SideCopy: A Threat Actor targeting Indian Defense and Armed Forces Personnel for a Long Time
There have been several instances where Pakistani threat actors targeted the Indian Government and allied organizations for cyber espionage and other malicious activities. One such threat activity is the Operation SideCopy in which the threat actors had been specifically targeting Indian Defense and Army Forces personnel since 2019. These threat actors have been evolving continuously […]
https://hackhunting.com/2024/04/30/sidecopy-a-threat-actor-targeting-indian-defense-and-armed-forces-personnel-for-a-long-time/
🎖@malwr
There have been several instances where Pakistani threat actors targeted the Indian Government and allied organizations for cyber espionage and other malicious activities. One such threat activity is the Operation SideCopy in which the threat actors had been specifically targeting Indian Defense and Army Forces personnel since 2019. These threat actors have been evolving continuously […]
https://hackhunting.com/2024/04/30/sidecopy-a-threat-actor-targeting-indian-defense-and-armed-forces-personnel-for-a-long-time/
🎖@malwr
Zloader | ThreatLabz
Technical Analysis | Zloader revives an old ZeuS-inspired anti-analysis feature, implementing unique execution restrictions.
https://www.zscaler.com/blogs/security-research/zloader-learns-old-tricks
🎖@malwr
Technical Analysis | Zloader revives an old ZeuS-inspired anti-analysis feature, implementing unique execution restrictions.
https://www.zscaler.com/blogs/security-research/zloader-learns-old-tricks
🎖@malwr
Zscaler
Zloader | ThreatLabz
Technical Analysis | Zloader revives an old ZeuS-inspired anti-analysis feature, implementing unique execution restrictions.
(The) Postman Carries Lots of Secrets ◆ Truffle Security Co.
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, it’s become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a variety of popular SaaS and cloud providers.
https://trufflesecurity.com/blog/postman-carries-lots-of-secrets
🎖@malwr
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, it’s become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a variety of popular SaaS and cloud providers.
https://trufflesecurity.com/blog/postman-carries-lots-of-secrets
🎖@malwr
Trufflesecurity
(The) Postman Carries Lots of Secrets ◆ Truffle Security Co.
Postman, the popular API testing platform, hosts the largest collection of public APIs. Unfortunately, it’s become one of the largest public sources of leaked secrets. We estimate over 4,000 live credentials are currently leaking publicly on Postman for a…
Identifying X-Refs with Capstone | 0ffset Training Solutions
In this post, I will explain how you can locate cross references programmatically using Python modules that are generally helpful in reverse engineering.
https://www.0ffset.net/reverse-engineering/identifying-xrefs-with-capstone/
🎖@malwr
In this post, I will explain how you can locate cross references programmatically using Python modules that are generally helpful in reverse engineering.
https://www.0ffset.net/reverse-engineering/identifying-xrefs-with-capstone/
🎖@malwr
0ffset Training Solutions | Practical and Affordable Cyber Security Training
Identifying X-Refs with Capstone | 0ffset Training Solutions
In this post, I will explain how you can locate cross references programmatically using Python modules that are generally helpful in reverse engineering.
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks
This blog entry aims to highlight the dangers of internet-facing routers and elaborate on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024.
https://www.trendmicro.com/en_us/research/24/e/router-roulette.html
🎖@malwr
This blog entry aims to highlight the dangers of internet-facing routers and elaborate on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024.
https://www.trendmicro.com/en_us/research/24/e/router-roulette.html
🎖@malwr
Trend Micro
Router Roulette: Cybercriminals and Nation-States Sharing Compromised Networks
This blog entry aims to highlight the dangers of internet-facing routers and elaborate on Pawn Storm's exploitation of EdgeRouters, complementing the FBI's advisory from February 27, 2024.
