Registry: 1
Softs:
jaxx, tronlink, binancechain, telegram, jaxxliberty, chrome
Algorithms:
base64, xor, rc4
Functions:
x64-specific
Win API:
NtQueryInformationProcess
Languages:
python
Links:
08-09-2022
Raccoon Stealer 2.0 Malware analysis
https://any.run/cybersecurity-blog/raccoon-stealer-v2-malware-analysis/?utm_source=linkedin
Threats:
Raccoon_stealer
Recordbreaker_stealer
Follina_vuln
Industry:
Financial
TTPs:
Tactics: 1
Technics: 0
IOCs:
File: 4
Hash: 17
Registry: 1
Softs:
jaxx, tronlink, binancechain, telegram, jaxxliberty, chrome
Algorithms:
base64, xor, rc4
Functions:
x64-specific
Win API:
NtQueryInformationProcess
Languages:
python
Links:
https://github.com/mrexodia/TitanHide/commit/6a5a68a2447ad9454adfcbd9390ec05b9dcef2d6https://github.com/mrexodia/TitanHide/issues/70ANY.RUN's Cybersecurity Blog
Raccoon Stealer 2.0 Malware analysis - ANY.RUN's Cybersecurity Blog
ANY.RUN team of analytics has done a malware research of Raccoon Stealer 2.0. Check our results, including the script to extract C2 servers.
#ParsedReport
08-09-2022
The Week in Cybersecurity: Vice Society ransomware group targets back-to-school
https://blog.reversinglabs.com/blog/the-week-in-cybersecurity-vice-society-ransomware
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Hellokitty
Zeppelin
Cobalt_strike
Empire_loader
Systembc
Deadbolt
Shikitega
Sunburst
Industry:
Government, Financial, Education, Iot
Geo:
Montenegro, Americas, Russia
08-09-2022
The Week in Cybersecurity: Vice Society ransomware group targets back-to-school
https://blog.reversinglabs.com/blog/the-week-in-cybersecurity-vice-society-ransomware
Actors/Campaigns:
Vice_society (motivation: cyber_criminal)
Threats:
Hellokitty
Zeppelin
Cobalt_strike
Empire_loader
Systembc
Deadbolt
Shikitega
Sunburst
Industry:
Government, Financial, Education, Iot
Geo:
Montenegro, Americas, Russia
ReversingLabs
The Week in Cybersecurity: Vice Society ransomware group targets back-to-school
This week: Vice Society ransomware group targets America’s education sector, the U.S. government’s new position on software supply chain security, and more.
#ParsedReport
08-09-2022
(Magniber) (*.cpl -> *.jse) 9/8. Magniber Ransomware Change ( *.cpl-> *.jse) -9/8
https://asec.ahnlab.com/ko/38706
Threats:
Magniber
Typosquatting_technique
IOCs:
File: 2
Hash: 1
Softs:
chrome
Algorithms:
zip
08-09-2022
(Magniber) (*.cpl -> *.jse) 9/8. Magniber Ransomware Change ( *.cpl-> *.jse) -9/8
https://asec.ahnlab.com/ko/38706
Threats:
Magniber
Typosquatting_technique
IOCs:
File: 2
Hash: 1
Softs:
chrome
Algorithms:
zip
ASEC
매그니베르(Magniber) 랜섬웨어 변경(*.cpl -> *.jse) – 9/8일자 - ASEC
7월 20일에 MSI 형식에서 CPL 형식으로 유포방식을 변경한 이후, 8월 중순 이후부터 유포가 잠시 주춤한 것으로 확인되고 있었다. 지속적으로 변화 상황을 모니터링 하던 중, 2022년 9월 8일부터는 유포 방식이 *.CPL (DLL형식)에서 *.JSE (스크립트) 형태로 변경된 것을 확인하였다. 매그니베르 랜섬웨어는 국내 사용자에 가장 큰 피해를 주는 랜섬웨어 중 하나로 활발하게 유포되고 있고, 백신의 탐지를 우회하기 위한 […]
#ParsedReport
08-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
E-commerce, Media, Government
Geo:
Iran, Tehran, Iranian, Irans
IOCs:
File: 9
Hash: 5
Softs:
visual studio, instagram, telegram, microsoft office, egram grou, microsoft powerpoint, android, microsoft word, windows media player, ram.org/bo
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
08-09-2022
SafeBreach Labs Researchers Uncover New Remote Access Trojan (RAT). CodeRAT Overview
https://www.safebreach.com/resources/blog/remote-access-trojan-coderat
Threats:
Coderat
Robothief
Antidebugging_technique
Industry:
E-commerce, Media, Government
Geo:
Iran, Tehran, Iranian, Irans
IOCs:
File: 9
Hash: 5
Softs:
visual studio, instagram, telegram, microsoft office, egram grou, microsoft powerpoint, android, microsoft word, windows media player, ram.org/bo
Functions:
BossWatch, CheckBoss
Win API:
CryptUnprotectData
Languages:
python
Platforms:
x86
YARA: Found
Links:
https://github.com/MrModed/DWMSafeBreach
SafeBreach Uncovers New Remote Access Trojan (RAT)
Dubbed CodeRAT, the new RAT is used in attacks targeting Farsi-speaking code developers using a Microsoft Dynamic Data Exchange (DDE) exploit.
