#ParsedReport
08-09-2022
Crimeware Trends \| Ransomware Developers Turn to Intermittent Encryption to Evade Detection
https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection
Actors/Campaigns:
Blackcat
Qilin
Threats:
Blackbasta
Qyick
Blackcat
Playcrypt
Conti
Industry:
Healthcare, Education, Financial, Energy
Geo:
Asia, Argentina, Africa, Russian, German
IOCs:
Hash: 4
Algorithms:
chacha20, aes
Win API:
LockFile
Languages:
rust
08-09-2022
Crimeware Trends \| Ransomware Developers Turn to Intermittent Encryption to Evade Detection
https://www.sentinelone.com/labs/crimeware-trends-ransomware-developers-turn-to-intermittent-encryption-to-evade-detection
Actors/Campaigns:
Blackcat
Qilin
Threats:
Blackbasta
Qyick
Blackcat
Playcrypt
Conti
Industry:
Healthcare, Education, Financial, Energy
Geo:
Asia, Argentina, Africa, Russian, German
IOCs:
Hash: 4
Algorithms:
chacha20, aes
Win API:
LockFile
Languages:
rust
SentinelOne
Crimeware Trends | Ransomware Developers Turn to Intermittent Encryption to Evade Detection
Partially encrypting victims' files improves ransomware speed and aids evasion. First seen in LockFile, the technique is now being widely adopted.
#ParsedReport
08-09-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government
Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows registry, windows service
Algorithms:
rc4, base64
Functions:
GetUpdates
Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary
Platforms:
x86
YARA: Found
Links:
08-09-2022
Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
https://www.mandiant.com/resources/blog/likely-iranian-threat-actor-conducts-politically-motivated-disruptive-activity-against
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Axiom
Threats:
Roadsweep
Chimneysweep
Zeroclear
Dustman_wiper
Markirat
Mosesstaff
Metasploit_tool
Delf
Netstat_tool
Process_injection_technique
Timestomp_technique
Industry:
Government
Geo:
Israeli, Iran, Lebanon, Albania, Bahrain, Iranian
TTPs:
Tactics: 3
Technics: 19
IOCs:
Domain: 9
File: 12
Hash: 20
IP: 1
Path: 4
Coin: 1
Registry: 2
Softs:
telegram, windows registry, windows service
Algorithms:
rc4, base64
Functions:
GetUpdates
Win API:
FindFirstFileW, socket, FindNextFileW, GetFileSize, DeviceIoControl, GetSystemDirectoryW, GetProcAddress, LoadLibrary
Platforms:
x86
YARA: Found
Links:
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/bypassuac\_silentcleanup.rbGoogle Cloud Blog
ROADSWEEP Ransomware Targets the Albanian Government | Google Cloud Blog
Mandiant identified the ROADSWEEP ransomware family which targeted the Albanian government in a politically motivated disruptive operation. Learn more.
#ParsedReport
08-09-2022
Lazarus and the tale of three RATs
http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
Actors/Campaigns:
Lazarus (motivation: cyber_espionage)
Threats:
Vsingle
Yamabot
Magicrat
Bespoke
Log4shell_vuln
Dtrack_rat
Mauicrypt
Netstat_tool
Putty_tool
Plink
Impacket_tool
Credential_harvesting_technique
Mimikatz
Procdump_tool
Wevtutil_tool
Adfind_tool
Industry:
Government, Energy
Geo:
Japan, Korean, Canada, Korea, Japanese
TTPs:
Tactics: 4
Technics: 21
IOCs:
IP: 12
File: 24
Path: 13
Registry: 12
Coin: 1
Hash: 15
Url: 40
Softs:
windows defender, 3proxy, active directory, vmware horizon, vssadmin
Algorithms:
base64
Win API:
select
Languages:
golang, php, java, python
Platforms:
x86
Links:
08-09-2022
Lazarus and the tale of three RATs
http://blog.talosintelligence.com/2022/09/lazarus-three-rats.html
Actors/Campaigns:
Lazarus (motivation: cyber_espionage)
Threats:
Vsingle
Yamabot
Magicrat
Bespoke
Log4shell_vuln
Dtrack_rat
Mauicrypt
Netstat_tool
Putty_tool
Plink
Impacket_tool
Credential_harvesting_technique
Mimikatz
Procdump_tool
Wevtutil_tool
Adfind_tool
Industry:
Government, Energy
Geo:
Japan, Korean, Canada, Korea, Japanese
TTPs:
Tactics: 4
Technics: 21
IOCs:
IP: 12
File: 24
Path: 13
Registry: 12
Coin: 1
Hash: 15
Url: 40
Softs:
windows defender, 3proxy, active directory, vmware horizon, vssadmin
Algorithms:
base64
Win API:
select
Languages:
golang, php, java, python
Platforms:
x86
Links:
https://github.com/3proxy/3proxyCisco Talos Blog
Lazarus and the tale of three RATs
Cisco Talos assesses with high confidence these attacks have been conducted by the North Korean state-sponsored threat actor Lazarus Group.
