Thu, 17 Mar 2022 00:27:25 +0000
Malicious Word Files Disguised as Product Introduction
https://asec.ahnlab.com/en/32609/
ASEC BLOG
Malicious Word Files Disguised as Product Introduction - ASEC BLOG
The ASEC analysis team has discovered a word document that is in the same category as the document introduced in the post <Word File Disguised as a Design Modification Request for Information Theft>, uploaded in December last year. The title of the document…
Thu, 17 Mar 2022 16:18:09 +0000
Exposing initial access broker with ties to Conti
https://blog.google/threat-analysis-group/exposing-initial-access-broker-ties-conti/
Google
Exposing initial access broker with ties to Conti
Threat Analysis Group (TAG) observed a financially motivated threat actor we refer to as EXOTIC LILY, exploiting a 0day in Microsoft MSHTML (CVE-2021-40444). Investigating this group's activity, we determined they are an Initial Access Broker (IAB) who appear…
Thu, 17 Mar 2022 17:36:12 +0000
Dissecting the Ransomless AntiWar Malware: Zero Demand for Ransom
https://blog.cyble.com/2022/03/17/dissecting-the-ransomless-antiwar-malware-zero-demand-for-ransom/
Cyble
Dissecting the Ransomless AntiWar Malware: Zero Demand for Ransom
Cyble Research Labs recently came across a ransomware sample allegedly targeting Russia and sending out a message to stop the war.
Fri, 18 Mar 2022 00:22:54 +0000
ASEC Weekly Malware Statistics (March 7th, 2022 – March 13th, 2022)
https://asec.ahnlab.com/en/32677/
ASEC BLOG
ASEC Weekly Malware Statistics (March 7th, 2022 - March 13th, 2022) - ASEC BLOG
The ASEC analysis team is using the ASEC automatic analysis system RAPIT to categorize and respond to known malware. This post will list weekly statistics collected from March 7th, 2022 (Monday) to March 13th, 2022 (Sunday). For the main category, info-stealer…
Fri, 18 Mar 2022 11:26:43 +0000
Mēris and TrickBot standing on the shoulders of giants
https://decoded.avast.io/martinhron/meris-and-trickbot-standing-on-the-shoulders-of-giants/?utm_source=rss&utm_medium=rss&utm_campaign=meris-and-trickbot-standing-on-the-shoulders-of-giants
Gendigital
Mēris and TrickBot standing on the shoulders of giants
Introduction to MikroTik Vulnerabilities
Fri, 18 Mar 2022 22:57:11 +0000
Double header: IsaacWiper and CaddyWiper
https://blog.malwarebytes.com/threat-intelligence/2022/03/double-header-isaacwiper-and-caddywiper/
ThreatDown by Malwarebytes
Double header: IsaacWiper and CaddyWiper - ThreatDown by Malwarebytes
As war in Ukraine rages, new destructive malware continues to be discovered. In this short blog post, we will review IsaacWiper and CaddyWiper, two new wipers that do not have much in common based on…
Mon, 21 Mar 2022 02:01:15 +0000
APT35 Automates Initial Access Using ProxyShell
https://thedfirreport.com/2022/03/21/apt35-automates-initial-access-using-proxyshell/
The DFIR Report
PHOSPHORUS Automates Initial Access Using ProxyShell
In December 2021, we observed an adversary exploiting the Microsoft Exchange ProxyShell vulnerabilities to gain initial access and execute code via multiple web shells. The overlap of activities an…
Mon, 21 Mar 2022 05:46:25 +0000
BitRAT Disguised as Windows Product Key Verification Tool Being Distributed
https://asec.ahnlab.com/en/32781/
ASEC
BitRAT Disguised as Windows Product Key Verification Tool Being Distributed - ASEC
BitRAT Disguised as Windows Product Key Verification Tool Being Distributed ASEC
Mon, 21 Mar 2022 09:24:18 +0000
Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain
https://www.proofpoint.com/us/blog/threat-insight/serpent-no-swiping-new-backdoor-targets-french-entities-unique-attack-chain
Proofpoint
Serpent, No Swiping! New Backdoor Targets French Entities with Unique Attack Chain | Proofpoint US
Key Findings Proofpoint identified a targeted attack leveraging an open-source package installer Chocolatey to deliver a backdoor. The attack targeted French entities in the construction,
Mon, 21 Mar 2022 21:03:40 +0000
From BlackMatter to BlackCat: Analyzing two attacks from one affiliate
http://blog.talosintelligence.com/2022/03/from-blackmatter-to-blackcat-analyzing.html
Cisco Talos Blog
From BlackMatter to BlackCat: Analyzing two attacks from one affiliate
* BlackCat is a recent and growing ransomware-as-a-service (RaaS) group that targeted several organizations worldwide over the past few months.