#ParsedReport
07-09-2022
Profiling DEV-0270: PHOSPHORUS ransomware operations
https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations
Actors/Campaigns:
Phosphorus
Threats:
Lolbin
Log4shell_vuln
Minidump_tool
Impacket_tool
Mamba
Credential_stealing_technique
Lazagne
Mimikatz
Proxyshell_vuln
Industry:
Government
Geo:
Iran, Iranian
CVEs:
CVE-2021-26858 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
CVE-2021-27065 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)
CVE-2021-26857 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2010, 2013, 2019, 2016, 2019, 2016)
TTPs:
Tactics: 8
Technics: 0
IOCs:
File: 15
Domain: 2
Registry: 2
Softs:
microsoft defender for endpoint, local security authority, bitlocker, microsoft defender, microsoft 365 defender, task scheduler, psexec
Links:
07-09-2022
Profiling DEV-0270: PHOSPHORUS ransomware operations
https://www.microsoft.com/security/blog/2022/09/07/profiling-dev-0270-phosphorus-ransomware-operations
Actors/Campaigns:
Phosphorus
Threats:
Lolbin
Log4shell_vuln
Minidump_tool
Impacket_tool
Mamba
Credential_stealing_technique
Lazagne
Mimikatz
Proxyshell_vuln
Industry:
Government
Geo:
Iran, Iranian
CVEs:
CVE-2021-26858 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2019, 2019)
CVE-2021-27065 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2013, 2016, 2016, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2021-26855 [Vulners]
Vulners: Score: 7.5, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 9.1
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2016, 2016, 2013, 2016, 2016, 2013, 2016, 2019, 2013, 2016, 2016, 2016, 2016, 2016, 2016, 2016, 2019, 2019, 2019, 2019, 2019, 2019, 2019, 2019)
CVE-2018-13379 [Vulners]
Vulners: Score: 5.0, CVSS: 3.2,
Vulners: Exploitation: True
X-Force: Risk: 7.5
X-Force: Patch: Official fix
Soft:
- fortinet fortios (le6.0.4, le5.6.7)
CVE-2021-26857 [Vulners]
Vulners: Score: 6.8, CVSS: 2.8,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- microsoft exchange server (2010, 2013, 2019, 2016, 2019, 2016)
TTPs:
Tactics: 8
Technics: 0
IOCs:
File: 15
Domain: 2
Registry: 2
Softs:
microsoft defender for endpoint, local security authority, bitlocker, microsoft defender, microsoft 365 defender, task scheduler, psexec
Links:
https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Email%20data%20exfiltration%20via%20PowerShell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270WMICDiscoverySep2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Create%20new%20user%20with%20known%20DEV-0270%20username%20and%20password.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/PowerShell%20adding%20exclusion%20path%20for%20Microsoft%20Defender%20of%20ProgramData.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270RegistryIOCSep2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/DLLHost.exe%20WMIC%20domain%20discovery.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270NewUserSep2022.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Disabling%20Services%20via%20Registry.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Modifying%20the%20registry%20to%20add%20a%20ransom%20message%20notification.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/Add%20malicious%20user%20to%20Admins%20and%20RDP%20users%20group%20via%20PowerShell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/Microsoft%20365%20Defender/Ransomware/DEV-0270/DLLHost.exe%20file%20creation%20via%20PowerShell.yamlhttps://github.com/Azure/Azure-Sentinel/blob/master/Detections/MultipleDataSources/Dev-0270PowershellSep2022.yamlhttps://github.com/SecureAuthCorp/impacket/Microsoft News
Profiling DEV-0270: PHOSPHORUS’ ransomware operations
Microsoft threat intelligence teams have been tracking multiple ransomware campaigns tied to DEV-0270, also known as Nemesis Kitten, a sub-group of Iranian actor PHOSPHORUS.