#technique
Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.
https://github.com/CodeXTF2/cobaltstrike-headless
Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client.
https://github.com/CodeXTF2/cobaltstrike-headless
GitHub
GitHub - CodeXTF2/cobaltstrike-headless: Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt…
Aggressorscript that turns the headless aggressor client into a (mostly) functional cobalt strike client. - CodeXTF2/cobaltstrike-headless
#ParsedReport
09-09-2022
LUNA Ransomware Attack Pattern Analysis. Key Takeaways
https://www.elastic.co/security-labs/luna-ransomware-attack-pattern
Threats:
Luna
Seth_locker
Cuba
Geo:
Switzerland
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 974
Algorithms:
base64, aes, curve25519
Win API:
NtLmSsp
Languages:
python, rust
YARA: Found
Links:
09-09-2022
LUNA Ransomware Attack Pattern Analysis. Key Takeaways
https://www.elastic.co/security-labs/luna-ransomware-attack-pattern
Threats:
Luna
Seth_locker
Cuba
Geo:
Switzerland
TTPs:
Tactics: 4
Technics: 0
IOCs:
File: 974
Algorithms:
base64, aes, curve25519
Win API:
NtLmSsp
Languages:
python, rust
YARA: Found
Links:
https://github.com/dalek-cryptography/x25519-dalek
https://github.com/elastic/protections-artifacts/blob/main/behavior/rules/defense\_evasion\_attempt\_to\_disable\_windows\_defender\_services.tomlwww.elastic.co
LUNA Ransomware Attack Pattern Analysis — Elastic Security Labs
In this research publication, we'll explore the LUNA attack pattern — a cross-platform ransomware variant.
#ParsedReport
09-09-2022
Charming Kitten: Can We Have A Meeting?
https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Apt42 (motivation: cyber_espionage)
Phosphorus (motivation: cyber_espionage)
Industry:
Education, Government, Financial, Healthcare
Geo:
Iraq, American, Iranian, Iran, Syria, French, France, Irans, Israel, Libya, Africa
IOCs:
Url: 3
Domain: 78
IP: 13
Email: 5
Hash: 1
Softs:
zoom
09-09-2022
Charming Kitten: Can We Have A Meeting?
https://blog.certfa.com/posts/charming-kitten-can-we-wave-a-meeting
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Apt42 (motivation: cyber_espionage)
Phosphorus (motivation: cyber_espionage)
Industry:
Education, Government, Financial, Healthcare
Geo:
Iraq, American, Iranian, Iran, Syria, French, France, Irans, Israel, Libya, Africa
IOCs:
Url: 3
Domain: 78
IP: 13
Email: 5
Hash: 1
Softs:
zoom
Certfa
Charming Kitten: “Can We Have A Meeting?” - Certfa Lab
Our recent investigation at Certfa Lab, the APT42 has been running multiple phishing campaigns since late 2021 and some of them are ongoing and still active.
В отчетах попадаются списки виндовых сервисов, которые стопаются вредоносом. Запилил парсинг их названий. С понедельника они тоже будут извлекаться из отчетов и добавляться в сообщения в телеге.
