Spyware vendors use 0-days and n-days against popular platforms https://blog.google/threat-analysis-group/spyware-vendors-use-0-days-and-n-days-against-popular-platforms/
Google
Spyware vendors use 0-days and n-days against popular platforms
Google’s Threat Analysis Group (TAG) tracks actors involved in information operations (IO), government backed attacks and financially motivated abuse. For years, TAG has…
RISC-V: Why The ISA Battles Aren’t Over Yet https://hackaday.com/2019/11/12/risc-v-why-the-isa-battles-arent-over-yet/
Hackaday
RISC-V: Why The ISA Battles Aren’t Over Yet
A computer processor uses a so-called Instruction Set Architecture to talk with the world outside of its own circuitry. This ISA consists of a number of instructions, which essentially define the f…
Magniber ransomware analysis: Tiny Tracer in action https://hshrzd.wordpress.com/2023/03/30/magniber-ransomware-analysis/
hasherezade's 1001 nights
Magniber ransomware analysis: Tiny Tracer in action
Intro Magniber is a ransomware that was initially targeting South Korea. My first report on this malware was written for Malwarebytes in 2017 (here). Since then, the ransomware was completely rewri…
Dissecting redis CVE-2023-28425 with chatGPT as assistant https://tin-z.github.io/redis/cve/chatgpt/2023/04/02/redis-cve2023.html
Lambda driver blog
Dissecting redis CVE-2023-28425 with chatGPT as assistant
Intro
Windows Installer EOP (CVE-2023-21800) https://blog.doyensec.com//2023/03/21/windows-installer.html
Doyensec
Windows Installer EOP (CVE-2023-21800)
TL;DR: This blog post describes the details and methodology of our research targeting the Windows Installer (MSI) installation technology. If you’re only interested in the vulnerability itself, then jump right there
GoatRAT Attacks Automated Payment Systems https://labs.k7computing.com/index.php/goatrat-attacks-automated-payment-systems/
K7 Labs
GoatRAT Attacks Automated Payment Systems
Recently, we came across a detection in our telemetry report named “com.goatmw” which gained our attention. We decided to investigate […]
Pro-Russian hackers target elected US officials supporting Ukraine https://arstechnica.com/information-technology/2023/03/pro-russian-hackers-target-elected-us-officials-supporting-ukraine/
Ars Technica
Pro-Russian hackers target elected US officials supporting Ukraine
Group tracked since 2021 exploits unpatched Zimbra servers to hack email accounts.
👍1
Dridex malware, the banking trojan https://cybersecurity.att.com/blogs/security-essentials/dridex-malware-the-banking-trojan
AT&T Cybersecurity
Dridex malware, the banking trojan
The content of this post is solely the responsibility of the author. AT&T does not adopt or endorse any of the views, positions, or information provided by the author in this article. Introduction: Dridex, also known as Cridex or Bugat, is a banking Trojan…
Windows Forensics: Examine Windows Files and Metadata https://belcyber.medium.com/windows-forensics-examine-windows-files-and-metadata-f8c3c43ea05a
Medium
Windows Forensics: (6–7 Examine Windows Files and Metadata)
The Windows forensics methodology comprises of 8 phases, and we have previously covered the initial five. If you wish to explore them…
👍1
How to use Steganography for attacks or to hide messages https://infosecwriteups.com/how-to-hide-messages-with-steganography-8b91c74b3594
Medium
How to hide messages with Steganography
Quick study of this wonderful technique
👍2
MacStealer malware: A growing threat to macOS users https://www.jamf.com/blog/macstealer-malware-macos-threat/
Jamf
Beware of MacStealer, a growing malware threat that affects macOS
The malware variant uses Telegram's communications protocol to hide its command and control (C2) processes while it exfiltrates sensitive data.
Multiple vulnerabilities in Aten PE8108 power distribution unit https://www.pentagrid.ch/en/blog/multiple-vulnerabilities-in-aten-PE8108-power-distribution-unit/
Pentagrid AG
Multiple vulnerabilities in Aten PE8108 power distribution unit
A Pentagrid security advisory about multiple vulnerabilities in the Aten PE8108 PDU remote power outlet control.
CAN Injection: keyless car theft https://kentindell.github.io/2023/04/03/can-injection/
Ken Tindell’s blog
CAN Injection: keyless car theft
This is a detective story about how a car was stolen - and how it uncovered an epidemic of high-tech car theft. It begins with a tweet. In April 2022, my friend Ian Tabor tweeted that vandals had been at his car, pulling apart the headlight and unplugging…
Rorschach – A New Sophisticated and Fast Ransomware https://research.checkpoint.com/2023/rorschach-a-new-sophisticated-and-fast-ransomware/
Check Point Research
Rorschach – A New Sophisticated and Fast Ransomware - Check Point Research
Research by: Jiri Vinopal, Dennis Yarizadeh and Gil Gekker Key Findings: Introduction While responding to a ransomware case against a US-based company, the CPIRT recently came across a unique ransomware strain deployed using a signed component of a commercial…
👍1
Malicious ISO File Leads to Domain Wide Ransomware https://thedfirreport.com/2023/04/03/malicious-iso-file-leads-to-domain-wide-ransomware/
The DFIR Report
Malicious ISO File Leads to Domain Wide Ransomware - The DFIR Report
IcedID continues to deliver malspam emails to facilitate a compromise. This case covers the activity from a campaign in late September of 2022. Post exploitation activities detail some familiar and some new techniques and tooling, which led to domain wide…
A Guide to Reversing Shared Objects with Ghidra https://medium.com/@cy1337/a-guide-to-reversing-shared-objects-with-ghidra-cec83d5031e6
Medium
A Guide to Reversing Shared Objects with Ghidra
I’m excited to announce that I will be returning this year to the Black Hat USA 2023 conference in Las Vegas. As with previous years’…
Ironing out (the macOS) details of a Smooth Operator (Part II) https://objective-see.org/blog/blog_0x74.html
Objective-See
Ironing out (the macOS) details of a Smooth Operator (Part II)
Analyzing UpdateAgent, the 2nd-stage macOS payload of the 3CX supply chain attack
Hackers Exploit WinRAR SFX Archives to Install Backdoors Undetected https://socradar.io/hackers-exploit-winrar-sfx-archives-to-install-backdoors-undetected/
SOCRadar® Cyber Intelligence Inc.
Hackers Exploit WinRAR SFX Archives to Install Backdoors Undetected
Threat actors exploit WinRAR self-extracting (SFX) archives containing decoy files by adding malicious functionality to install backdoors in target
The (Possible) Return of 2easy and What It Means for the Fraud Ecosystem https://flashpoint.io/blog/2easy-fraud-ecosystem/
Flashpoint
The (Possible) Return of 2easy and What It Means for the Fraud Ecosystem
2easy is a Russian-and English-language illicit shop that sells logs as well as user information collected from browsers via stealer malware.