RSSAmplifier

Blog

contagio

malware dump

contagiodump.blogspot.comRSS feed ↗25 posts

Latest posts

2024-11-04 CRON#TRAP (Emulated Linux Environments) Samples

2024-11-04 Securonix: CRON#TRAP: Emulated Linux Environments as the Latest Tactic in Malware Staging Attackers distribute a custom QEMU-emulated Linux environment via a malicious .lnk file within a phishing email. When executed, this file installs and initiates a QEMU instance to run a Tiny Core Linux backdoor, enabling covert persistence on the victim's machine. The .lnk file activates PowerShell…

2024-10-30 Lunar Spider's Latrodectus JS loader samples

2024-10-30 EclecticIQ: Inside Intelligence Center: LUNAR SPIDER Enabling Ransomware Attacks on Financial Sector with Brute Ratel C4 and Latrodectus LUNAR SPIDER’s recent campaign used Latrodectus, a heavily obfuscated JavaScript loader, to deliver Brute Ratel C4 payloads targeting the financial sector. Key technical observations include: Malvertising and SEO Poisoning: Victims searching…

2024-10-23 WarmCookie/BadSpace - APT TA866 - Samples

2024-10-23 TALOS Threat Spotlight: WarmCookie/BadSpace Summary: WarmCookie, also known as BadSpace, is a sophisticated malware family that emerged in April 2024, primarily distributed through malspam and malvertising. This malware provides long-term access to compromised environments and facilitates the deployment of additional payloads, such as CSharp-Streamer-RAT and Cobalt Strike. Its infection…

2024-10-25 HeptaX - Unauthorized RDP Connections. Nalicious LNK. > Powershell > Bat files Samples

2024-10-25 Cyble: HeptaX: Unauthorized RDP Connections for Cyberespionage Operations Summary: The attack starts with a malicious LNK file delivered within a ZIP file, likely distributed through phishing emails, and seems to target the healthcare industry. Upon execution, the LNK file initiates a PowerShell command that downloads multiple scripts and batch files from a remote server to establish…

2024-10-03 Amnesia Stealer Samples

2024-10-03 Threatmon: Amnesia Stealer Amnesia Stealer, a customizable open-source malware, was identified by ThreatMon on September 17, 2024. Functions as Malware-as-a-Service (MaaS), making it easily accessible for cybercriminals. Uses Discord and Telegram for Command & Control (C2) operations. Capable of stealing sensitive data like browser passwords, Discord tokens, cryptocurrency wallets, and…

2024-09-24 Linux Malware Cryptocurrency Miners, DONUT LOADER, RUDEVIL RAT, KAIJI- Stager and DDoS botnet samples

2024-09-26 Elastic: Betting on Bots: Investigating Linux malware, crypto mining, and gambling API abuse Elastic Security Labs uncovered a sophisticated Linux malware campaign targeting servers through an Apache2 web server exploit in March 2024. The attackers used a mix of tools, including custom malware, KAIJI (a DDoS botnet), and RUDEDEVIL (a cryptocurrency miner). They utilized C2 channels…

2024-09-23 SNIPBOT RomCom Multi-Stage RAT Samples

Image courtesy of Palo Alto 2024-09-23 Palo Alto Unit42: Inside SnipBot: The Latest RomCom Malware Variant This latest version integrates novel obfuscation techniques and exhibits distinct post-infection activities not seen in previous variants (RomCom 3.0 and PEAPOD/RomCom 4.0). Key Points: Capabilities: SnipBot allows attackers to execute commands and download additional modules onto the…

2024-09-19 UNC1860 Iran APT - Temple of Oats ( OATBOAT, TEMPLEDOOR, SASHEYAWAY, OBFUSLAY, WINTAPIX, CRYPTOSLAY) Samples

2024-09-19 Mandiant: UNC1860 and the Temple of Oats: Iran’s Hidden Hand in Middle Eastern Networks UNC1860 is an Iranian state-sponsored threat actor, likely affiliated with the Ministry of Intelligence and Security (MOIS), known for its persistent and stealthy operations. It employs a variety of specialized tools, passive backdoors, and custom utilities to target high-priority networks, such as…