Docker Hub Hosted a Massive 3 Million Imageless Repositories for Phishing Campaigns
Docker Hub is a platform hosting docker images for applications and allows developers to develop, collaborate, and distribute docker images publicly. Investigations revealed millions of empty repositories, with 2.81 million used for malware campaigns. Threat actors used metadata to redirect users to deceptive websites. Users are advised to use "Trusted Content" docker repositories to avoid these attacks.
https://hackhunting.com/2024/05/01/docker-hub-hosted-a-massive-3-million-imageless-repositories-for-phishing-campaigns/
🎖@malwr
Docker Hub is a platform hosting docker images for applications and allows developers to develop, collaborate, and distribute docker images publicly. Investigations revealed millions of empty repositories, with 2.81 million used for malware campaigns. Threat actors used metadata to redirect users to deceptive websites. Users are advised to use "Trusted Content" docker repositories to avoid these attacks.
https://hackhunting.com/2024/05/01/docker-hub-hosted-a-massive-3-million-imageless-repositories-for-phishing-campaigns/
🎖@malwr
HACKHUNTING
Docker Hub Hosted a Massive 3 Million Imageless Repositories for Phishing Campaigns
Docker Hub is a platform hosting docker images for applications and allows developers to develop, collaborate, and distribute docker images publicly. Investigations revealed millions of empty repos…
Fake Windows Explorer Installs a Crypto Miner
Overview This week the SonicWall Capture Labs threat research team came across a sample purporting to be Windows Explorer. At a glance, everything checks out – it uses the legitimate Windows Explorer icon and the
https://blog.sonicwall.com/en-us/2024/04/fake-windows-explorer-installs-a-crypto-miner/
🎖@malwr
Overview This week the SonicWall Capture Labs threat research team came across a sample purporting to be Windows Explorer. At a glance, everything checks out – it uses the legitimate Windows Explorer icon and the
https://blog.sonicwall.com/en-us/2024/04/fake-windows-explorer-installs-a-crypto-miner/
🎖@malwr
CrushFTP Server-Side Template Injection (SSTI)
Overview SonicWall Capture Labs threat research team became aware of a fully unauthenticated server-side template injection vulnerability within CrushFTP, assessed its impact, and developed mitigation measures. CrushFTP is an enterprise file transfer tool. Such tools
https://blog.sonicwall.com/en-us/2024/05/crushftp-server-side-template-injection-ssti/
🎖@malwr
Overview SonicWall Capture Labs threat research team became aware of a fully unauthenticated server-side template injection vulnerability within CrushFTP, assessed its impact, and developed mitigation measures. CrushFTP is an enterprise file transfer tool. Such tools
https://blog.sonicwall.com/en-us/2024/05/crushftp-server-side-template-injection-ssti/
🎖@malwr
FIN7 Abusing Malicious MSIX Packages To Deliver NetSupport RAT | by rewscel | May, 2024 | Medium
A quick introduction to the group: FIN7 is a Russian advanced persistent threat (APT) group with financial motive. The criminal group has several techniques they utilize for initial access, but in…
https://rewscel.medium.com/fin7-abusing-malicious-msix-packages-to-deliver-netsupport-rat-09962fdf33ef
🎖@malwr
A quick introduction to the group: FIN7 is a Russian advanced persistent threat (APT) group with financial motive. The criminal group has several techniques they utilize for initial access, but in…
https://rewscel.medium.com/fin7-abusing-malicious-msix-packages-to-deliver-netsupport-rat-09962fdf33ef
🎖@malwr
Medium
FIN7 Abusing Malicious MSIX Packages To Deliver NetSupport RAT
Quick note: This post is an attempt to share what I’ve learned while doing some research about this specific group (FIN7). I am newer to…
"Dirty stream" attack: Discovering and mitigating a common vulnerability pattern in Android apps
https://www.microsoft.com/en-us/security/blog/2024/05/01/dirty-stream-attack-discovering-and-mitigating-a-common-vulnerability-pattern-in-android-apps/
🎖@malwr
https://www.microsoft.com/en-us/security/blog/2024/05/01/dirty-stream-attack-discovering-and-mitigating-a-common-vulnerability-pattern-in-android-apps/
🎖@malwr
Microsoft News
“Dirty stream” attack: Discovering and mitigating a common vulnerability pattern in Android apps
Microsoft discovered a vulnerability pattern in multiple popular Android applications that could enable a malicious application to overwrite files in the vulnerable application’s internal data storage directory, which could lead to arbitrary code execution…
macOS Adload | Prolific Adware Pivots Just Days After Apple’s XProtect Clampdown
Learn about the latest Adload adware variants, written in Go and intended to bypass Apple's recent XProtect updates.
