2024-11-04 Securonix: CRON#TRAP: Emulated Linux Environments as the Latest Tactic in Malware Staging Attackers distribute a custom QEMU-emulated Linux environment via a malicious .lnk file within a phishing email. When executed, this file installs and initiates a QEMU instance to run a Tiny Core Linux backdoor, enabling covert persistence on the victim's machine. The .lnk file activates PowerShell…
2024-10-23 TALOS Threat Spotlight: WarmCookie/BadSpace Summary: WarmCookie, also known as BadSpace, is a sophisticated malware family that emerged in April 2024, primarily distributed through malspam and malvertising. This malware provides long-term access to compromised environments and facilitates the deployment of additional payloads, such as CSharp-Streamer-RAT and Cobalt Strike. Its infection…
2024-10-25 Cyble: HeptaX: Unauthorized RDP Connections for Cyberespionage Operations Summary: The attack starts with a malicious LNK file delivered within a ZIP file, likely distributed through phishing emails, and seems to target the healthcare industry. Upon execution, the LNK file initiates a PowerShell command that downloads multiple scripts and batch files from a remote server to establish…
2024-10-03 Threatmon: Amnesia Stealer Amnesia Stealer, a customizable open-source malware, was identified by ThreatMon on September 17, 2024. Functions as Malware-as-a-Service (MaaS), making it easily accessible for cybercriminals. Uses Discord and Telegram for Command & Control (C2) operations. Capable of stealing sensitive data like browser passwords, Discord tokens, cryptocurrency wallets, and…
2024-09-26 Elastic: Betting on Bots: Investigating Linux malware, crypto mining, and gambling API abuse Elastic Security Labs uncovered a sophisticated Linux malware campaign targeting servers through an Apache2 web server exploit in March 2024. The attackers used a mix of tools, including custom malware, KAIJI (a DDoS botnet), and RUDEDEVIL (a cryptocurrency miner). They utilized C2 channels…
Image courtesy of Palo Alto 2024-09-23 Palo Alto Unit42: Inside SnipBot: The Latest RomCom Malware Variant This latest version integrates novel obfuscation techniques and exhibits distinct post-infection activities not seen in previous variants (RomCom 3.0 and PEAPOD/RomCom 4.0). Key Points: Capabilities: SnipBot allows attackers to execute commands and download additional modules onto the…
2024-09-19 Mandiant: UNC1860 and the Temple of Oats: Iran’s Hidden Hand in Middle Eastern Networks UNC1860 is an Iranian state-sponsored threat actor, likely affiliated with the Ministry of Intelligence and Security (MOIS), known for its persistent and stealthy operations. It employs a variety of specialized tools, passive backdoors, and custom utilities to target high-priority networks, such as…
2024-09-19 Kaspersky: Exotic SambaSpy is now dancing with Italian users SambaSpy is a highly obfuscated Java-based RAT, protected by the Zelix KlassMaster protector. It supports a range of malicious activities, including: File system and process management Keystroke logging using the JNativeHook library, sending keystrokes to the C2 upon key release Clipboard content control through Java Abstract…
Trend Micro - Infection Chain 2024-09-08 TrendMicro Earth Baxia Uses Spear-Phishing and GeoServer Exploit to Target APAC Earth Baxia, a threat actor suspected to originate from China, has been targeting government organizations in Taiwan and other Asia-Pacific (APAC) countries, using spear-phishing emails and exploiting a vulnerability in GeoServer (CVE-2024-36401), a remote code execution (RCE)…
2024-09-18 Lumen: Derailing the Raptor Train Black Lotus Labs The Raptor Train botnet, discovered in 2023, is a large, multi-tiered network primarily composed of compromised SOHO routers, IP cameras, NAS servers, and NVR/DVR devices. The botnet's primary implant, named "Nosedive," is a customized variant of the Mirai malware, designed to infect various IoT architectures like MIPS, ARM, PowerPC,…
2024-09-12 Ahnlab: SuperShell malware targeting Linux SSH servers SuperShell is a sophisticated backdoor malware targeting Linux SSH servers, written in the Go language, which allows cross-platform functionality on Linux, Windows, and Android. Created by a Chinese-speaking developer, it operates as a reverse shell, enabling attackers to execute commands remotely on the compromised systems. The…
2024-09-12 0day in {REA_TEAM}: The X-Worm malware is being spread through a phishing email by m4n0w4r More about X-Worm: Malpedia: X-Worm Malware with wide range of capabilities ranging from RAT to ransomware. Phishing Tactics: An attacker sent an email with a shortened link that, when clicked, triggered the download of a file named Itinerary.doc_.zip. The downloaded .zip file contained a shortcut…
