2024-05-09: GootLoader activity
https://www.malware-traffic-analysis.net/2024/05/09/index.html
🎖@malwr
https://www.malware-traffic-analysis.net/2024/05/09/index.html
🎖@malwr
Telekopye: Chamber of Neanderthals’ secrets
Insight into groups operating Telekopye bots that scam people in online marketplaces
https://www.welivesecurity.com/en/eset-research/telekopye-chamber-neanderthals-secrets/
🎖@malwr
Insight into groups operating Telekopye bots that scam people in online marketplaces
https://www.welivesecurity.com/en/eset-research/telekopye-chamber-neanderthals-secrets/
🎖@malwr
Welivesecurity
Telekopye: Chamber of Neanderthals’ secrets
ESET research shares insights about groups operating Telekopye, Telegram bots that scam people in online marketplaces, their internal onboarding process, different tricks of trade that Neanderthals use, and more.
Doctor Web’s annual virus activity review for 2023
https://news.drweb.com/show/?i=14851&lng=en&c=5
🎖@malwr
https://news.drweb.com/show/?i=14851&lng=en&c=5
🎖@malwr
Exploring the Depths of SolarMarker's Multi-tiered Infrastructure
Uncover SolarMarker’s multi-tiered infrastructure and its impact on sectors like education, healthcare, and government. Learn more.
https://www.recordedfuture.com/exploring-the-depths-of-solarmarkers-multi-tiered-infrastructure
🎖@malwr
Uncover SolarMarker’s multi-tiered infrastructure and its impact on sectors like education, healthcare, and government. Learn more.
https://www.recordedfuture.com/exploring-the-depths-of-solarmarkers-multi-tiered-infrastructure
🎖@malwr
XWiki Remote Code Execution Vulnerability
Overview The SonicWall Capture Labs threat research team became aware of CVE-2024-31984, which is a code injection vulnerability in XWiki’s management of space titles and has a critical CVSS score of 9.9. After assessing the
https://blog.sonicwall.com/en-us/2024/05/xwiki-remote-code-execution-vulnerability/
🎖@malwr
Overview The SonicWall Capture Labs threat research team became aware of CVE-2024-31984, which is a code injection vulnerability in XWiki’s management of space titles and has a critical CVSS score of 9.9. After assessing the
https://blog.sonicwall.com/en-us/2024/05/xwiki-remote-code-execution-vulnerability/
🎖@malwr
Foxit PDF “Flawed Design” Exploitation
https://research.checkpoint.com/2024/foxit-pdf-flawed-design-exploitation/
🎖@malwr
https://research.checkpoint.com/2024/foxit-pdf-flawed-design-exploitation/
🎖@malwr
Check Point Research
Foxit PDF “Flawed Design” Exploitation - Check Point Research
Check Point Research has identified an unusual pattern of behavior involving PDF exploitation, mainly targeting users of Foxit Reader. This exploit triggers security warnings that could deceive unsuspecting users into executing harmful commands. Check Point…
GitCaught: Threat Actor Leverages GitHub Repository for Malicious Infrastructure
Discover how Russian-speaking hackers leverage GitHub to host malware disguised as legitimate software. Explore the campaign, implications, and protection strategies.
https://www.recordedfuture.com/gitcaught-threat-actor-leverages-github-repository-for-malicious-infrastructure
🎖@malwr
Discover how Russian-speaking hackers leverage GitHub to host malware disguised as legitimate software. Explore the campaign, implications, and protection strategies.
https://www.recordedfuture.com/gitcaught-threat-actor-leverages-github-repository-for-malicious-infrastructure
🎖@malwr
Remcos Is Pairing with PrivateLoader to Extend Its Capabilities
Overview This week, the SonicWall Capture Labs threat research team investigated a sample of the RemcosRAT that uses a PrivateLoader module to provide additional data and persistence on the victim’s machine. By installing VB scripts,
https://blog.sonicwall.com/en-us/2024/05/remcos-is-pairing-with-privateloader-to-extend-its-capabilities/
🎖@malwr
Overview This week, the SonicWall Capture Labs threat research team investigated a sample of the RemcosRAT that uses a PrivateLoader module to provide additional data and persistence on the victim’s machine. By installing VB scripts,
https://blog.sonicwall.com/en-us/2024/05/remcos-is-pairing-with-privateloader-to-extend-its-capabilities/
🎖@malwr
ESET APT Activity Report Q4 2023–Q1 2024
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2023 and Q1 2024
https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2023-q1-2024/
🎖@malwr
An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2023 and Q1 2024
https://www.welivesecurity.com/en/eset-research/eset-apt-activity-report-q4-2023-q1-2024/
🎖@malwr
Welivesecurity
ESET APT Activity Report Q4 2023–Q1 2024
This report summarizes notable activities of selected advanced persistent threat (APT) groups that were documented by ESET researchers from October 2023 until the end of March 2024.
MICROSOFT SECURITY BULLETIN COVERAGE FOR MAY 2024
Overview Microsoft’s May 2024 Patch Tuesday has 59 vulnerabilities, 25 of which are Remote Code Execution vulnerabilities. The SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of
https://blog.sonicwall.com/en-us/2024/05/microsoft-security-bulletin-coverage-for-may-2024/
🎖@malwr
Overview Microsoft’s May 2024 Patch Tuesday has 59 vulnerabilities, 25 of which are Remote Code Execution vulnerabilities. The SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of
https://blog.sonicwall.com/en-us/2024/05/microsoft-security-bulletin-coverage-for-may-2024/
🎖@malwr
Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain
One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft
https://www.welivesecurity.com/en/eset-research/ebury-alive-unseen-400k-linux-servers-compromised-cryptotheft-financial-gain/
🎖@malwr
One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft
https://www.welivesecurity.com/en/eset-research/ebury-alive-unseen-400k-linux-servers-compromised-cryptotheft-financial-gain/
🎖@malwr
Welivesecurity
Ebury is alive but unseen: 400k Linux servers compromised for cryptotheft and financial gain
One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft.
Detecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices
Last month, Volexity reported on its discovery of zero-day, in-the-wild exploitation of CVE-2024-3400 in the GlobalProtect feature of Palo Alto Networks PAN-OS by a threat actor Volexity tracks as UTA...
https://www.volexity.com/blog/2024/05/15/detecting-compromise-of-cve-2024-3400-on-palo-alto-networks-globalprotect-devices/
🎖@malwr
Last month, Volexity reported on its discovery of zero-day, in-the-wild exploitation of CVE-2024-3400 in the GlobalProtect feature of Palo Alto Networks PAN-OS by a threat actor Volexity tracks as UTA...
https://www.volexity.com/blog/2024/05/15/detecting-compromise-of-cve-2024-3400-on-palo-alto-networks-globalprotect-devices/
🎖@malwr
Volexity
Detecting Compromise of CVE-2024-3400 on Palo Alto Networks GlobalProtect Devices
Last month, Volexity reported on its discovery of zero-day, in-the-wild exploitation of CVE-2024-3400 in the GlobalProtect feature of Palo Alto Networks PAN-OS by a threat actor Volexity tracks as UTA0218. Volexity has conducted several additional incident…
Tracking the Progression of Earth Hundun's Cyberespionage Campaign in 2024
This report describes how Waterbear and Deuterbear — two of the tools in Earth Hundun's arsenal — operate, based on a campaign from 2024.
https://www.trendmicro.com/en_us/research/24/e/earth-hundun-2.html
🎖@malwr
This report describes how Waterbear and Deuterbear — two of the tools in Earth Hundun's arsenal — operate, based on a campaign from 2024.
https://www.trendmicro.com/en_us/research/24/e/earth-hundun-2.html
🎖@malwr
Trend Micro
Tracking the Progression of Earth Hundun's Cyberespionage Campaign in 2024
This report describes how Waterbear and Deuterbear — two of the tools in Earth Hundun's arsenal — operate, based on a campaign from 2024.
👍1
To the Moon and back(doors): Lunar landing in diplomatic missions
ESET researchers provide technical analysis of the Lunar toolset, likely used by the Turla APT group, that infiltrated a European ministry of foreign affairs
https://www.welivesecurity.com/en/eset-research/moon-backdoors-lunar-landing-diplomatic-missions/
🎖@malwr
ESET researchers provide technical analysis of the Lunar toolset, likely used by the Turla APT group, that infiltrated a European ministry of foreign affairs
https://www.welivesecurity.com/en/eset-research/moon-backdoors-lunar-landing-diplomatic-missions/
🎖@malwr
Welivesecurity
To the Moon and back(doors): Lunar landing in diplomatic missions
ESET researchers provide technical analysis of the Lunar toolset, likely used by the Turla APT group, that infiltrated a European ministry of foreign affairs
Talos releases new macOS open-source fuzzer
Compared to fuzzing for software vulnerabilities on Linux, where most of the code is open-source, targeting anything on macOS presents a few difficulties.
https://blog.talosintelligence.com/talos-releases-new-macos-fuzzer/
🎖@malwr
Compared to fuzzing for software vulnerabilities on Linux, where most of the code is open-source, targeting anything on macOS presents a few difficulties.
https://blog.talosintelligence.com/talos-releases-new-macos-fuzzer/
🎖@malwr
Cisco Talos
Talos releases new macOS open-source fuzzer
Compared to fuzzing for software vulnerabilities on Linux, where most of the code is open-source, targeting anything on macOS presents a few difficulties.
Hackers use Malicious OneNote files for Delivering Payloads to Victims
Microsoft OneNote is a digital note-taking app in the Microsoft Office Suite. Hackers use it to embed malicious objects like scripts and executables, tricking users into downloading malware. The malware aims to deliver malicious payloads like Qakbot, Emotet, and AsyncRAT. Attackers prefer lightweight malware for easier delivery, avoiding heavier files like EXE or Office 97-2003 files.
https://hackhunting.com/2024/05/17/hackers-use-malicious-onenote-files-for-delivering-payloads-to-victims/
🎖@malwr
Microsoft OneNote is a digital note-taking app in the Microsoft Office Suite. Hackers use it to embed malicious objects like scripts and executables, tricking users into downloading malware. The malware aims to deliver malicious payloads like Qakbot, Emotet, and AsyncRAT. Attackers prefer lightweight malware for easier delivery, avoiding heavier files like EXE or Office 97-2003 files.
https://hackhunting.com/2024/05/17/hackers-use-malicious-onenote-files-for-delivering-payloads-to-victims/
🎖@malwr
HACKHUNTING
Hackers use Malicious OneNote files for Delivering Payloads to Victims
Microsoft OneNote is a digital note-taking app in the Microsoft Office Suite. Hackers use it to embed malicious objects like scripts and executables, tricking users into downloading malware. The ma…
Mobile Malware Analysis Part 7 – Blackrock
https://8ksec.io/mobile-malware-analysis-part-7-blackrock/
🎖@malwr
https://8ksec.io/mobile-malware-analysis-part-7-blackrock/
🎖@malwr
8kSec
Mobile Malware Part 7: Blackrock Analysis | 8kSec
Analyze the Blackrock Android malware in Part 7 of the mobile malware series. Learn how it abuses accessibility services and overlays to steal data.