CTT Report Hub
3.22K subscribers
8.01K photos
6 videos
67 files
11.7K links
Threat Intelligence Report Hub
https://cyberthreat.tech
ООО Технологии киберугроз
Contact: @nikolaiav
Download Telegram
#ParsedReport
10-01-2023

A Deep Dive Into poweRAT: a Newly Discovered Stealer/RAT Combo Polluting PyPI

https://blog.phylum.io/a-deep-dive-into-powerat-a-newly-discovered-stealer/rat-combo-polluting-pypi

Threats:
Powerat
Xrat_rat

Industry:
Government

IOCs:
File: 7
Domain: 1

Softs:
flask, telegram, discord

Algorithms:
lzma, base64, zip

Functions:
run_with_cloudflared

Languages:
javascript, python

Links:
https://github.com/cloudflare/cloudflared
#ParsedReport
11-01-2023

A View Into Web(View) Attacks in Android

https://securityintelligence.com/posts/view-into-webview-attacks-android

Threats:
Fake-trusteer
Zeus_sphinx
Zeus
Sphinx
Icedid
Trickbot
Rustock
Flubot
Sharkbot
Hydra

Industry:
Financial, E-commerce

IOCs:
Hash: 2

Softs:
android, google chrome, chrome

Algorithms:
base64

Functions:
val, loadUrl, getCookie

Languages:
javascript
#ParsedReport
11-01-2023

NeedleDropper

https://decoded.avast.io/threatresearch/needledropper/?utm_source=rss&utm_medium=rss&utm_campaign=needledropper

Threats:
Needledropper
Formbook

TTPs:
Tactics: 1
Technics: 0

IOCs:
File: 5
Path: 1
Hash: 9

Softs:
discord

Win API:
CryptDecrypt, WriteProcessMemory

Languages:
visual_basic, autoit

Links:
https://github.com/avast/ioc/tree/master/NeedleDropper
#ParsedReport
11-01-2023

Raspberry Robins botnet second life

https://blog.sekoia.io/raspberry-robins-botnet-second-life

Actors/Campaigns:
Evil_corp (motivation: financially_motivated)
Turla
Apt31

Threats:
Raspberry_robin
Qnapworm
Dridex
Socgholish_loader
Bumblebee
Truebot
Icedid
Dns_hijacking_technique
Quantum_locker
Retadup
Andromeda
Aurora

Industry:
Education

Geo:
Kazakhstan, France, Romania, Oman, Russian, Bahrain, Germany, Morocco

IOCs:
Domain: 3

Softs:
microsoft jscript
#ParsedReport
11-01-2023

DDosia Project: Volunteers Carrying out NoName(057)16s Dirty Work

https://decoded.avast.io/martinchlumecky/ddosia-project/?utm_source=rss&utm_medium=rss&utm_campaign=ddosia-project

Actors/Campaigns:
Noname057
Killnet

Threats:
Ddosia_botnet
Bobiks
Redline_stealer
Nmap_tool
Prestige_ransomware

Industry:
Education, Financial, Healthcare, Government, Transport, Aerospace

Geo:
Polish, Polands, Belarus, Canada, Germany, Ukrainian, Moscow, Ukraine, Poland, Russian, Lithuania, Berlin, Russia, Latvia

IOCs:
File: 3
IP: 1
Url: 2

Softs:
telegram, macos, pyinstaller, nginx

Algorithms:
zip

Languages:
python

Links:
https://github.com/avast/ioc/blob/master/Bobik/targets.xlsx
#ParsedReport
11-01-2023

StrongPity espionage campaign targeting Android users

https://www.welivesecurity.com/2023/01/10/strongpity-espionage-campaign-targeting-android-users

Threats:
Strongpity
Httrack_tool
Bahamut

Geo:
Syrian, Ukraine

TTPs:
Tactics: 7
Technics: 15

IOCs:
Hash: 13
File: 3
Domain: 2
IP: 2

Softs:
android, android telegram, telegram, tinder, wechat, instagram, instagram.android

Algorithms:
aes, cbc

YARA: Found
#ParsedReport
11-01-2023

Gootkit Loader Actively Targets Australian Healthcare Industry

https://www.trendmicro.com/en_us/research/23/a/gootkit-loader-actively-targets-the-australian-healthcare-indust.html

Actors/Campaigns:
Stone_panda

Threats:
Gootkit
Gootloader
Cobalt_strike
Dll_sideloading_technique
Beacon
Process_injection_technique
Bloodhound_tool
Trojan.win32.frs.vsnw0ek22
Follina_vuln
Trojan.js.downloader.ac
Trojan.ps1.powload.tiaoeno

Industry:
Healthcare, Media

Geo:
Australia, Australian

TTPs:
Tactics: 3
Technics: 0

IOCs:
File: 7
Path: 1
IP: 1
Hash: 4
Url: 2

Softs:
wordpress

Algorithms:
zip

Languages:
javascript, php
#ParsedReport
11-01-2023

Dark Pink

https://blog.group-ib.com/dark-pink-apt

Actors/Campaigns:
Darkpink (motivation: financially_motivated, cyber_espionage)
Axiom
Saaiwc

Threats:
Telepowerbot
Kamikakabot
Cucky_stealer
Ctealer_stealer
Dll_sideloading_technique
Powersploit
Uac_bypass_technique

Industry:
Government

Geo:
Indonesian, Cambodia, Iran, China, Pakistan, Vietnamese, Korea, Philippines, Vietnam, Malaysia, Apac, Chinese, Indonesia

TTPs:
Tactics: 2
Technics: 0

IOCs:
Registry: 33
File: 23
Email: 6
Path: 4
Hash: 12

Softs:
telegram, windows defender, chrome, coccoc, chromium, amigo, kometa, nichrome, comodo dragon, vivaldi, have more...

