🎣 #PhishingAlert: The Zoho Form link from this fake HP printer email notification leads to #Tycoon phishing page.
IOCs:
hxxps[://]forms[.]zohopublic[.]com/adminlera1/form/August/formperma/eKn5pLDz1u8g7yg3sQ_lKKMf0EaX66YDx87mW6TJolc
hxxps[://]vstvq[.]sormanvet[.]su/ZIHH0J/
hxxps[://]kWAS[.]guisx[.]ru
#MailMarshal #ZohoForm
🎣 #PhishingAlert: The initial URL from this #phishing campaign by #tycoon#PaaS displays a fake page of an email security vendor before redirecting to the next stage URL. The second URL is a compromised site that redirects to either https://t.co/LBgsAjlLDQ or the #Microsoft phishing page, depending on its validation of the initial URL's query part.
#MailMarshal
🚨 #MalspamAlert: A recent #malware campaign is making rounds, using email subjects related to legal issues or unauthorized content use to lure victims into downloading malware. The email pretends to be from a law firm alleging copyright infringement on a #Facebook page, complete with details of the supposed infringement. It contains a short link that redirects to a Dropbox-hosted archive, which includes a decoy PDF, a law firm logo, an executable misleadingly named "Content that infringes on copyright.exe" to appear as a legitimate document and a malicious DLL. When the executable is run, the DLL is sideloaded, deploying the Rhadamanthys #infostealer.
#IoCs:
Download URLs:
hxxps[://]t[.]ly/R8cBb
hxxps[://]www[.]dropbox[.]com/scl/fi/el80dg1rgy1ep7yedvmo2/Content-that-infringes-on-copyright[.]zip?rlkey=mpa7ca3vf3cbvucy6zcptmvpd&st=a9i7grw5&dl=1
File Hashes:
Content that infringes on copyright.exe
4864a55cff27f686023456a22371e790
08c7fb6067acc8ac207d28ab616c9ea5bc0d394956455d6a3eecb73f8010f7a2
msimg32.dll
80fa521b6426a4bfdbf86fc236aa1126
87b80761f18389ea14086a4f612d4f9ba9b695f5ef60746bda3e94f6f45552f9
C2 server:
15[.]235.176.166:8344
Leverage Trustwave #MailMarshal to protect against this and other email-borne threats.
Mallox has significantly expanded its operations. The group has transitioned to a RaaS model, enlisting affiliates to broaden its reach, contributing to a notable increase in activities, with a surge observed around mid-2023. (https://t.co/i8lHHCcu0O)
Inside a Mallox Attack
Trustwave #SpiderLabs has discovered a 120MB file called "BNKoFAmerica.txt" on the Dark Web, containing 667,599 lines of what looks like sensitive financial data, supposedly from Bank of America. The file includes user IDs, balances, card types, expiration dates, last 4 card digits, and possibly CVV codes. It also mentions the GWIM (Global Wealth and Investment Management) division over 11,600 times. This might be a genuine transaction log.
CISA and the FBI released a notification and guidance on Chinese-manufactured drones, that could have vulnerabilities enabling data theft or that could facilitate network compromises. (https://t.co/i8lHHCcu0O)#CISA#drones#CyberSecurity
Trustwave Government Solutions (TGS) has attained authorized status by the State Risk and Authorization Management Program (StateRAMP) for its Government Fusion platform. #CyberSecurity https://t.co/5f5ynxHer8
The focus is not on the DNC, but outside forces are also attempting to influence the upcoming presidential election. Harris-Trump Presidential Election: Looking at the Threats and Cybersecurity Challenges (https://t.co/i8lHHCcu0O) #DNC2024#GOP
@stefen_rosner Sorry this is blowing smoke. I tend to find the bright spot in most events and yes we have some points, but the team has blown 11 leads and can't keep the other team away from the net in the last few minutes of a game, or period for that matter.
What You Need to Know About Cyber Threats Targeting Hospitality - Trustwave #SpiderLabs team completed an extensive investigation into the global #cyber threats targeting the #hospitality sector.
https://t.co/i8lHHCbWbg
Trustwave just completed an almost 3-year-long project that took the team to several exotic Pacific paradises. We spent long days helping install variety of defensive platforms, but one couldn’t complain about the location. #CyberSecurity https://t.co/86GF2fUosY
From Trustwave SpiderLabs On May 19, 2023, Barracuda Networks identified a remote command injection vulnerability (CVE-2023-2868) present in the Barracuda Email Security Gateway. #emailsecurity https://t.co/DftO5Qk1sC
Former Texas Rep. William Thornberry and Trustwave Government Solutions President Bill Rucker sat down to discuss several pressing issues impacting the federal government’s cybersecurity preparedness. #cybersecurity#UkraineWarNews https://t.co/e5SlvM74YD
Having the best incident response plan in the world is useless unless you are prepared to implement it properly. #CyberSecurity#CyberSecurityAwareness
https://t.co/IvWgxWOtdI
Updated @Forbes: this article has now been updated following the three week (December 26) deadline for patching issued by #CISA. Extended comment from Ed Williams (@Trustwave SpiderLabs) warning why this is too long.
#infosec#Google#Chrome#ZeroDay
https://t.co/aNV8kr4m41
Trustwave SpiderLabs will conduct two briefing on the cyber weapons in the Ukraine-Russia War.
REG: AMS/EMEA on Tuesday, August 23, 2022 | 10am CDT | 4pm BST https://t.co/QYQB9TrxlY
REG: APAC on Wednesday, Aug. 24, 2022 | 7:00am SGT | 10am AEDT | 12pm NZDT https://t.co/pLqbZYnp4w