#ParsedReport
11-09-2022
Evasive Shikitega Linux malware drops Monero cryptominer
https://www.malwarebytes.com/blog/news/2022/09/evasive-shikitega-linux-malware-drops-monero-cryptominer
Threats:
Shikitega
Alien
Mettle
Metasploit_tool
Meterpreter_tool
Xmrig_miner
Geo:
Japanese
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
Algorithms:
xor, shikata_ga_nai
11-09-2022
Evasive Shikitega Linux malware drops Monero cryptominer
https://www.malwarebytes.com/blog/news/2022/09/evasive-shikitega-linux-malware-drops-monero-cryptominer
Threats:
Shikitega
Alien
Mettle
Metasploit_tool
Meterpreter_tool
Xmrig_miner
Geo:
Japanese
CVEs:
CVE-2021-4034 [Vulners]
Vulners: Score: 7.2, CVSS: 4.4,
Vulners: Exploitation: True
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- polkit project polkit (*)
- redhat enterprise linux desktop (7.0)
- redhat enterprise linux workstation (7.0)
- redhat enterprise linux for scientific computing (7.0)
- redhat enterprise linux server (7.0, 6.0)
have more...
CVE-2021-3493 [Vulners]
Vulners: Score: 7.2, CVSS: 4.1,
Vulners: Exploitation: Unknown
X-Force: Risk: 7.8
X-Force: Patch: Official fix
Soft:
- canonical ubuntu linux (<18.04, <20.04, <20.10)
Algorithms:
xor, shikata_ga_nai
Vulners Database
CVE-2021-4034 - vulnerability database | Vulners.com
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users according predefined policies. The current version of p...
#ParsedReport
12-09-2022
The Curious Case of Monti Ransomware: A Real-World Doppelganger
https://blogs.blackberry.com/en/2022/09/the-curious-case-of-monti-ransomware-a-real-world-doppelganger
Threats:
Monti
Conti
Log4shell_vuln
Anydesk_tool
Cobalt_strike
Gmer_tool
Megasync_tool
Mimikatz
Passthehash_technique
Netscan_tool
Putty_tool
Babuk
Yashma
Yanluowang
Chaos
Industry:
Financial
CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 9
Domain: 2
Hash: 7
Softs:
esxi, vmware horizon, chrome, active directory, internet explorer, psexec, winscp, local security authority
Algorithms:
xor, base64
YARA: Found
Links:
12-09-2022
The Curious Case of Monti Ransomware: A Real-World Doppelganger
https://blogs.blackberry.com/en/2022/09/the-curious-case-of-monti-ransomware-a-real-world-doppelganger
Threats:
Monti
Conti
Log4shell_vuln
Anydesk_tool
Cobalt_strike
Gmer_tool
Megasync_tool
Mimikatz
Passthehash_technique
Netscan_tool
Putty_tool
Babuk
Yashma
Yanluowang
Chaos
Industry:
Financial
CVEs:
CVE-2021-44228 [Vulners]
Vulners: Score: 9.3, CVSS: 4.5,
Vulners: Exploitation: True
X-Force: Risk: 10
X-Force: Patch: Official fix
Soft:
- apache log4j (2.0, 2.0, 2.0, 2.0, <2.15.0, <2.3.1, <2.12.2)
- siemens sppa-t3000 ses3000 firmware (*)
- siemens logo\! soft comfort (*)
- siemens spectrum power 4 (4.70, 4.70, <4.70, 4.70)
- siemens siveillance control pro (*)
have more...