Algorithms:
xor, base64, zip

Win API:
DriveType
#ParsedReport
11-01-2023

Malicious JARs and Polyglot files: Who do you think you JAR?

https://www.deepinstinct.com/blog/malicious-jars-and-polyglot-files-who-do-you-think-you-jar

Threats:
Polyglot
Strrat
Ratty_rat

Geo:
Bulgarian

CVEs:
CVE-2020-1464 [Vulners]
Vulners: Score: 2.1, CVSS: 2.5,
Vulners: Exploitation: True
X-Force: Risk: 5.3
X-Force: Patch: Official fix
Soft:
- microsoft windows 10 (-, 1607, 1709, 1803, 1809, 1903, 1909, 2004)
- microsoft windows 7 (-)
- microsoft windows 8.1 (-)
- microsoft windows rt 8.1 (-)
- microsoft windows server 2008 (-, r2)
have more...

TTPs:
Tactics: 3
Technics: 4

IOCs:
Hash: 40
Domain: 1
Url: 1

Softs:
discord

Algorithms:
zip

Languages:
java

Links:
https://github.com/deepinstinct/RattyConfigExtractor
https://github.com/deepinstinct/JAR-Polyglot-POC
https://github.com/Polydet/polyglot-database
#ParsedReport
12-01-2023

NoName057(16) The Pro-Russian Hacktivist Group Targeting NATO

https://www.sentinelone.com/labs/noname05716-the-pro-russian-hacktivist-group-targeting-nato

Actors/Campaigns:
Noname057 (motivation: hacktivism)
Killnet (motivation: hacktivism)

Threats:
Bobiks
Ddosia_botnet

Industry:
Government, Telco, Financial, Transport

Geo:
Lithuania, Czech, Poland, Ukraine, Russian, Denmark, Polish, Danish, Bulgarian, Dutch, Russia, Ukrainian

IOCs:
Domain: 3
IP: 5
Url: 5
Hash: 12
Email: 1

Softs:
telegram, pyinstaller, macos, android

Languages:
python, golang
#ParsedReport
12-01-2023

Lockbit 3.0 AKA Lockbit Black is here, with a new icon, new ransom note, new wallpaper, but less evasiveness?

https://minerva-labs.com/blog/lockbit-3-0-aka-lockbit-black-is-here-with-a-new-icon-new-ransom-note-new-wallpaper-but-less-evasiveness

Threats:
Lockbit
Blackcat
Uac_bypass_technique

Geo:
Romanian, Russian, Syria, Belarusian, Moldova, Azerbaijani, Ukrainian

TTPs:
Tactics: 1
Technics: 0

IOCs:
Hash: 1
Registry: 1

Softs:
msexchange, onenote, thebat, wordpad, windows defender

Algorithms:
xor

Functions:
Windows

Win API:
GetSystemDefaultUILanguage, GetUserDefaultUILanguage, NtSetInformationThread

Win Services:
GxVss, GxBlr, GxFWD, GxCVD, GxCIMgr, ocssd, dbsnmp, synctime, agntsvc, isqlplussvc, have more...
#ParsedReport
12-01-2023

New updated IceXLoader claims thousands of victims around the world

https://minerva-labs.com/blog/new-updated-icexloader-claims-thousands-of-victims-around-the-world

Threats:
Icexloader
Process_hollowing_technique
Nimbda_loader
Bazarnimrod
Process_injection_technique

Geo:
Chinese

TTPs:

IOCs:
Path: 8
Registry: 2
File: 4
Command: 2
Hash: 4
Url: 1

Softs:
net framework, windows defender

Win API:
AmsiScanBuffer

Languages:
javascript
#ParsedReport
12-01-2023

Rhadamanthys: New Stealer Spreading Through Google Ads

https://blog.cyble.com/2023/01/12/rhadamanthys-new-stealer-spreading-through-google-ads

Threats:
Rhadamanthys
Anydesk_tool
Antivm
Beacon
Process_injection_technique

Industry:
Financial

TTPs:
Tactics: 8
Technics: 19

IOCs:
Url: 1
File: 5
Domain: 12
Hash: 6

Softs:
zoom, pyinstaller, virtualbox, chrome, opera, pale moon, coccoc, zcash, winscp), (foxmail, have more...

Algorithms:
base64

Win API:
CreateThread, BitBlt

Languages:
python
#ParsedReport
12-01-2023

STOP/DJVU Ransomware

https://minerva-labs.com/blog/stop-djvu-ransomware

Threats:
Stop_ransomware
Process_hollowing_technique
Vidar_stealer
Gozi

Industry:
Financial

Geo:
Tajikistan, Ukraine, Kazakhstan, Uzbekistan, Azerbaijan, Kyrgyzstan, Belarus, Russia, Armenia, Syria

IOCs:
Registry: 1
Path: 2
Url: 2
File: 3

Win API:
InternetReadFile, ShellExecuteA

Platforms:
x86, intel