Hacking Articles Tips Tricks Videos Tutorials
471 subscribers
65.9K photos
15 videos
157 files
132K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The 10 Best Kali Linux Terminal Commands for Ethical Hacking

Kali Linux is an open source operating system designed for penetration testing and digital forensics. It comes with a variety of powerful…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Thor APT Scanner

https://cdn-images-1.medium.com/max/600/1*9xHO0NFdnuLYlyL5bKLY2A.jpeg
This report presents a technical analysis of an ELF 64-bit LSB executable with an MD5 hash of 2f4ccd747707eb957625bb388aa11df5, which is…

Continue reading on Medium »
Hacking Articles Tips Tricks Videos Tutorials
Photo
Black Hat Ethical Hacking
In-Browser Windows Update Simulation Used as a Vehicle for Aurora Malware

In-Browser Windows Update Simulation Used as a Vehicle for Aurora MalwarePost Views: 11 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/uploads/2022/12/Patreon.png Subscribe to Patreon to watch this episode.
Reading Time: 3 Minutes Sophisticated Malverising Campaign Spreads Aurora Malware with Fake Windows Update Simulation A sophisticated malvertising campaign has recently been uncovered, employing an in-browser Windows update simulation to distribute the notorious Aurora information-stealing malware. Known for its advanced capabilities and low detection rates, Aurora has been advertised on hacker forums for over a year. Researchers at Malwarebytes have revealed that this malvertising operation strategically utilizes popunder ads on adult content websites with high traffic, redirecting unsuspecting users to locations hosting the malware.

https://www.malwarebytes.com/blog/threat-intelligence/2023/05/easset_upload_file12739_265978_e.gif Fake Windows update (Malwarebytes)

Popunder ads are a type of inexpensive advertisement that opens behind the active browser window, remaining hidden until the user closes or moves the main window. In a similar vein, Google had reported a popunder-based ad fraud campaign in December of last year, which generated hundreds of thousands of visitors and tens of millions of fraudulent ad impressions.

While the impact of the recent malvertising campaign was relatively lower, redirecting around 30,000 users and resulting in the download and installation of the data-stealing malware on nearly 600 systems, it employed a deceptive tactic. The threat actor devised a clever strategy where the popunder displays a full-screen browser window, simulating a Windows system update screen.
See Also: So you want to be a hacker? Offensive Security, Bug Bounty Courses Unraveling the Malicious Tactics of a Sophisticated Malvertising CampaignThe researchers at Malwarebytes tracked multiple domains involved in the campaign, with several of them mimicking adult websites while simulating the fake Windows update. These domains included names such as activessd[.]ru, xhamster-18[.]ru, and click7adilla[.]ru, among others. Despite the deceptive nature of the full-screen browser window, some users fell victim to the ruse and unknowingly executed the malicious executable file named “ChromeUpdate.exe” that was offered for download.

https://www.bleepstatic.com/images/news/u/1220909/2023/Malware/32/down-file.png Downloaded file (Malwarebytes)

Upon closer examination, it was discovered that the alleged Chrome updater was, in fact, a “fully undetectable” (FUD) malware loader known as ‘Invalid Printer,’ exclusively used by this particular threat actor. Interestingly, when Malwarebytes analysts first encountered ‘Invalid Printer,’ no antivirus engines on Virus Total classified it as malicious. However, a few weeks later, detection started to increase following the release of a relevant report from Morphisec.

https://www.bleepstatic.com/images/news/u/1220909/2023/Malware/32/loader-code.png Malware loader code snippet (Malwarebytes)

The ‘Invalid Printer’ malware loader is designed to check the host’s graphics card to determine if it is running on a virtual machine or in a sandbox environment. If not, it proceeds to unpack and launch the Aurora information-stealer, as revealed by the researchers. Malwarebytes commented that the threat actor behind this campaign appears to have a strong interest in creating tools that are difficult to detect, constantly uploading new samples on Virus Total to gauge their detection rates.
https://www.bleepstatic.com/images/news/u/12209[...]
Hacking Articles Tips Tricks Videos Tutorials
Black Hat Ethical Hacking In-Browser Windows Update Simulation Used as a Vehicle for Aurora Malware In-Browser Windows Update Simulation Used as a Vehicle for Aurora MalwarePost Views: 11 Premium Contenthttps://www.blackhatethicalhacking.com/wp-content/u…
09/2023/Malware/32/content.png Payload carried by ‘Invalid Printer’ (Malwarebytes)
Trending: How to Exploit “improper error handling” in Web Applications Trending: Malware Analysis Tool: retoolkit
Jérôme Segura, the director of threat intelligence at Malwarebytes, noticed a notable pattern during their investigation. Each time a new sample was initially submitted to Virus Total, it originated from a user in Turkey, with file names that appeared freshly compiled (e.g., build1_enc_s.exe). Further investigation revealed that the threat actor also utilizes an Amadey panel, suggesting the potential use of a well-documented reconnaissance and malware loading tool, alongside running tech support scams that target Ukrainian victims.

Malwarebytes has provided a comprehensive technical analysis of the malware’s installation and behavior, along with a set of indicators of compromise (IoCs) that companies and security vendors can leverage to protect their users.
Trending: APT hacking group uses double DLL sideloading to bypass security Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?

If you want to express your idea in an article contact us here for a quote: info@blackhatethicalhacking.com
Source: bleepingcomputer.com Source Link https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Store.png Recent News* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-3-300x150.png Critical Linux Kernel Flaw – Unprivileged Users Gain Root ControlMay 10, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-2-300x150.png CACTUS Ransomware Exploits VPN Flaws to Infiltrate Corporate NetworksMay 9, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-1-300x150.png New Akira Ransomware Operation Hits Corporate NetworksMay 8, 2023
* https://www.blackhatethicalhacking.com/wp-content/uploads/2023/05/Images-for-the-News-posts-13-300x150.png North Korean Kimsuky Hacking Group Ups Their Game with New ‘ReconShark’ MalwareMay 5, 2023 https://www.blackhatethicalhacking.com/wp-content/uploads/2022/06/OffSec-Course.png Offensive Security & Ethical Hacking CourseBegin the learning curve of hacking now! https://www.blackhatethicalhacking.com/wp-content/uploads/2023/03/Solutions.png Information Security SolutionsFind out how Pentesting Services can help you.
The post In-Browser Windows Update Simulation Used as a Vehicle for Aurora Malware first appeared on Black Hat Ethical Hacking.
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Hacking competition

Hey fellow hackers! I'm curious to know if there are any upcoming hacking-related competitions or challenges that you're aware of. I'm eager to put my skills to the test and learn from the hacking community. Do you have any recommendations or information about exciting hacking competitions happening in the near future?

submitted by /u/couldnt5indGoodName
[link] [comments]
Hacking Articles Tips Tricks Videos Tutorials
Photo
hacking: security in practice
Does anyone know if Kali on Arm on the Pi Zero 2 is worth it?

I've got a pi zero 2 lying around from a project that ended up getting shelved. I'm now thinking about using the pi for Kali on Arm or rather Kali Pi-Tail as a little device to toy around with. Does anyone know how the pi zero 2 perform with Kali on arm/Kali Pi-Tail?

submitted by /u/Schaksie
[link] [comments]
Dark Reading: Attacks/Breaches
Google Touts Security Features for Gmail, Drive

Company executives at Google I/O described tools such as About This Image, Safe Browsing API, and others to help keep users safe online.
Understanding the Cross Site Request Forgery (CSRF) attack

The Cross Site Request Forgery attack is one of those types of attacks that are hard to recognize at first glance.Continue reading on Medium »
Read more...