TTPs:
Tactics: 2
Technics: 0
IOCs:
File: 9
Domain: 2
Hash: 7
Softs:
esxi, vmware horizon, chrome, active directory, internet explorer, psexec, winscp, local security authority
Algorithms:
xor, base64
YARA: Found
Links:
https://github.com/sadshade/veeam-credsBlackBerry
The Curious Case of “Monti” Ransomware: A Real-World Doppelganger
While working a recent ransomware incident, BlackBerry identified a group whose name and TTPs mimicked the long-standing, popular ransomware crew Conti. Furthermore, the encryptor payload used in the attack was taken from the original group and modified for…
#ParsedReport
12-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
Asia, Belarus, China, Ukrainian, Asian, Russia
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualProtect, NtGlobalFlag, GetProcAddress, LoadLibraryA, VirtualAlloc, VirtualFree, ExitThread, RtlDecompressBuffer
12-09-2022
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
https://www.cybereason.com/blog/threat-analysis-report-plugx-rat-loader-evolution
Actors/Campaigns:
Emissary_panda
Threats:
Plugx_rat
Dll_sideloading_technique
Proxylogon_exploit
Thor
Industry:
Aerospace, Government
Geo:
Asia, Belarus, China, Ukrainian, Asian, Russia
TTPs:
Tactics: 6
Technics: 0
IOCs:
Hash: 18
File: 3
Algorithms:
rc4
Win API:
GetSystemTime, VirtualProtect, NtGlobalFlag, GetProcAddress, LoadLibraryA, VirtualAlloc, VirtualFree, ExitThread, RtlDecompressBuffer
Cybereason
THREAT ANALYSIS REPORT: PlugX RAT Loader Evolution
PlugX is a post-exploitation modular RAT (Remote Access Trojan), which is known for its multiple functionalities such as data exfiltration, keystroke grabbing, backdoor functionality, and utilizing DLL-Sideloading techniques for evading security solutions...
#ParsedReport
12-09-2022
BRONZE PRESIDENT Targets Government Officials
https://www.secureworks.com/blog/bronze-president-targets-government-officials
Actors/Campaigns:
Red_delta (motivation: government_sponsored)
Threats:
Plugx_rat
Cobalt_strike
Industry:
Government
Geo:
Ukraine, Myanmar, Chinese, America, Vietnam, Suriname, China
IOCs:
File: 10
Hash: 112
IP: 3
Softs:
opera, avastbrowser
Algorithms:
xor
Win API:
GetCommandLineW, EnumThreadWindows, CheckRemoteDebuggerPresent
12-09-2022
BRONZE PRESIDENT Targets Government Officials
https://www.secureworks.com/blog/bronze-president-targets-government-officials
Actors/Campaigns:
Red_delta (motivation: government_sponsored)
Threats:
Plugx_rat
Cobalt_strike
Industry:
Government
Geo:
Ukraine, Myanmar, Chinese, America, Vietnam, Suriname, China
IOCs:
File: 10
Hash: 112
IP: 3
Softs:
opera, avastbrowser
Algorithms:
xor
Win API:
GetCommandLineW, EnumThreadWindows, CheckRemoteDebuggerPresent
Secureworks
BRONZE PRESIDENT Targets Government Officials
The likely Chinese government-sponsored threat group uses decoy documents and PlugX malware to compromise targets.
#ParsedReport
12-09-2022
BUGHATCH Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/bughatch-malware-analysis
Threats:
Bughatch
Cuba
Termite
Process_injection_technique
Mimikatz
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 5
File: 4
Path: 1
Softs:
visual studio
Algorithms:
xor, base64
Functions:
CreateThread, RemoveEntryRecvLinkedList
Win API:
VirtualAlloc, WaitForSingleObject, CreateThread, Sleep, SeDebugPrivilege, QueryPerformanceCounter, GetIpAddrTable, AllocateAndInitializeSid, CheckTokenMembership, OpenProcessToken, have more...
Languages:
python
YARA: Found
Links:
12-09-2022
BUGHATCH Malware Analysis. Key takeaways
https://www.elastic.co/security-labs/bughatch-malware-analysis
Threats:
Bughatch
Cuba
Termite
Process_injection_technique
Mimikatz
TTPs:
Tactics: 4
Technics: 0
IOCs:
Hash: 5
File: 4
Path: 1
Softs:
visual studio
Algorithms:
xor, base64
Functions:
CreateThread, RemoveEntryRecvLinkedList
Win API:
VirtualAlloc, WaitForSingleObject, CreateThread, Sleep, SeDebugPrivilege, QueryPerformanceCounter, GetIpAddrTable, AllocateAndInitializeSid, CheckTokenMembership, OpenProcessToken, have more...
