M-Trends 2023 is live! Download the 14th edition of Mandiant’s unique analysis of today’s cyber threat landscape today.
https://t.co/WouGruDvxK
#MTrends#Cybersecurity
In September 2022 Mandiant Managed Defense detected data staging and exfiltration at a Ukrainian organization. Digging into this incident, we discovered QUIETCANARY (aka Tunnus), a suspected Turla Team backdoor, was the source.
Mandiant Blog - Turla: A Galaxy of Opportunity https://t.co/Alh37xmdmv This is Mandiant’s first observation of suspected Turla targeting Ukrainian entities since the onset of the invasion.
@mgreen27@malmoeb@velocidex Yeah figuring out a way to keep the yara current would be awesome. The challenge is that the original ones I rely on (from @CapeSandbox ) usually have static detections logic (they check for MZ headers for ex.) So they need to be adapted for this in memory hunting scenario
🔥 “It is plausible that the actors behind UNC2165 operations will continue to take additional steps to distance themselves from the Evil Corp name.” - Mandiant https://t.co/bbPy7rUAdH
Just added an artifact to find hidden scheduled tasks that are using the evasion technique found in the Tarrask malware to the #Velociraptor Artifact Exchange. @velocidex
Get it here: https://t.co/rGkHQyVINT
@velocidex How many times during an IR engagement (typically large scale #ransomware) we have found Windows Defender quarantined a bunch of malicious tools from the threat actors along their intrusion path? Too many! This will speed up investigation and analysis
I've just published a small @velocidex 🦖 artifact to find, decrypt and return the original binaries from Windows Defender Quarantine folders, along with supporting info (such as PE structures) and hashes, across an entire organization in just seconds!
https://t.co/VJwCTsFiBB