* There are rumors of a relationship between BlackCat and the BlackMatter/DarkSide ransomware groups, infamous…
* There are rumors of a relationship between BlackCat and the BlackMatter/DarkSide ransomware groups, infamous…
Mon, 21 Mar 2022 21:04:02 +0000
Threat Advisory: CaddyWiper
http://blog.talosintelligence.com/2022/03/threat-advisory-caddywiper.html
Cisco Talos Blog
Threat Advisory: CaddyWiper
This post is also available in:
日本語 (Japanese)
Українська (Ukrainian)
Overview
Cybersecurity company ESET disclosed another Ukraine-focused wiper dubbed "CaddyWiper" on March 14. This wiper is relatively smaller than previous wiper attacks we've seen…
日本語 (Japanese)
Українська (Ukrainian)
Overview
Cybersecurity company ESET disclosed another Ukraine-focused wiper dubbed "CaddyWiper" on March 14. This wiper is relatively smaller than previous wiper attacks we've seen…
Tue, 22 Mar 2022 02:25:37 +0000
APT Attack Being Distributed as Windows Help File (*.chm)
https://asec.ahnlab.com/en/32800/
ASEC BLOG
APT Attack Being Distributed as Windows Help File (*.chm) - ASEC BLOG
The ASEC analysis team has recently discovered the distribution of malware disguised as a Windows Help File (*.chm), specifically targeting Korean users. The CHM file is a compiled HTML Help file that is executed via the Microsoft® HTML help executable program.…
Tue, 22 Mar 2022 11:20:19 +0000
The Attack of the Chameleon Phishing Page
https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-attack-of-the-chameleon-phishing-page/
Trustwave
The Attack of the Chameleon Phishing Page | Trustwave
Recently, we encountered an interesting phishing webpage that caught our interest because it acts like a chameleon by changing and blending its color based on its environment. In addition, the site adapts its background page and logo depending on user input…
APT-C-53(Gamaredon in recent attacks in new changes)
https://translate.yandex.ru/translate?url=https%3A%2F%2Fmp.weixin.qq.com%2Fs%2FYsyeLQDR_LQLfKhigSm2_Q&lang=zh-en
https://translate.yandex.ru/translate?url=https%3A%2F%2Fmp.weixin.qq.com%2Fs%2FYsyeLQDR_LQLfKhigSm2_Q&lang=zh-en
translate.yandex.ru
Переводчик сайтов онлайн на русский и другие языки – Яндекс.Переводчик
Перевод сайтов с английского, немецкого, французского, испанского, польского, турецкого и других языков на русский и обратно. Работает в режиме онлайн.
Tue, 22 Mar 2022 15:35:19 +0000
FBI and FinCEN Release Advisory on AvosLocker Ransomware
https://us-cert.cisa.gov/ncas/current-activity/2022/03/22/fbi-and-fincen-release-advisory-avoslocker-ransomware
Tue, 22 Mar 2022 16:21:25 +0000
Storm Cloud on the Horizon: GIMMICK Malware Strikes at macOS
https://www.volexity.com/blog/2022/03/22/storm-cloud-on-the-horizon-gimmick-malware-strikes-at-macos/
Volexity
Storm Cloud on the Horizon: GIMMICK Malware Strikes at macOS
In late 2021, Volexity discovered an intrusion in an environment monitored as part of its Network Security Monitoring service. Volexity detected a system running frp, otherwise known as fast reverse […]
Tue, 22 Mar 2022 17:29:42 +0000
Hunters become the Hunted
https://blog.cyble.com/2022/03/22/hunters-become-the-hunted/
Cyble
Cyble - Hunters Become The Hunted
Cyble Research Labs analyzes a Clipper malware variant disguised as an AvD Crypto-stealer, potentially targeting other Threat Actors.
Wed, 23 Mar 2022 00:28:02 +0000
Distribution of ClipBanker Disguised as Malware Creation Tool
https://asec.ahnlab.com/en/32825/
ASEC
Distribution of ClipBanker Disguised as Malware Creation Tool - ASEC
The ASEC analysis team has recently discovered a distribution of ClipBanker disguised as a malware creation tool. ClipBanker is a malware that monitors the clipboard of the infected system. If a string for a coin wallet address is copied, the malware changes…
Wed, 23 Mar 2022 00:57:04 +0000
Word Document Attack Targeting Companies Specialized in Carbon Emissions
https://asec.ahnlab.com/en/32822/
ASEC BLOG
Word Document Attack Targeting Companies Specialized in Carbon Emissions - ASEC BLOG
On March 18th, the ASEC analysis team discovered a document-borne APT attack targeting companies specialized in carbon emissions. According to logs collected from AhnLab’s ASD (AhnLab Smart Defense), the user of the infected PC appears to have downloaded…