ApoMacroSploit : Apocalyptical FUD race https://research.checkpoint.com/2021/apomacrosploit-apocalyptical-fud-race/
Check Point Research
ApoMacroSploit : Apocalyptical FUD race - Check Point Research
1.1 Introduction At the end of November, Check Point Research detected a new Office malware builder called APOMacroSploit, which was implicated in multiple malicious emails to more than 80 customers worldwide. In our investigation, we found that this…
Introducing MacHound: A Solution to MacOS Active Directory-Based Attacks https://www.xmcyber.com/introducing-machound-a-solution-to-macos-active-directory-based-attacks/
XM Cyber
Introducing MacHound: A Solution to MacOS Active Directory-Based Attacks
Learn all about MacHound, a plugin for Bloodhound Active Directory, allowing to collect Active Directory relationships from MacOS devices.
Malvertiser “ScamClub” Bypasses Iframe Sandboxing With postMessage() Shenanigans [CVE-2021–1801] https://blog.confiant.com/malvertiser-scamclub-bypasses-iframe-sandboxing-with-postmessage-shenanigans-cve-2021-1801-1c998378bfba
Confiant
Malvertiser “ScamClub” Bypasses Iframe Sandboxing With postMessage() Shenanigans [CVE-2021–1801]
This blog post is about the mechanics of a long tail iframe sandbox bypass found in a payload belonging to the persistent malvertising attacker that we call ScamClub.
PE-Packer: Windows x86 PE file packer written in C & Microsoft Assembly https://securityonline.info/pe-packer-windows-x86-pe-file-packer-written-in-c-microsoft-assembly/
Penetration Testing
PE-Packer: Windows x86 PE file packer written in C & Microsoft Assembly
PE-Packer is a simple packer for Windows PE files. The new PE file after packing can obstruct the process of reverse engineering.
Neurax: A framework for constructing self-spreading binaries https://github.com/redcode-labs/Neurax
GitHub
GitHub - redcode-labs/neurax: A framework for constructing self-spreading binaries
A framework for constructing self-spreading binaries - redcode-labs/neurax
Further Updates in LODEINFO Malware (targeted attack in Japan) https://blogs.jpcert.or.jp/en/2021/02/LODEINFO-3.html
JPCERT/CC Eyes
Further Updates in LODEINFO Malware - JPCERT/CC Eyes
The functions and evolution of malware LODEINFO have been described in our past articles in February 2020 and June 2020. Yet in 2021, JPCERT/CC continues to observe activities related to this malware. Its functions have been expanding with some new...
Sandbox detection and evasion techniques. How malware has evolved over the last 10 years https://www.ptsecurity.com/ww-en/analytics/antisandbox-techniques/
ptsecurity.com
Sandbox detection and evasion techniques. How malware has evolved over the last 10 years
In most cases, hackers
The Story of Jian – How APT31 Stole and Used an Unknown Equation Group 0-Day https://research.checkpoint.com/2021/the-story-of-jian/
Check Point Research
The Story of Jian - How APT31 Stole and Used an Unknown Equation Group 0-Day - Check Point Research
Research by: Eyal Itkin and Itay Cohen There is a theory which states that if anyone will ever manage to steal and use nation-grade cyber tools, any network would become untrusted, and the world would become a very dangerous place to live in. There is another…
ImHex: A Hex Editor for Reverse Engineers, Programmers and people that value their eye sight when working at 3 AM https://github.com/WerWolv/ImHex
GitHub
GitHub - WerWolv/ImHex: 🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3…
🔍 A Hex Editor for Reverse Engineers, Programmers and people who value their retinas when working at 3 AM. - WerWolv/ImHex
SrClient DLL Hijacking: a Windows Server 2012 0-day that won't be patched https://blog.vonahi.io/srclient-dll-hijacking/
Vonahi Security's Blog
SrClient DLL Hijacking: a Windows Server 2012 0-day that won't be patched
This blog discusses a DLL hijacking vulnerability affecting all versions of Windows Server 2012 (but not Server 2012 R2). This 0-day vulnerability can be exploited for privilege escalation by any regular user and does not require a system reboot, yet it will…
Hancitor Infection Chain Analysis: An Examination of its Unpacking Routine and Execution Techniques https://threatresearch.ext.hp.com/hancitors-return-analyzing-its-latest-infection-chain/
HP Wolf Security
Hancitor Infection Chain Analysis: An Examination of its Unpacking Routine and Execution Techniques | HP Wolf Security
Don’t let cyber threats get the best of you. Read our post, Hancitor Infection Chain Analysis: An Examination of its Unpacking Routine and Execution Techniques, to learn more about cyber threats and cyber security.
Big kudos to @vxunderground, very nice content here! » https://twitter.com/vxunderground/status/1365904863603941377?s=09
Twitter
vx-underground
In case you missed it - we created a GitHub repo called "WinAPI Tricks". We've added a little bit of content to it. *All content is in C *Attached image lists current examples *A LOT more to come Check it out here: https://t.co/Xb2Y4ojjSq
Some anti-debug and anti-memory dump for Android OS https://github.com/darvincisec/AntiDebugandMemoryDump
GitHub
GitHub - darvincisec/AntiDebugandMemoryDump: Anti-Debug and Anti-Memory Dump for Android
Anti-Debug and Anti-Memory Dump for Android. Contribute to darvincisec/AntiDebugandMemoryDump development by creating an account on GitHub.
CheckPoint cybersec report 2021, good details on critical vulnerabilities exploited in 2020 https://www.checkpoint.com/downloads/resources/cyber-security-report-2021.pdf
CVE-2020-8625: A Fifteen-Year-Old RCE Bug Returns in ISC BIND Server https://www.zerodayinitiative.com/blog/2021/2/24/cve-2020-8625-a-fifteen-year-old-rce-bug-returns-in-isc-bind-server
Zero Day Initiative
Zero Day Initiative — CVE-2020-8625: A Fifteen-Year-Old RCE Bug Returns in ISC BIND Server
The Patch The patched versions are BIND 9.16.12 and BIND 9.11.28. To fix BIND 9.16, ISC fixed the buffer allocation size at (1). In BIND 9.11, they applied the patch as well. Conclusion This bug shows how vulnerabilities can reside undetected for years…
Nice chart about the connections between cybercrime groups » https://www.zdnet.com/article/this-chart-shows-the-connections-between-cybercrime-groups/
ZDNET
This chart shows the connections between cybercrime groups
CrowdStrike puts together a list of connections and how cybercrime groups cooperate with each other.
1Password has none, KeePass has none... So why are there seven embedded trackers in the LastPass Android app? https://www.theregister.com/2021/02/25/lastpass_android_trackers_found/
The Register
1Password has none, KeePass has none... So why are there seven embedded trackers in the LastPass Android app?
Third-party code in security-critical apps is obviously suboptimal, but company says you can opt out
Network Graph Analysis for Suricata and Zeek using Brim and NetworkX https://medium.com/brim-securitys-knowledge-funnel/visualizing-network-cyber-attacks-with-suricata-and-zeek-using-brim-and-networkx-332dd265d4b6
Medium
Visualizing Network Cyber Attacks with Suricata and Zeek using Brim and NetworkX
Gaining meaningful Insights out of Security Data