Full write-up - lure screenshots, the VBS, Agta on the box, the 66-panel network behind it, YARA/Sigma/KQL:
https://t.co/htIBvjSKBP
#BlueTeam#DFIR#ThreatHunting
New alert, new host, new lure. So why were the Agta Backup binaries on it byte-identical to the ones I published three weeks ago?
Fake Adobe update -> ScreenConnect -> VBS -> Agta. 🧵
Agta lands as a hidden service with tasks that re-arm it every minute, then starts a keylogger and a live screen stream in the user's session.
That's two SYSTEM-level ways back in. Treat every credential typed on that host as stolen.
@Omargue82520161@Omargue82520161 In the sample I looked at, the kit landed in %TEMP%\1780088578925\. That digit string looks like a epoch timestamp. Don't hunt for the folder name, hunt for the tactics.
RMM abuse is on the rise. Daisy-chaining disparate tools is standard tradecraft. Here's what that looks like: one fake Webex download, ScreenConnect landed three ways, a self-named Go RAT, and a console built to lock a victim out of their own PC.
https://t.co/YzOPgwsYFj
node.exe is signed by OpenJS Foundation. So why was it spawning reg.exe to read MachineGuid from a scheduled task buried in AppData?
Signed binary. Extensionless loader. Every string locked to the folder name. In-memory C2. 🧵
Three controls:
1. Block node.exe from AppData via App Control (ML1) - EID 4688
2. Alert EID 4698 for tasks running a script runtime against a user-profile file
3. Hunt EID 4688 for node.exe -> reg.exe QUERY MachineGuid - the tell that fired the original detection
Full write-up - the Pyarmor triage trick, the miner config, getthem and nig, IOCs and two YARA rules, mapped to ASD Essential Eight + MITRE ATT&CK:
https://t.co/ZkqkndMnUt
#BlueTeam#DFIR#ThreatHunting#BlueTeamCoolTeam
Pyarmor encrypted every module body in this bundle. Zero URLs, IPs, or keys out of the protected code.
The honest filenames and the libraries shipped around them gave up the whole kit anyway: miner, stealer, wallet-phisher. No decryption needed. 🧵
Three controls that bite:
1. Hunt EID 4688 for python.exe/pythonw.exe running under C:\Windows\ - near-zero legit hits.
2. App Control blocks the bundled interpreter and xmrig.exe cold (ML1).
3. Treat "just a coinminer" as the thread to pull - the theft is the real story.
Full write-up - peeling the obfuscation without running it, the localhost RAT, IOCs and a YARA rule, mapped to ASD Essential Eight + MITRE ATT&CK:
https://t.co/zaBKpbzzrc
#BlueTeam#DFIR#ThreatHunting#BlueTeamCoolTeam
A host ran clean for 2 years. Then a new scheduled task appears: XblGameCachesTask.
It launches a PowerShell backdoor with no C2 address in it at all. The thing listens on 127.0.0.1:58172 and waits for a separate tunnel to reach in. 🧵
Three hunts that bite:
1. EID 4104: HttpListener + RunspaceFactory + VirtualProtectEx in one script.
2. powershell.exe owning a LISTENING socket - bizarre on a workstation.
3. EID 4698 for XblGameCachesTask; 4688 for conhost --headless.