Malware News
13K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
The Anatomy of an ALPHA SPIDER Ransomware Attack

ALPHA SPIDER is the adversary behind the development and operation of the Alphv ransomware as a service (RaaS). Over the last year, ALPHA SPIDER affiliates have been leveraging a variety of novel techniques as part of their ransomware operations. CrowdStrike Services has observed techniques such as the usage of NTFS Alternate Data Streams for hiding...

https://www.crowdstrike.com/blog/anatomy-of-alpha-spider-ransomware/


πŸŽ–@malwr
πŸ‘2
2024-03-06: Pikabot infection leads to Meduza Stealer

https://www.malware-traffic-analysis.net/2024/03/06/index.html


πŸŽ–@malwr
2024-03-14: AsyncRAT and XWorm infection

https://www.malware-traffic-analysis.net/2024/03/14/index.html


πŸŽ–@malwr
The LockBit story: Why the ransomware affiliate model can turn takedowns into disruptions

Talos explores the recent law enforcement takedown of LockBit, a prolific ransomware group that claimed to resume their operations 7 days later.

https://blog.talosintelligence.com/ransomware-affiliate-model/


πŸŽ–@malwr
πŸ‘1
Hello everybody. I'm sorry for inconvenience. To keep our channel up, I have to pay for server and services. For that, we need financial support. If channel members could kindly donate in BTC, I will not post any ads in the channel.

Sincerely,
@SirMalware


πŸŽ–@malwr
πŸ‘7
Healthcare still a prime target for cybercrime gangs – Week in security with Tony Anscombe

Healthcare organizations remain firmly in attackers' crosshairs, representing 20 percent of all victims of ransomware attacks among critical infrastructure entities in the US in 2023

https://www.welivesecurity.com/en/videos/healthcare-target-cybercrime-week-security-tony-anscombe/


πŸŽ–@malwr
Earth Krahang Exploits Intergovernmental Trust to Launch Cross-Government Attacks

Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide, with a strong focus in Southeast Asia, but also seen targeting Europe, America, and Africa.

https://www.trendmicro.com/en_us/research/24/c/earth-krahang.html


πŸŽ–@malwr
Jenkins Args4j CVE-2024-23897: Files Exposed, Code at Risk

Jenkins, a popular open-source automation server, was discovered to be affected by a file read vulnerability, CVE-2024-23897.

https://www.trendmicro.com/en_us/research/24/c/cve-2024-23897.html


πŸŽ–@malwr
πŸ‘1
LockBit Attempts to Stay Afloat With a New Version

This research is the result of our collaboration with the National Crime Agency in the United Kingdom, who took action against LockBit as part of Operation Cronos, an international effort resulting in the undermining of its operations.

https://www.trendmicro.com/en_us/research/24/b/lockbit-attempts-to-stay-afloat-with-a-new-version.html


πŸŽ–@malwr
Adversarial Intelligence: Red Teaming Malicious Use Cases for AI

Recorded Future tested four malicious use cases for artificial intelligence (AI) to illustrate β€œthe art of the possible” for threat actor use.

https://www.recordedfuture.com/adversarial-intelligence-red-teaming-malicious-use-cases-ai


πŸŽ–@malwr
πŸ”₯2
Analyzing AsyncRAT's Code Injection into aspnet_compiler.exe Across Multiple Incident Response Cases

This blog entry delves into MxDR's unraveling of the AsyncRAT infection chain across multiple cases, shedding light on the misuse of aspnet_compiler.exe, a legitimate Microsoft process originally designed for precompiling ASP.NET web applications.

https://www.trendmicro.com/en_us/research/23/l/analyzing-asyncrat-code-injection-into-aspnetcompiler-exe.html


πŸŽ–@malwr
πŸ”₯1
TeamCity Vulnerability Exploits Lead to Jasmin Ransomware, Other Malware Types

CVE-2024-27198 and CVE-2024-27199 are vulnerabilities within the TeamCity On-Premises platform that can allow attackers to gain administrative control over affected systems.

https://www.trendmicro.com/en_us/research/24/c/teamcity-vulnerability-exploits-lead-to-jasmin-ransomware.html


πŸŽ–@malwr
πŸ‘2
Dissecting a complex vulnerability and achieving arbitrary code execution in Ichitaro Word

Research conducted by Cisco Talos last year has uncovered multiple vulnerabilities that were rated as low-severity despite their ability to allow for full arbitrary code execution. This article examines the exploitation process step-by-step.

https://blog.talosintelligence.com/exploiting-low-severity-vulnerability-using-a-frame-pointer-overwrite/


πŸŽ–@malwr
Attributing I-SOON: Private Contractor Linked to Multiple Chinese State-sponsored Groups

Insikt Group uncovers ties between I-SOON and multiple Chinese state-sponsored cyber groups like RedAlpha and RedHotel.

https://www.recordedfuture.com/attributing-i-soon-private-contractor-linked-chinese-state-sponsored-groups


πŸŽ–@malwr
πŸ”₯1
❀1