WhatsApp caught NSO Group targeting its platform in violation of court orders. Files injunction
Also announces its donating to the Spyware Accountability Initiative https://t.co/XqeWJlisIu
Introducing: continuous YARA scanning against host response content! 🤩 Discover malicious, compromised, and other interesting content in near real time with Validin.
Read about what we did, how we did it, and why it matters on our blog: ⤵️
https://t.co/d6OYi9CZ8r
While setting up a new Tor analysis environment, I noticed that the @firefox installer had a different hash for each download. I compared one download to a known good installer and found a blob of data added to the installer that is unique per download (see screenshot).
Code similarity is a common and powerful way to cluster malware samples and make connections between seemingly unrelated malware families. Although it sounds simple, it is actually a complex problem and is hard to automate at scale without generating false positives. 1/
We release a tool in python to do dataset in #Suricata to pull and do sightings with @MISPProject !
You can test this tool here !
I'll do a post on medium quickly !
https://t.co/BS8IEoNUL9
#botconf2022
New blog post! In this post I take a look at #Emotet's TTP experimentation to use LNK shortcut files from start to the DLL execution. https://t.co/wxf7AhoLf0
#malware#lnk
AD mindmap update (now in svg 🥳 ):
- white background:
https://t.co/cvbcH38Ams
- black background:
https://t.co/ZrDLJOfj8S
Thanks to @Vikingfr and @Sant0rryu for the help !
As always xmind sources are available here : https://t.co/uBJZJeSufV
We've had 6 wipers in the wake of the Ukraine invasion but the biggest elephant in the room has been the infamous 'satellite modem hack'. Despite statements saying there was no malware involved, we believe it was the work of a 7th wiper– AcidRain
#Emotet E5 Update - Within the last several hours, we have seen some bots on the Epoch 5 botnet begin to drop SystemBC now as a module and execute it. This is the first drop beyond Cobalt Strike that we have seen since Emotet returned. This is a significant change 1/x
I've spent the last couple months doing extensive dev/testing to achieve shellcode injection in a remote process against a couple of top tier EDRs. I've learned a lot but I really can't overstate the value of the *concepts* presented in this blog post: https://t.co/CerFaumNGM
Conti ransomware group previously put out a message siding with the Russian government.
Today a Conti member has begun leaking data with the message "Fuck the Russian government, Glory to Ukraine!"
You can download the leaked Conti data here: https://t.co/BDzHQU5mgw
THREAD We investigated SwissArms: exported as civilian/humanitarian goods but in reality used against civilians in Rio’s favelas, by the Saudis in #Yemen & wreaking havoc on markets in Afghanistan
This is a good write up on #Qakbot, #IcedID, and #Emotet infection chains and post infection activity. Lots of good info for writing EDR detections. https://t.co/7p3Fxc3lNi
A common executable was run in 4 different hosts containing top tier EDRs to find Ntdll in memory to check for syscall/NTAPI traps. Can anyone see the interesting find here? 😆
With recent talk of Russian disinformation campaigns related to the current tensions around Ukraine we thought it would be timely to revisit some of Russia's previous attempts at disinformation, in particular the four M's that describe their use of satellite and aerial imagery 🧵