Languages:
python
YARA: Found
Links:
https://github.com/elastic/protections-artifacts/blob/main/yara/rules/Windows\_Trojan\_Bughatch.yarwww.elastic.co
BUGHATCH Malware Analysis — Elastic Security Labs
Elastic Security has performed a deep technical analysis of the BUGHATCH malware. This includes capabilities as well as defensive countermeasures.
#technique
Massayo is a small proof-of-concept Rust library based on UnhookingPOC, which removes AV/EDR hooks in a given system DLL.
https://github.com/thiagopeixoto/massayo
Massayo is a small proof-of-concept Rust library based on UnhookingPOC, which removes AV/EDR hooks in a given system DLL.
https://github.com/thiagopeixoto/massayo
GitHub
GitHub - thiagopeixoto/massayo: Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL
Massayo is a small proof-of-concept Rust library which removes AV/EDR hooks in a given system DLL - thiagopeixoto/massayo
#technique
https://www.secureworks.com/research/azure-active-directory-pass-through-authentication-flaws
https://www.secureworks.com/research/azure-active-directory-pass-through-authentication-flaws
Sophos
Azure Active Directory Pass-Through Authentication Flaws
In May 2022, Sophos® Counter Threat Unit™ (CTU) researchers analyzed how the protocols used by Pass-Through Authentication could be exploited.
#technique
In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed.
https://codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html
In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attack difficult to detect in environments where no additional security products are installed.
https://codewhitesec.blogspot.com/2022/09/attacks-on-sysmon-revisited-sysmonente.html
Blogspot
CODE WHITE | Blog: Attacks on Sysmon Revisited - SysmonEnte
In this blogpost we demonstrate an attack on the integrity of Sysmon which generates a minimal amount of observable events making this attac...
#ParsedReport
13-09-2022
Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO
https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Phosphorus
Apt42
Cosmic_lynx
Threats:
Credential_harvesting_technique
Industry:
Education, Healthcare
Geo:
Israel, Russia
IOCs:
File: 5
Hash: 2
Domain: 2
Softs:
telegram
13-09-2022
Look What You Made Me Do: TA453 Uses Multi-Persona Impersonation to Capitalize on FOMO
https://www.proofpoint.com/us/blog/threat-insight/ta453-uses-multi-persona-impersonation-capitalize-fomo
Actors/Campaigns:
Cleaver (motivation: cyber_espionage)
Phosphorus
Apt42
Cosmic_lynx
Threats:
Credential_harvesting_technique
Industry:
Education, Healthcare
Geo:
Israel, Russia
IOCs:
File: 5
Hash: 2
Domain: 2
Softs:
telegram
Proofpoint
TA453 Uses Impersonation to Capitalize on FOMO | Proofpoint US
In 2022, TA453 used multi-persona impersonation to turn FOMO into a cybersecurity risk. Proofpoint details the FOMO cyber-attack, what it is, how it works, and more.
