TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany
https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/
π@malwr
https://securityintelligence.com/posts/trickbot-pushing-a-2fa-bypass-app-to-bank-customers-in-germany/
π@malwr
Security Intelligence
TrickBot Pushing a 2FA Bypass App to Bank Customers in Germany
Our team is closely monitoring TrickBot's developing capabilities, including its new cross-channel attacks using the TrickMo component.
Icnanker, a Linux Trojan-Downloader Protected by SHC
https://blog.netlab.360.com/icnanker-trojan-downloader-shc-en/
π@malwr
https://blog.netlab.360.com/icnanker-trojan-downloader-shc-en/
π@malwr
360 Netlab Blog - Network Security Research Lab at 360
Icnanker, a Linux Trojan-Downloader Protected by SHC
Background
On August 15, 2019, 360Netlab Threat Detecting System flagged an unknown ELF sample (5790dedae465994d179c63782e51bac1) which generated Elknot Botnet related network traffic. We manually took a look and noticed that it is a Trojan-Downloader whichβ¦
On August 15, 2019, 360Netlab Threat Detecting System flagged an unknown ELF sample (5790dedae465994d179c63782e51bac1) which generated Elknot Botnet related network traffic. We manually took a look and noticed that it is a Trojan-Downloader whichβ¦
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...
https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
π£chrisknight1985
π@malwr
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Since Tor Browser users are relying on its security features to anonymously browse the Internet, having their identity exposed by a JavaScript that could be used for fingerprinting or unveiling their true location defeated the browser's private browsing promise without tracking, surveillance, or censorship...
https://www.bleepingcomputer.com/news/security/tor-browser-907-patches-bug-that-could-deanonymize-users/
π£chrisknight1985
π@malwr
BleepingComputer
Tor Browser 9.0.7 Patches Bug That Could Deanonymize Users
The Tor Project released Tor Browser 9.0.7 today with a permanent fix for a bug that allowed JavaScript code to run on the Safest security level in some situations while using the previous Tor Browser version.
Chinese Hackers Attacked Foreign Health Care, Military, Oil Networks as Coronavirus Hit China
π£FourFans0fFreedom
π@malwr
π£FourFans0fFreedom
π@malwr
Defense One
Chinese Hackers Attacked Foreign Health Care, Military, Oil Networks as Coronavirus Hit China
In January, the βwidespreadβ assault targeted a vulnerability in virtual desktops, cloud computing, and network applications, FireEye announced.
Operation Poisoned News: Hong Kong Users Targeted With Mobile Malware via Local News Links
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/
π@malwr
https://blog.trendmicro.com/trendlabs-security-intelligence/operation-poisoned-news-hong-kong-users-targeted-with-mobile-malware-via-local-news-links/
π@malwr
Trend Micro
Research, News, and Perspectives
Azorult loader stages
https://maxkersten.nl/binary-analysis-course/malware-analysis/azorult-loader-stages/
π@malwr
https://maxkersten.nl/binary-analysis-course/malware-analysis/azorult-loader-stages/
π@malwr
SharpML - Active Directory Password Hunting with ML for File-Shares
π£hunniccyber
Nice approach there!
You might want to have ML-folks/data scientists to chime in here; please add samples of the training data you used; above that, I couldnβt find any hints at the actual accuracy. NLP has seen some great results lately - keep experimenting!
Along the lines you mentioned potentially lacking (ML) domain knowledge - but still you will be offering a paid course - Iβd rather render this into a joint research/project initiative. But these are just my 2 quarantined cents =]
π€vornamemitd
π@malwr
π£hunniccyber
Nice approach there!
You might want to have ML-folks/data scientists to chime in here; please add samples of the training data you used; above that, I couldnβt find any hints at the actual accuracy. NLP has seen some great results lately - keep experimenting!
Along the lines you mentioned potentially lacking (ML) domain knowledge - but still you will be offering a paid course - Iβd rather render this into a joint research/project initiative. But these are just my 2 quarantined cents =]
π€vornamemitd
π@malwr
Hunnic Cyber Blog
Password Hunting with Machine Learning in Active Directory
tdlr: Situation: - Passwords embedded in files on fileshares lead to compromise. Complication: - It is hard to tell what is a password. Resolution: - Use SharpML toβ¦
Looking to learn about system exploitation, but don't know where to start? This (very) detailed guide covers all the basics. Contains 21 detailed CTF solutions, plenty of theory, and zero times the phrase "exercise left to the reader".
π£ynvb
> The standard answer is often an embarrassed mumble that there are no golden rules, and that you should probably follow this or that person on Twitter to get tips, then βgo practice, like you would with CTF exercises.β
CTF exercises are basically self-contained challenges that require the player to crack some problem and recover some piece of text (the βflagβ) as a proof of having cracked the problem.
This is always my answer to this question.
π€MaliciouSSymbol
Thank you!!!
π€redimusu76
This is a great read. I hope more of this pops up.
π€snake_case_believer
π@malwr
π£ynvb
> The standard answer is often an embarrassed mumble that there are no golden rules, and that you should probably follow this or that person on Twitter to get tips, then βgo practice, like you would with CTF exercises.β
CTF exercises are basically self-contained challenges that require the player to crack some problem and recover some piece of text (the βflagβ) as a proof of having cracked the problem.
This is always my answer to this question.
π€MaliciouSSymbol
Thank you!!!
π€redimusu76
This is a great read. I hope more of this pops up.
π€snake_case_believer
π@malwr
Check Point Research
"I want to learn about exploitation! Where do I start?" - Check Point Research
A comprehensive exploitation ("hacking") tutorial based on Georgia Tech's pwnable.kr exercises. Theory, hands-on exercises and detailed solutions.
Writing Your First Bootloader for Better Analyses
https://marcoramilli.com/2019/09/03/writing-your-first-bootloader-for-better-analyses/
π@malwr
https://marcoramilli.com/2019/09/03/writing-your-first-bootloader-for-better-analyses/
π@malwr
Marco Ramilli Web Corner
Writing Your First Bootloader for Better Analyses
From time to time we might observe special Malware storing themselves into a MBR and run during the booting process. Attackers could use this neat technique to infect and to mess-up your disk and eβ¦
InQL Scanner: can be used as a stand-alone script, or as a Burp Suite extension (available for both Professional and Community editions) to assess GraphQL
π£digicat
π@malwr
π£digicat
π@malwr
Doyensec
InQL Scanner
As a part of our continuing security research journey, we started developing an internal tool to speed-up GraphQL security testing efforts. Weβre excited to announce that InQL is available on Github.
iOS exploit chain deploys βLightSpyβ feature-rich malware (same campaign as Operation Poisoned News: Hong Kong Users Targeted With Mobile Malware via Local News Links)
π£digicat
π@malwr
π£digicat
π@malwr
Securelist
iOS exploit chain deploys LightSpy feature-rich malware
A watering hole was discovered on January 10, 2020 utilizing a full remote iOS exploit chain to deploy a feature-rich implant named LightSpy.
Hacker Mails Best Buy Gift Card Offer to Trick Victim into Plugging in Malicious USB Thumb Drive
π£andyholla84
π@malwr
π£andyholla84
π@malwr
PCMAG
PSA: If You Get a 'Best Buy Gift Card' on a USB Drive in the Mail, Don't Plug It Into Your PC
Trustwave has uncovered an incident where a hacker mailed a malicious USB stick to a victim on the pretense the thumb drive was part of a Best Buy gift card offer. In reality, the thumb drive was full of malware.