2024-09-18 SAMBASPY Java RAT Samples

2024-09-19 Kaspersky: Exotic SambaSpy is now dancing with Italian users SambaSpy is a highly obfuscated Java-based RAT, protected by the Zelix KlassMaster protector. It supports a range of malicious activities, including: File system and process management Keystroke logging using the JNativeHook library, sending keystrokes to the C2 upon key release Clipboard content control through Java Abstract…

2024-09-18 Earth Baxia APT - RIPCOY + SWORDLDR Samples (Spear-Phishing and GeoServer Exploit used to Target APAC)

Trend Micro - Infection Chain 2024-09-08 TrendMicro Earth Baxia Uses Spear-Phishing and GeoServer Exploit to Target APAC Earth Baxia, a threat actor suspected to originate from China, has been targeting government organizations in Taiwan and other Asia-Pacific (APAC) countries, using spear-phishing emails and exploiting a vulnerability in GeoServer (CVE-2024-36401), a remote code execution (RCE)…

2024-08-18 RAPTOR TRAIN NOSEDIVE - Mirai-type IoT Botnet Samples

2024-09-18 Lumen: Derailing the Raptor Train Black Lotus Labs The Raptor Train botnet, discovered in 2023, is a large, multi-tiered network primarily composed of compromised SOHO routers, IP cameras, NAS servers, and NVR/DVR devices. The botnet's primary implant, named "Nosedive," is a customized variant of the Mirai malware, designed to infect various IoT architectures like MIPS, ARM, PowerPC,…

2024-09-12 SUPERSHELL + 2023-03-13 SHELLBOT Targeting Linux SSH servers Samples

2024-09-12 Ahnlab: SuperShell malware targeting Linux SSH servers SuperShell is a sophisticated backdoor malware targeting Linux SSH servers, written in the Go language, which allows cross-platform functionality on Linux, Windows, and Android. Created by a Chinese-speaking developer, it operates as a reverse shell, enabling attackers to execute commands remotely on the compromised systems. The…

2024-09-19 X-WORM RAT (Phishing) Samples

2024-09-12 0day in {REA_TEAM}: The X-Worm malware is being spread through a phishing email by m4n0w4r More about X-Worm: Malpedia: X-Worm Malware with wide range of capabilities ranging from RAT to ransomware. Phishing Tactics: An attacker sent an email with a shortened link that, when clicked, triggered the download of a file named Itinerary.doc_.zip. The downloaded .zip file contained a shortcut…

2023-11-23 BEAVERTAIL and INVISIBLE_FERRET Lazarus Group Malware Samples

2023-11-23 Palo Alto Unit42: Hacking Employers and Seeking Employment: Two Job-Related This is a 2023 article by Unit42 covering two cyber campaigns, "Contagious Interview" (CL-STA-0240) and "Wagemole" (CL-STA-0241), linked to the Lazarus group (North Korea). There is a more recent campaign VMCONNECT described by Reversing Labs here 2024-09-10 Fake recruiter coding tests target devs with malicious…

2024-09-10 KIMSUKY (North Korean APT) Sample (Sakai @sakaijjan - Terms and Conditions.msc)

2024-09-10 Sakai @sakaijjang 김수키(Kimsuky) 에서 만든 악성코드-Terms and conditions(이용 약관).msc(2024.9.6) - Kimsuky (North Korea) - Terms and Conditions.msc by https://x.com/sakaijjang?lang=en Article translation in English More about Kimsuky: 2020-10-27 CISA North Korean Advanced Persistent Threat Focus The malware is delivered as a file named "Terms and conditions.msc," containing embedded PowerShell…

2024-09-03 LUXY Ransomware / Stealer Sample

2024-09-03 K7 Security Labs: Luxy: A Stealer and a Ransomware in one The sample is a .NET 32-bit executable, enforcing single-instance execution via a mutex and ensuring network connectivity before proceeding. It also implements anti-VM checks using System UUIDs, process names, and other system identifiers to evade sandbox environments. Browser Data Extraction: Utilizes methods like…

2024-09-05 SHRINKLOCKER (Bitlocker) Ransomware Samples

2024-09-05 Splunk: ShrinkLocker Malware: Abusing BitLocker to Lock Your Data ShrinkLocker is a newly discovered ransomware strain that exploits BitLocker, a legitimate Windows feature, to encrypt data by locking users out of their systems. Unlike traditional ransomware, ShrinkLocker leverages BitLocker's secure boot partition to make decryption extremely challenging. The malware initiates its…

