Malware News
16.2K subscribers
1.64K photos
7 videos
130 files
8.3K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
MITRE ATT&CK for Kubernetes: 4+1 Threat Vectors for the Defense Evasion Tactic
Read the whole article.

TL;DR

The defense evasion tactic consists of techniques that are used by attackers to avoid detection and stay under the radar by concealing any evidence of their presence.
Tactic #1: Clear container logs - deleting relevant logs from an application or an operating system that would record traces of an attacker’s activity. Mitigating Tactic #1 by limiting or denying completely the host mounts, and by using a real-time, automated analysis tool for Kubernetes audit logs.
Tactic #2: Deleting Kubernetes Events - Deleting these events reduces the risk of detecting security-related activities performed by the attacker. Mitigating Tactic #2 by configuring continuous audit logging and preferably exporting it to an external SIEM tool and the likes of it.
Tactics #3: Container name similarity - Attackers can create pods with a random suffix in their names, hiding the presence of unauthorized pods within a cluster. Mitigate Tactic #3 with Role-Based Access Control (RBAC) configurations, keeping the principle of least privilege.
Tactic #4: Connect from proxy server - Proxy servers and anonymous networks such as TOR are often used by attackers to hide their origin IP and initiate communication channels with applications or directly to the API server. Mitigate Tactic #4 by restricting network access to the Kubernetes API server and implementing proper firewall rules at the cloud provider level.
Bonus Tactic not in MITRE ATT&CK: DNS Resolution - A common practice for establishing covert channels is to exploit inherent weaknesses in the DNS protocol messages exchange. Monitor DNS activity within your Kubernetes cluster to detect and potentially prevent C2 channels from establishing covert channels.
πŸ—£alcideio


πŸŽ–@malwr
Understanding "Solorigate"'s Identity IOCs
πŸ—£Wireless_Life

The Solarwinds attack is an ongoing investigation, and teams at Microsoft continue to act as first responders to these attacks. The following post shares how they leverage threat intelligence and monitor for new indicators that could signal attacker activity.
πŸ‘€Wireless_Life


πŸŽ–@malwr
BlueTeam Online Training
I’m looking to have continuous training for a blue team and I’m curious as to what the group would recommend. Outside of Cybrary and SANS what do you recommend?

I’m personally interested in core disciplines and not aimed towards a certification. Also, being continuous is also helpful.
πŸ—£nullsku

https://wildwesthackinfest.com/training-schedule/
πŸ‘€Sho_nuff_

I haven’t used it but ISACA’s training looks solid. Was gonna try it before training budget was cut.

Maybe you can do a trial to see if you like it.

https://www.isaca.org/training-and-events/cybersecurity
πŸ‘€Just_saying_brah


πŸŽ–@malwr
Reversing APT-28 64-bit Keylogger [Zebrocy Nim TLP: White ](https://0xthreatintel.medium.com/reversing-apt-28-64-bit-keylogger-zebrocy-nim-tlp-white-a77033f5c36b)
πŸ—£digicat


πŸŽ–@malwr
SOLARWINDS BACKDOOR (SUNBURST) INCIDENT RESPONSE PLAYBOOK
πŸ—£digicat

Looks like some good steps and would be a good starting point for many looking to have a checklist of items if their security IRP is not well flushed out.
πŸ‘€hackfacts


πŸŽ–@malwr