https://www.sentinelone.com/blog/macos-adload-prolific-adware-pivots-just-days-after-apples-xprotect-clampdown/
🎖@malwr
Learn about the latest Adload adware variants, written in Go and intended to bypass Apple's recent XProtect updates.
https://www.sentinelone.com/blog/macos-adload-prolific-adware-pivots-just-days-after-apples-xprotect-clampdown/
🎖@malwr
SentinelOne
macOS Adload | Prolific Adware Pivots Just Days After Apple’s XProtect Clampdown
Learn about the latest Adload adware variants, written in Go and intended to bypass Apple's recent XProtect updates.
It’s Morphin’ Time: Self-Modifying Code Sections with WriteProcessMemory for EDR Evasion | by Thiago Peixoto | Apr, 2024 | Medium
An EDR can identify malicious activity within a process through mechanisms such as kernel callbacks and userland hooks on commonly used Windows API functions exploited by malware. In the case of…
https://revflash.medium.com/its-morphin-time-self-modifying-code-sections-with-writeprocessmemory-for-edr-evasion-9bf9e7b7dced
🎖@malwr
An EDR can identify malicious activity within a process through mechanisms such as kernel callbacks and userland hooks on commonly used Windows API functions exploited by malware. In the case of…
https://revflash.medium.com/its-morphin-time-self-modifying-code-sections-with-writeprocessmemory-for-edr-evasion-9bf9e7b7dced
🎖@malwr
Medium
It’s Morphin’ Time: Self-Modifying Code Sections with WriteProcessMemory for EDR Evasion
The Mockingjay process injection technique was designed to prevent the allocation of a buffer with RWX permission, typically used for…
🔥1
Dissecting Windows Malware Series – RISC vs CISC Architectures – Part 4
https://8ksec.io/dissecting-windows-malware-series-risc-vs-cisc-architectures-part-4/
🎖@malwr
https://8ksec.io/dissecting-windows-malware-series-risc-vs-cisc-architectures-part-4/
🎖@malwr
8kSec
Windows Malware Part 4: RISC vs CISC | 8kSec
Understand RISC vs CISC CPU architectures in Part 4 of the Windows malware series. Learn why architecture differences matter for malware analysis.
CVE-2024-2887: A Pwn2Own Winning Bug in Google Chrome
https://www.thezdi.com/blog/2024/5/2/cve-2024-2887-a-pwn2own-winning-bug-in-google-chrome
🎖@malwr
https://www.thezdi.com/blog/2024/5/2/cve-2024-2887-a-pwn2own-winning-bug-in-google-chrome
🎖@malwr
Zero Day Initiative
Zero Day Initiative — CVE-2024-2887: A Pwn2Own Winning Bug in Google Chrome
In this guest blog from Master of Pwn winner Manfred Paul, he details CVE-2024-2887 – a type confusion bug that occurs in both Google Chrome and Microsoft Edge (Chromium). He used this bug as a part of his winning exploit that led to code execution in the…
Secure Kernel Research with LiveCloudKd
https://windows-internals.com/secure-kernel-research-with-livecloudkd/
🎖@malwr
https://windows-internals.com/secure-kernel-research-with-livecloudkd/
🎖@malwr
New “Goldoon” Botnet Targeting D-Link Devices | FortiGuard Labs
FortiGuard Labs discovered the new botnet “Goldoon” targeting D-Link devices through related vulnerability CVE-2015-2051. Learn more.