2023-11-23 Palo Alto Unit42: Hacking Employers and Seeking Employment: Two Job-Related This is a 2023 article by Unit42 covering two cyber campaigns, "Contagious Interview" (CL-STA-0240) and "Wagemole" (CL-STA-0241), linked to the Lazarus group (North Korea). There is a more recent campaign VMCONNECT described by Reversing Labs here 2024-09-10 Fake recruiter coding tests target devs with malicious…
2024-09-10 Sakai @sakaijjang 김수키(Kimsuky) 에서 만든 악성코드-Terms and conditions(이용 약관).msc(2024.9.6) - Kimsuky (North Korea) - Terms and Conditions.msc by https://x.com/sakaijjang?lang=en Article translation in English More about Kimsuky: 2020-10-27 CISA North Korean Advanced Persistent Threat Focus The malware is delivered as a file named "Terms and conditions.msc," containing embedded PowerShell…
2024-09-03 K7 Security Labs: Luxy: A Stealer and a Ransomware in one The sample is a .NET 32-bit executable, enforcing single-instance execution via a mutex and ensuring network connectivity before proceeding. It also implements anti-VM checks using System UUIDs, process names, and other system identifiers to evade sandbox environments. Browser Data Extraction: Utilizes methods like…
2024-09-05 Splunk: ShrinkLocker Malware: Abusing BitLocker to Lock Your Data ShrinkLocker is a newly discovered ransomware strain that exploits BitLocker, a legitimate Windows feature, to encrypt data by locking users out of their systems. Unlike traditional ransomware, ShrinkLocker leverages BitLocker's secure boot partition to make decryption extremely challenging. The malware initiates its…
2024 -08 -30 Truesec : Dissecting the Cicada (Ransomware ) ESXi Ransomware Cicada3301, a ransomware group first detected in June 2024, appears to be either a rebranded or derivative version of the ALPHV ransomware group, employing a ransomware-as-a-service (RaaS) model. The ransomware, written in Rust, targets both Windows and Linux/ESXi environments, utilizing ChaCha20 for encryption. Technical…
2024-09-02 SocRadar: Dark Web Profile: Abyss Ransomware Abyss Ransomware, first identified in 2023, is a sophisticated ransomware strain targeting both Windows and Linux systems, with a specific focus on VMware ESXi environments. It employs advanced encryption techniques, multi-extortion tactics, and strategic network infiltration to disrupt operations across various sectors, including finance,…
2024-08-30 Microsoft: North Korean threat actor Citrine Sleet exploiting Chromium zero-day 2024-03-01 Lazarus group operations — A deep dive into FudModule Rootkit by Lucas Mancilha 2024-02-28 Avast: Lazarus and the FudModule Rootkit: Beyond BYOVD with anAdmin-to-Kernel Zero-Day - Avast Threat Labs 2024 Blackhat Asia Speakers: Luigino Camastra, Igor Morgenstern Video Slides 2024-04-18 Avast: From…
2024 -08 -28 Akamai Beware the Unpatchable : Corona Mirai Botnet Spreads via Zero -Day (CVE -2024 -7029) - command injection vulnerability found in the brightness function of AVTECH closed -circuit television (CCTV ) Akamai's Security Intelligence and Response Team (SIRT) has identified a new botnet campaign exploiting multiple vulnerabilities, including a zero-day vulnerability, CVE-2024-7029 ,…
2024 -08 -29 Esentire: Exploring AsyncRAT and Infostealer Plugin Delivery Through Phishing Emails eSentire's Threat Response Unit (TRU) discovered an AsyncRAT infection that was delivered through a Windows Script File (.wsf) via email. The malicious .wsf file, named “SummaryForm_,” downloaded a VBScript from a remote server, which then fetched a fake image file. This file was actually a ZIP…
2024 -08 -29 Fortinet Ransomware Roundup - Underground The Underground ransomware is likely spread by the RomCom group ( also known as Storm-0978). The group exploits the Microsoft Office and Windows HTML RCE vulnerability (CVE-2023-36884). Other methods, such as phishing emails and access via Initial Access Brokers (IABs), may also be used. Shadow Copies Deletion: It removes all shadow copies to…
2024 -08 -23 Cyfirma . A Comprehensive Analysis of Angry Stealer : Rage Stealer in a New Disguise (Telegram rat ) . CYFIRMA analyzed malware known as " Angry Stealer", which is heavily advertised on platforms like Telegram, a repackaged version of the previously identified " Rage Steale r " The dropper is a 32-bit Win32 executable written in .NET, which acts as the initial stage of the attack.…
2024 -08 -14 Elastic: Beyond the wail : deconstructing the BANSHEE infostealer This analysis of BANSHEE Stealer reveals a sophisticated macOS-based malware (sold for $3,000) developed by Russian threat actors, targeting both x86_64 and ARM64 architectures. BANSHEE Stealer is designed to collect a wide range of data from infected systems, including browser history, cookies, logins, cryptocurrency…