#ParsedReport
08-09-2022
Crimeware Trends \| Ransomware Developers Turn to Intermittent Encryption to Evade Detection
https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection
Actors/Campaigns:
Blackcat
Qilin
Threats:
Blackbasta
Qyick
Blackcat
Playcrypt
Conti
Industry:
Healthcare, Education, Financial, Energy
Geo:
Asia, Argentina, Africa, Russian, German
IOCs:
Hash: 4
Algorithms:
chacha20, aes
Win API:
LockFile
Languages:
rust
08-09-2022
Crimeware Trends \| Ransomware Developers Turn to Intermittent Encryption to Evade Detection
https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection
Actors/Campaigns:
Blackcat
Qilin
Threats:
Blackbasta
Qyick
Blackcat
Playcrypt
Conti
Industry:
Healthcare, Education, Financial, Energy
Geo:
Asia, Argentina, Africa, Russian, German
IOCs:
Hash: 4
Algorithms:
chacha20, aes
Win API:
LockFile
Languages:
rust
SentinelOne
Crimeware Trends | Ransomware Developers Turn to Intermittent Encryption to Evade Detection
Partially encrypting victims' files improves ransomware speed and aids evasion. First seen in LockFile, the technique is now being widely adopted.
#ParsedReport
08-09-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government
Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows registry, windows service
Algorithms:
rc4, base64
Functions:
GetUpdates
Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary
Platforms:
x86
YARA: Found
Links:
08-09-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government
Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows registry, windows service
Algorithms:
rc4, base64
Functions:
GetUpdates
Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary
Platforms:
x86
YARA: Found
Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rbGoogle Cloud Blog
ROADSWEEP Ransomware Targets the Albanian Government | Google Cloud Blog
Mandiant identified the ROADSWEEP ransomware family which targeted the Albanian government in a politically motivated disruptive operation. Learn more.
#ParsedReport
08-09-2022
Lazarus and the tale of three RATs
http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
Actors/Campaigns:
Lazarus (motivation: cyber_espionage)
Threats:
Vsingle
Yamabot
Magicrat
Bespoke
Log4shell_vuln
Dtrack_rat
Mauicrypt
Netstat_tool
Putty_tool
Plink
Impacket_tool
Credential_harvesting_technique
Mimikatz
Procdump_tool
Wevtutil_tool
Adfind_tool
Industry:
Government, Energy
Geo:
Japan, Korean, Canada, Korea, Japanese
TTPs:
Tactics: 4
Technics: 21
IOCs:
IP: 12
File: 24
Path: 13
Registry: 12
Coin: 1
Hash: 15
Url: 40
Softs:
windows defender, 3proxy, active directory, vmware horizon, vssadmin
Algorithms:
base64
Win API:
select
Languages:
golang, php, java, python
Platforms:
x86
Links:
08-09-2022
Lazarus and the tale of three RATs
http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
Actors/Campaigns:
Lazarus (motivation: cyber_espionage)
Threats:
Vsingle
Yamabot
Magicrat
Bespoke
Log4shell_vuln
Dtrack_rat
Mauicrypt
Netstat_tool
Putty_tool
Plink
Impacket_tool
Credential_harvesting_technique
Mimikatz
Procdump_tool
Wevtutil_tool
Adfind_tool
Industry:
Government, Energy
Geo:
Japan, Korean, Canada, Korea, Japanese
TTPs:
Tactics: 4
Technics: 21
IOCs:
IP: 12
File: 24
Path: 13
Registry: 12
Coin: 1
Hash: 15
Url: 40
Softs:
windows defender, 3proxy, active directory, vmware horizon, vssadmin
Algorithms:
base64
Win API:
select
Languages:
golang, php, java, python
Platforms:
x86
Links:
https://github.com/3proxy/3proxyCisco Talos Blog
Lazarus and the tale of three RATs
Cisco Talos assesses with high confidence these attacks have been conducted by the North Korean state-sponsored threat actor Lazarus Group.
#technique
Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.
https://github.com/CodeXTF2/cobaltstrike-headless
Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.
https://github.com/CodeXTF2/cobaltstrike-headless
GitHub
GitHub - CodeXTF2/cobaltstrike-headless: Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt…
Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client. - CodeXTF2/cobaltstrike-headless
#ParsedReport
09-09-2022
LUNA Ransomware Attack Pattern Analysis. Key Takeaways
https://www.elastic.co/security-labs/luna-ransomware-attack-pattern
Threats:
Luna
Seth_locker
Cuba
Geo:
Switzerland
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 974
Algorithms:
base64, aes, curve25519
Win API:
NtLmSsp
Languages:
python, rust
YARA: Found
Links:
09-09-2022
LUNA Ransomware Attack Pattern Analysis. Key Takeaways
https://www.elastic.co/security-labs/luna-ransomware-attack-pattern
Threats:
Luna
Seth_locker
Cuba
Geo:
Switzerland
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 974
Algorithms:
base64, aes, curve25519
Win API:
NtLmSsp
Languages:
python, rust
YARA: Found
Links:
https://github.com/dalek-cryptography/x25519-dalek
https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/defense\_evasion\_attempt\_to\_disable\_windows\_defender\_services.tomlwww.elastic.co
LUNA Ransomware Attack Pattern Analysis — Elastic Security Labs
In this research publication, we'll explore the LUNA attack pattern — a cross-platform ransomware variant.