#ParsedReport
13-09-2022
. Risk reminder about the large -scale dissemination of the "demon thief" the stolen Trojan horse
https://www.antiy.cn/research/notice&report/research_report/20220913.html
Threats:
Sandbox_evasion_technique
Geo:
China, Malaysia
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 49
Path: 14
File: 18
Registry: 2
IP: 1
Domain: 3
Url: 45
Softs:
foxmail
Algorithms:
aes, base64, zip
Platforms:
intel, x86
13-09-2022
. Risk reminder about the large -scale dissemination of the "demon thief" the stolen Trojan horse
https://www.antiy.cn/research/notice&report/research_report/20220913.html
Threats:
Sandbox_evasion_technique
Geo:
China, Malaysia
TTPs:
Tactics: 1
Technics: 0
IOCs:
Hash: 49
Path: 14
File: 18
Registry: 2
IP: 1
Domain: 3
Url: 45
Softs:
foxmail
Algorithms:
aes, base64, zip
Platforms:
intel, x86
www.antiy.cn
关于“魔盗”窃密木马大规模传播的风险提示
近期,CNCERT和安天联合监测到一批伪装成CorelDraw、Notepad++、IDA Pro、WinHex等多款实用软件进行传播的窃密木马。通过跟踪监测发现其每日上线境内肉鸡数(以IP数计算)最多已超过1.3万,由于该窃密木马会收集浏览器书签、邮箱账户等信息,故我们将命名为“魔盗”。
#ParsedReport
13-09-2022
Phishing Campaign targets Japanese tax payers
https://blog.cyble.com/2022/09/13/phishing-campaign-targets-japanese-tax-payers
Actors/Campaigns:
Roaming_mantis
Threats:
Fakecop
Mantis_botnet
Industry:
Financial
Geo:
Japan, Singapore, Georgia, India, China, Australia, Japanese, Dubai
TTPs:
Tactics: 7
Technics: 10
IOCs:
Url: 57
File: 1
Hash: 1
Softs:
android
13-09-2022
Phishing Campaign targets Japanese tax payers
https://blog.cyble.com/2022/09/13/phishing-campaign-targets-japanese-tax-payers
Actors/Campaigns:
Roaming_mantis
Threats:
Fakecop
Mantis_botnet
Industry:
Financial
Geo:
Japan, Singapore, Georgia, India, China, Australia, Japanese, Dubai
TTPs:
Tactics: 7
Technics: 10
IOCs:
Url: 57
File: 1
Hash: 1
Softs:
android
Cyble
Cyble - Phishing Campaign Targets Japanese Tax Payers
Cyble, Research & Intelligence Labs analyzes the National Tax Agency Phishing Campaign targeting Japanese taxpayers.
#ParsedReport
13-09-2022
TikTok Breached by BlueHornet
https://cyberint.com/blog/research/tiktok-breached-by-bluehornet
Actors/Campaigns:
Bluehornet
Industry:
Government
Geo:
Iran, Belarus, American, Usa, Chinese, Korea, China, Russia
Softs:
tiktok, wechat
13-09-2022
TikTok Breached by BlueHornet
https://cyberint.com/blog/research/tiktok-breached-by-bluehornet
Actors/Campaigns:
Bluehornet
Industry:
Government
Geo:
Iran, Belarus, American, Usa, Chinese, Korea, China, Russia
Softs:
tiktok, wechat
Cyberint
TikTok Breached by BlueHornet
The breach of the popular social network TikTok occurred, revealing 1.7 billion records and relations to another popular Chinese app - WeChat
#ParsedReport
13-09-2022
Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices
https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices
Threats:
Xorddos
Tsunami_botnet
Xmrig_miner
Netstat_tool
Industry:
Iot
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 3
Url: 1
Domain: 2
Hash: 19
Softs:
microsoft 365 defender, microsoft defender for endpoint, curl, sudo, unix, microsoft edge, microsoft defender
Algorithms:
xor, crc
Functions:
fork, setsid, signal, dec_conf, readlink, the, unhide, IOCTL, tcp4_seq_show, tcp6_seq_show, have more...
Platforms:
intel
Links:
13-09-2022
Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices
https://www.microsoft.com/security/blog/2022/05/19/rise-in-xorddos-a-deeper-look-at-the-stealthy-ddos-malware-targeting-linux-devices
Threats:
Xorddos
Tsunami_botnet
Xmrig_miner
Netstat_tool
Industry:
Iot
TTPs:
Tactics: 3
Technics: 0
IOCs:
File: 3
Url: 1
Domain: 2
Hash: 19
Softs:
microsoft 365 defender, microsoft defender for endpoint, curl, sudo, unix, microsoft edge, microsoft defender
Algorithms:
xor, crc
Functions:
fork, setsid, signal, dec_conf, readlink, the, unhide, IOCTL, tcp4_seq_show, tcp6_seq_show, have more...
Platforms:
intel
Links:
https://github.com/jermeyyy/rooty
https://github.com/mncoppola/suterusuMicrosoft News
Rise in XorDdos: A deeper look at the stealthy DDoS malware targeting Linux devices
Observing a 254% increase in activity over the last six months from a versatile Linux trojan called XorDdos, the Microsoft 365 Defender research team provides in-depth analysis into this stealthy malware's capabilities and key infection signs.