https://www.fortinet.com/blog/threat-research/new-goldoon-botnet-targeting-d-link-devices
🎖@malwr
FortiGuard Labs discovered the new botnet “Goldoon” targeting D-Link devices through related vulnerability CVE-2015-2051. Learn more.
https://www.fortinet.com/blog/threat-research/new-goldoon-botnet-targeting-d-link-devices
🎖@malwr
Fortinet Blog
New “Goldoon” Botnet Targeting D-Link Devices
FortiGuard Labs discovered the new botnet “Goldoon” targeting D-Link devices through related vulnerability CVE-2015-2051. Learn more. …
❤1
TargetCompany Ransomware Group Installs Mallox Ransomware on Vulnerable MS-SQL Servers
The TargetCompany ransomware group was discovered in June 2021, targeting improperly managed MS-SQL servers with malware variants such as Mallox ransomware. Using brute force and dictionary attacks, threat actors install Remocs RAT and remote screen control malware. The final stage involves installing Mallox ransomware, impacting file encryption and system functions. ASEC researchers have published a comprehensive report. Mitigation involves upgrading servers and enhancing password security. Indicators of Compromise are provided.
https://hackhunting.com/2024/05/03/targetcompany-ransomware-group-installs-mallox-ransomware-on-vulnerable-ms-sql-servers/
🎖@malwr
The TargetCompany ransomware group was discovered in June 2021, targeting improperly managed MS-SQL servers with malware variants such as Mallox ransomware. Using brute force and dictionary attacks, threat actors install Remocs RAT and remote screen control malware. The final stage involves installing Mallox ransomware, impacting file encryption and system functions. ASEC researchers have published a comprehensive report. Mitigation involves upgrading servers and enhancing password security. Indicators of Compromise are provided.
https://hackhunting.com/2024/05/03/targetcompany-ransomware-group-installs-mallox-ransomware-on-vulnerable-ms-sql-servers/
🎖@malwr
Flutter Windows Thick Client SSL Pinning Bypass | by Sourav Kalal | May, 2024 | Medium
Learn to bypass SSL Pinning in Flutter Windows Thick Client Application using Frida and Reverse Engineering. Also, find ouhow to configure Flutter for proxy.
https://blog.souravkalal.tech/flutter-windows-thick-client-ssl-pinning-bypass-492389ae1218
🎖@malwr
Learn to bypass SSL Pinning in Flutter Windows Thick Client Application using Frida and Reverse Engineering. Also, find ouhow to configure Flutter for proxy.
https://blog.souravkalal.tech/flutter-windows-thick-client-ssl-pinning-bypass-492389ae1218
🎖@malwr
Medium
Flutter Windows Thick Client SSL Pinning Bypass
I recently worked on a Flutter-based application and learned that it is different from other hybrid frameworks like React Native or…
“Dirty Stream” Attack : Android Apps with 4 Billion Installations are Affected
Mobile devices, especially Android, are targeted by hackers due to security vulnerabilities. Researchers at Microsoft discovered a Path Traversal attack that allows threat actors to overwrite files and execute arbitrary code in popular Android apps, like Xiaomi's File Manager. Developers should follow security guidelines and use Android Lint to avoid such vulnerabilities.
https://hackhunting.com/2024/05/04/dirty-stream-attack-android-apps-with-4-billion-installations-are-affected/
🎖@malwr
Mobile devices, especially Android, are targeted by hackers due to security vulnerabilities. Researchers at Microsoft discovered a Path Traversal attack that allows threat actors to overwrite files and execute arbitrary code in popular Android apps, like Xiaomi's File Manager. Developers should follow security guidelines and use Android Lint to avoid such vulnerabilities.
https://hackhunting.com/2024/05/04/dirty-stream-attack-android-apps-with-4-billion-installations-are-affected/
🎖@malwr
HACKHUNTING
“Dirty Stream” Attack : Android Apps with 4 Billion Installations are Affected
Mobile devices, especially Android, are targeted by hackers due to security vulnerabilities. Researchers at Microsoft discovered a Path Traversal attack that allows threat actors to overwrite files…