#ParsedReport
09-09-2022
Charming Kitten: Can We Have A Meeting?
https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Apt42 (motivation: cyber_espionage)
Phosphorus (motivation: cyber_espionage)
Industry:
Education, Government, Financial, Healthcare
Geo:
Iraq, American, Iranian, Iran, Syria, French, France, Irans, Israel, Libya, Africa
IOCs:
Url: 3
Domain: 78
IP: 13
Email: 5
Hash: 1
Softs:
zoom
09-09-2022
Charming Kitten: Can We Have A Meeting?
https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Apt42 (motivation: cyber_espionage)
Phosphorus (motivation: cyber_espionage)
Industry:
Education, Government, Financial, Healthcare
Geo:
Iraq, American, Iranian, Iran, Syria, French, France, Irans, Israel, Libya, Africa
IOCs:
Url: 3
Domain: 78
IP: 13
Email: 5
Hash: 1
Softs:
zoom
Certfa
Charming Kitten: “Can We Have A Meeting?” - Certfa Lab
Our recent investigation at Certfa Lab, the APT42 has been running multiple phishing campaigns since late 2021 and some of them are ongoing and still active.
В отчетах попадаются списки виндовых сервисов, которые стопаются вредоносом. Запилил парсинг их названий. С понедельника они тоже будут извлекаться из отчетов и добавляться в сообщения в телеге.
#ParsedReport
11-09-2022
Evasive Shikitega Linux malware drops Monero cryptominer
https://www.malwarebytes.com/blog/news/2022/09/evasive-shikitega-linux-malware-drops-monero-cryptominer
Threats:
Shikitega
Alien
Mettle
Metasploit_tool
Meterpreter_tool
Xmrig_miner
Geo:
Japanese
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
Algorithms:
xor, shikata_ga_nai
11-09-2022
Evasive Shikitega Linux malware drops Monero cryptominer
https://www.malwarebytes.com/blog/news/2022/09/evasive-shikitega-linux-malware-drops-monero-cryptominer
Threats:
Shikitega
Alien
Mettle
Metasploit_tool
Meterpreter_tool
Xmrig_miner
Geo:
Japanese
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
Algorithms:
xor, shikata_ga_nai
Vulners Database
CVE-2021-4034 - vulnerability database | Vulners.com
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of p...
#ParsedReport
12-09-2022
The Curious Case of Monti Ransomware: A Real-World Doppelganger
https://blogs.blackberry.com/en/2022/09/the-curious-case-of-monti-ransomware-a-real-world-doppelganger
Threats:
Monti
Conti
Log4shell_vuln
Anydesk_tool
Cobalt_strike
Gmer_tool
Megasync_tool
Mimikatz
Passthehash_technique
Netscan_tool
Putty_tool
Babuk
Yashma
Yanluowang
Chaos
Industry:
Financial
CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 9
Domain: 2
Hash: 7
Softs:
esxi, vmware horizon, chrome, active directory, internet explorer, psexec, winscp, local security authority
Algorithms:
xor, base64
YARA: Found
Links:
12-09-2022
The Curious Case of Monti Ransomware: A Real-World Doppelganger
https://blogs.blackberry.com/en/2022/09/the-curious-case-of-monti-ransomware-a-real-world-doppelganger
Threats:
Monti
Conti
Log4shell_vuln
Anydesk_tool
Cobalt_strike
Gmer_tool
Megasync_tool
Mimikatz
Passthehash_technique
Netscan_tool
Putty_tool
Babuk
Yashma
Yanluowang
Chaos
Industry:
Financial
CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 9
Domain: 2
Hash: 7
Softs:
esxi, vmware horizon, chrome, active directory, internet explorer, psexec, winscp, local security authority
Algorithms:
xor, base64
YARA: Found
Links:
https://github.com/sadshade/veeam-credsBlackBerry
The Curious Case of “Monti” Ransomware: A Real-World Doppelganger
While working a recent ransomware incident, BlackBerry identified a group whose name and TTPs mimicked the long-standing, popular ransomware crew Conti. Furthermore, the encryptor payload used in the attack was taken from the original group and modified for…
#ParsedReport
12-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
Asia, Belarus, China, Ukrainian, Asian, Russia
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualProtect, NtGlobalFlag, GetProcAddress, LoadLibraryA, VirtualAlloc, VirtualFree, ExitThread, RtlDecompressBuffer
12-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
Asia, Belarus, China, Ukrainian, Asian, Russia
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualProtect, NtGlobalFlag, GetProcAddress, LoadLibraryA, VirtualAlloc, VirtualFree, ExitThread, RtlDecompressBuffer
Cybereason
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
PlugX is a post-exploitation modular RAT (Remote Access Trojan), which is known for its multiple functionalities such as data exfiltration, keystroke grabbing, backdoor functionality, and utilizing DLL-Sideloading techniques for evading security solutions...