2024-08-30 Cicada ESXi Ransomware Sample

2024 -08 -30 Truesec : Dissecting the Cicada (Ransomware ) ESXi Ransomware Cicada3301, a ransomware group first detected in June 2024, appears to be either a rebranded or derivative version of the ALPHV ransomware group, employing a ransomware-as-a-service (RaaS) model. The ransomware, written in Rust, targets both Windows and Linux/ESXi environments, utilizing ChaCha20 for encryption. Technical…

2024-09-02 ABYSS Ransomware Windows and Linux Samples

2024-09-02 SocRadar: Dark Web Profile: Abyss Ransomware Abyss Ransomware, first identified in 2023, is a sophisticated ransomware strain targeting both Windows and Linux systems, with a specific focus on VMware ESXi environments. It employs advanced encryption techniques, multi-extortion tactics, and strategic network infiltration to disrupt operations across various sectors, including finance,…

2022-2024 North Korea Citrine Sleet /Lazarus FUDMODULE ( BYOVD ) Rootkit Samples

2024-08-30 Microsoft: North Korean threat actor Citrine Sleet exploiting Chromium zero-day 2024-03-01 Lazarus group operations — A deep dive into FudModule Rootkit by Lucas Mancilha 2024-02-28 Avast: Lazarus and the FudModule Rootkit: Beyond BYOVD with anAdmin-to-Kernel Zero-Day - Avast Threat Labs 2024 Blackhat Asia Speakers: Luigino Camastra, Igor Morgenstern Video Slides 2024-04-18 Avast: From…

2024-08-28 CORONA MIRAI Botnet Spreads via Zero-Day (CVE-2024-7029) - command injection vulnerability found in the brightness function of AVTECH closed-circuit television (CCTV) Samples

2024 -08 -28 Akamai Beware the Unpatchable : Corona Mirai Botnet Spreads via Zero -Day (CVE -2024 -7029) - command injection vulnerability found in the brightness function of AVTECH closed -circuit television (CCTV ) Akamai's Security Intelligence and Response Team (SIRT) has identified a new botnet campaign exploiting multiple vulnerabilities, including a zero-day vulnerability, CVE-2024-7029 ,…

2024-08-29 ASYNCRAT Samples

2024 -08 -29 Esentire: Exploring AsyncRAT and Infostealer Plugin Delivery Through Phishing Emails eSentire's Threat Response Unit (TRU) discovered an AsyncRAT infection that was delivered through a Windows Script File (.wsf) via email. The malicious .wsf file, named “SummaryForm_,” downloaded a VBScript from a remote server, which then fetched a fake image file. This file was actually a ZIP…

2024-08-29 UNDERGROUND Ransomware Samples

2024 -08 -29 Fortinet Ransomware Roundup - Underground The Underground ransomware is likely spread by the RomCom group ( also known as Storm-0978). The group exploits the Microsoft Office and Windows HTML RCE vulnerability (CVE-2023-36884). Other methods, such as phishing emails and access via Initial Access Brokers (IABs), may also be used. Shadow Copies Deletion: It removes all shadow copies to…

2024-08-23 ANGRY STEALER (Rage stealer variant) Telegram rat . Samples

2024 -08 -23 Cyfirma . A Comprehensive Analysis of Angry Stealer : Rage Stealer in a New Disguise (Telegram rat ) . CYFIRMA analyzed malware known as " Angry Stealer", which is heavily advertised on platforms like Telegram, a repackaged version of the previously identified " Rage Steale r " The dropper is a 32-bit Win32 executable written in .NET, which acts as the initial stage of the attack.…

2024-08-14 OSX BANSHEE infostealer Samples

2024 -08 -14 Elastic: Beyond the wail : deconstructing the BANSHEE infostealer This analysis of BANSHEE Stealer reveals a sophisticated macOS-based malware (sold for $3,000) developed by Russian threat actors, targeting both x86_64 and ARM64 architectures. BANSHEE Stealer is designed to collect a wide range of data from infected systems, including browser history, cookies, logins, cryptocurrency…