Attribution is in the object: using RTF object dimensions to track APT phishing weaponizers
https://www.virusbulletin.com/virusbulletin/2020/03/vb2019-paper-attribution-object-using-rtf-object-dimensions-track-apt-phishing-weaponizers/
π@malwr
https://www.virusbulletin.com/virusbulletin/2020/03/vb2019-paper-attribution-object-using-rtf-object-dimensions-track-apt-phishing-weaponizers/
π@malwr
Virusbulletin
Virus Bulletin :: VB2019 paper: Attribution is in the object: using RTF object dimensions to track APT phishing weaponizers
Anomali Labs has conducted an in-depth study of the unique object dimensions present in weaponized RTF exploits used in phishing attacks. Through this research we have found that the developers of malicious RTF weaponizers leave behind a unique fingerprintβ¦
Frida 12.8.15 is out w/ full support for iOS/arm64e and iOS 13.4
π£oleavr
Says it was released is December 2019?
π€tigr87
I simple getting started guide if interested.
https://frida.re/docs/ios/
π€littlejob
π@malwr
π£oleavr
Says it was released is December 2019?
π€tigr87
I simple getting started guide if interested.
https://frida.re/docs/ios/
π€littlejob
π@malwr
Frida β’ A world-class dynamic instrumentation toolkit
iOS
Observe and reprogram running programs on Windows, macOS, GNU/Linux, iOS, watchOS, tvOS, Android, FreeBSD, and QNX
Understanding Hardware-enforced Stack Protection
https://techcommunity.microsoft.com/t5/windows-kernel-internals/understanding-hardware-enforced-stack-protection/ba-p/1247815
π@malwr
https://techcommunity.microsoft.com/t5/windows-kernel-internals/understanding-hardware-enforced-stack-protection/ba-p/1247815
π@malwr
TECHCOMMUNITY.MICROSOFT.COM
Understanding Hardware-enforced Stack Protection
ROP (Return Oriented Programming) based control flow attacks have become a common form of attack. In this post, we will describe our efforts to harden control..
APT-C-36 new anti-detection tricks
https://lab52.io/blog/apt-c-36-new-anti-detection-tricks/
π@malwr
https://lab52.io/blog/apt-c-36-new-anti-detection-tricks/
π@malwr
Dear Windows Defender, please tell me where I can drop my malicious code
π£packmad
Lol Microsoft's response is great
π€wilhouse
π@malwr
π£packmad
Lol Microsoft's response is great
π€wilhouse
π@malwr
Medium
Dear Windows Defender, please tell me where I can drop my malicious code.
The Get-MpPreference cmdlet exposes the field ExclusionPath without administrator privilege.
How the Iranian Cyber Security Agency Detects Emissary Panda Malware
https://blog.team-cymru.com/2020/03/25/how-the-iranian-cyber-security-agency-detects-emissary-panda-malware/
π@malwr
https://blog.team-cymru.com/2020/03/25/how-the-iranian-cyber-security-agency-detects-emissary-panda-malware/
π@malwr
Team Cymru
Blog - Team Cymru
This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits
https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html
π@malwr
https://www.fireeye.com/blog/threat-research/2020/03/apt41-initiates-global-intrusion-campaign-using-multiple-exploits.html
π@malwr
Google Cloud
Mandiant Cybersecurity Consulting
Transform cyber defense with Mandiant. Engage frontline experts for incident response, threat intelligence services, and cyber risk management.
TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany
https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/
π@malwr
https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/
π@malwr
Security Intelligence
TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany
Our team is closely monitoring TrickBot's developing capabilities, including its new cross-channel attacks using the TrickMo component.
Icnanker, a Linux Trojan-Downloader Protected by SHC
https://blog.netlab.360.com/icnanker-trojan-downloader-shc-en/
π@malwr
https://blog.netlab.360.com/icnanker-trojan-downloader-shc-en/
π@malwr
360 Netlab Blog - Network Security Research Lab at 360
Icnanker, a Linux Trojan-Downloader Protected by SHC
Background
On August 15, 2019, 360Netlab Threat Detecting System flagged an unknown ELF sample (5790dedae465994d179c63782e51bac1) which generated Elknot Botnet related network traffic. We manually took a look and noticed that it is a Trojan-Downloader whichβ¦
On August 15, 2019, 360Netlab Threat Detecting System flagged an unknown ELF sample (5790dedae465994d179c63782e51bac1) which generated Elknot Botnet related network traffic. We manually took a look and noticed that it is a Trojan-Downloader whichβ¦
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...
https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
π£chrisknight1985
π@malwr
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...
https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
π£chrisknight1985
π@malwr
BleepingComputer
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Chinese Hackers Attacked Foreign Health Care, Military, Oil Networks as Coronavirus Hit China
π£FourFans0fFreedom
π@malwr
π£FourFans0fFreedom
π@malwr
Defense One
Chinese Hackers Attacked Foreign Health Care, Military, Oil Networks as Coronavirus Hit China
In January, the βwidespreadβ assault targeted a vulnerability in virtual desktops, cloud computing, and network applications, FireEye announced.
Operation Poisoned News: Hong Kong Users Targeted With Mobile Malware via Local News Links
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/
π@malwr
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/
π@malwr
Trend Micro
Research, News, and Perspectives
Azorult loader stages
https://maxkersten.nl/binary-analysis-course/malware-analysis/azorult-loader-stages/
π@malwr
https://maxkersten.nl/binary-analysis-course/malware-analysis/azorult-loader-stages/
π@malwr