#ParsedReport
12-09-2022
BRONZE PRESIDENT Targets Government Officials
https://www.secureworks.com/blog/bronze-president-targets-government-officials
Actors/Campaigns:
Red_delta (motivation: government_sponsored)
Threats:
Plugx_rat
Cobalt_strike
Industry:
Government
Geo:
Ukraine, Myanmar, Chinese, America, Vietnam, Suriname, China
IOCs:
File: 10
Hash: 112
IP: 3
Softs:
opera, avastbrowser
Algorithms:
xor
Win API:
GetCommandLineW, EnumThreadWindows, CheckRemoteDebuggerPresent
12-09-2022
BRONZE PRESIDENT Targets Government Officials
https://www.secureworks.com/blog/bronze-president-targets-government-officials
Actors/Campaigns:
Red_delta (motivation: government_sponsored)
Threats:
Plugx_rat
Cobalt_strike
Industry:
Government
Geo:
Ukraine, Myanmar, Chinese, America, Vietnam, Suriname, China
IOCs:
File: 10
Hash: 112
IP: 3
Softs:
opera, avastbrowser
Algorithms:
xor
Win API:
GetCommandLineW, EnumThreadWindows, CheckRemoteDebuggerPresent
Secureworks
BRONZE PRESIDENT Targets Government Officials
The likely Chinese government-sponsored threat group uses decoy documents and PlugX malware to compromise targets.
#ParsedReport
12-09-2022
BUGHATCH Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/bughatch-malware-analysis
Threats:
Bughatch
Cuba
Termite
Process_injection_technique
Mimikatz
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 5
File: 4
Path: 1
Softs:
visual studio
Algorithms:
xor, base64
Functions:
CreateThread, RemoveEntryRecvLinkedList
Win API:
VirtualAlloc, WaitForSingleObject, CreateThread, Sleep, SeDebugPrivilege, QueryPerformanceCounter, GetIpAddrTable, AllocateAndInitializeSid, CheckTokenMembership, OpenProcessToken, have more...
Languages:
python
YARA: Found
Links:
12-09-2022
BUGHATCH Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/bughatch-malware-analysis
Threats:
Bughatch
Cuba
Termite
Process_injection_technique
Mimikatz
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 5
File: 4
Path: 1
Softs:
visual studio
Algorithms:
xor, base64
Functions:
CreateThread, RemoveEntryRecvLinkedList
Win API:
VirtualAlloc, WaitForSingleObject, CreateThread, Sleep, SeDebugPrivilege, QueryPerformanceCounter, GetIpAddrTable, AllocateAndInitializeSid, CheckTokenMembership, OpenProcessToken, have more...
Languages:
python
YARA: Found
Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Bughatch.yarwww.elastic.co
BUGHATCH Malware Analysis — Elastic Security Labs
Elastic Security has performed a deep technical analysis of the BUGHATCH malware. This includes capabilities as well as defensive countermeasures.
#technique
Massayo is a small proof-of-concept Rust library based on UnhookingPOC, which removes AV/EDR hooks in a given system DLL.
https://github.com/thiagopeixoto/massayo
Massayo is a small proof-of-concept Rust library based on UnhookingPOC, which removes AV/EDR hooks in a given system DLL.
https://github.com/thiagopeixoto/massayo
GitHub
GitHub - thiagopeixoto/massayo: Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL
Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL - thiagopeixoto/massayo
#technique
https://www.secureworks.com/research/azure-active-directory-pass-through-authentication-flaws
https://www.secureworks.com/research/azure-active-directory-pass-through-authentication-flaws
Sophos
Azure Active Directory Pass-Through Authentication Flaws
In May 2022, Sophos® Counter Threat Unit™ (CTU) researchers analyzed how the protocols used by Pass-Through Authentication could be exploited.