ICYMI: On August 29, 2023, an FBI-led effort dismantled the Qakbot malware and botnet. Learn about the upward attack trend preceding the takedown from Daksh Kapur, @_Fritto_, and Nico Yturriaga. https://t.co/3FZ5BzVSdF
Law enforcement led a successful campaign to disrupt and dismantle Qakbot on August 29, 2023. @TrellixARC’s Daksh Kapur, @_Fritto_, and Nico Yturriaga share everything you need to know to understand the malware and botnet. Qakbot:
https://t.co/rRnm9ge5jE
🚨 Giveaway 🚨
Do we need a reason to hold a giveaway?
We want to give away two @TCMSecurity vouchers!
(1) Practical Web Application Penetration Testing
AND
(1) Practical Ethical Hacking
All you have to do to enter is:
1️⃣ Retweet this Tweet
2️⃣ Make sure you’re following us
Winner announced tomorrow at 5:00 PM
Want to mitigate the risk of being targeted w/ LOLBins? During their #RSAC session (located in Moscone South - 153), @TrellixARC researchers @tim_hux & @_Fritto_ discuss applicable threat hunting strategies & map MITRE techniques to real world examples. https://t.co/EnI2IRMnq7
Avoid being a future victim of weaponized LOLBins — join @TrellixARC security researchers @tim_hux and @_Fritto_ at #RSAC to equip yourself with relevant threat hunting tools & techniques. https://t.co/X9ZUTNALzw
In an additional report today, the @Trellix Threat Intelligence Group talks CVE-2021-21974, providing data on telemetry gathered by our sensors & share information about activity targeting this 2yr old vuln that some have left unpatched.
https://t.co/OCdHaKGfl0
The latest @Trellix report covers CVE-2023-0286, researchers Mark Bereza(@ROPsicle) & John Dunlap discuss the vulnerability as well as the litany of prerequisites & mitigating factors that limit its usefulness to attackers.
https://t.co/uy0ZQqsiEk
VMWare identified older and outdated products that have reached end of general support are those targeted in ESXiArgs Ransomware attacks. VMWare recommends upgrading to the latest supported version and disabling the OpenSLP
service in ESXi.
https://t.co/UYezWy4d4z
Lockbit ransomware group has informed us they have acquired a 3rd ransomware variant.
- Lockbit Red
- Lockbit Black
- Lockbit Green
They also have modified their ESXI ransomware variant.
Yes, they actually wrote "TLP:RED" in the image.
1/ DEV-0569, current distribution via #GoogleAds.
1.- #Gozi aka #Ursnif (bot) ↓
2.- #RedLine (stealer) ↓
And if the conditions are right, possibly:
3.- #CobaltStrike (C2) ↓
4.- #Royal Ransomware 💥
(No more BatLoader in the infection chain)
🚨 Ongoing mass exploitation of CVE-2022-44877 (Centos Web Panel 7 Unauthenticated Remote Code Execution).
Source: 206.189.170.136 🇺🇸
Malicious Base64 payload is a reverse shell that connects to 206.189.170.136:9181
The scanning of CWP instances started around January 06th.