At #VB2023 https://t.co/J4LtVeaQQf's Guillaume Couchard & @r1chev will outline the infection chains used by commodity malware, common detection methods used against them, & how generic detection rules on these chains can help in the fight against botnets. https://t.co/fsifdFMsuk
🔴 Yesterday, the 🇷🇺 Russian-affiliated hacktivist group #NoName057 leveraged its #DDoS tool #DDoSia to target #PMCWagner websites wagner2022[.]ru / wagnercentr[.]ru💣
During daily threat monitoring, our Threat & Detection Research (TDR) team identified new #NoName057's #DDoSia 🇫🇷 targets ⤵️
www[.]assemblee-nationale[.]fr
www[.]gendarmerie[.]interieur[.]gouv[.]fr
cnes[.]fr
dares[.]travail-emploi[.]gouv[.]fr
The indicator of compromise mentioned in the Google TAG report that corresponds to a C2 server of #Rhadamanthys is 104.156.149[.]126, active at least from January 16, 2023 to end of March according to our @sekoia_io C2 trackers.
It was also publicly shared by @0xrb on ThreatFox!
Today TDR analysts released a blogpost related to 🇰🇵 #DPRK associated #Reaper#APT (aka #APT37), based on their observations of this group's C2 🧵 1/6
https://t.co/SuDb3nFUVc
Last week, we published an analysis of the newly discovered infostealer named #Stealc. Here is the part 2 with the reverse engineering of the #malware.
https://t.co/EtdolkbEP2
💣 Among others, @sekoia_io discovered yesterday 55 #PyPI malicious packages pushed by the same Threat actor.
It's not the first time that we are seeing this actor pushing this kind of malicious packages. PyPI contacted and packages removed 👌
Related packages and IoCs below ↘️
https://t.co/CnRXY1H4Ke uncovered a new #infostealer advertised as #Stealc on underground forums since early 2023 and already widespread in the wild.
In a nutshell, Stealc is a copycat of the prominent #Vidar and #Raccoon stealers.
https://t.co/3FqVt4y9ZM
As the ongoing 🇷🇺 Russo-Ukrainian 🇺🇦 conflict is about to mark its first year anniversary, our analysts share through our latest blogpost their analysis pertaining to the #cyber picture.
https://t.co/CABD2f9BZZ
Netzob is back with its v2.0.0 major release. New datatypes, new relationships, and a brand new fuzzing module for message format and state machine! #ProtocolModelization#TrafficGeneration#ReverseEngineering Release: https://t.co/kMY1C4pasu New doc: https://t.co/emiWwaf2vS
Our new blog post aims at presenting a typical infection chain distributing #Raccoon and #Vidar stealers by leveraging SEO poisoned websites.
https://t.co/CnRXY1H4Ke illuminated a large and resilient infrastructure of 250+ domains.
https://t.co/LAt0Zrw706
Our new blog post aims at contextualising and analysing trends pertaining to cyber malicious activities associated to the 🇰🇵 Democratic People’s Republic of Korea-nexus Intrusion Sets reported in open sources in 2022 ⤵️
https://t.co/W7wDvPRGKO
#CTI#DPRK
#IcedID is distributed on sites impersonating popular enterprise software applications, such as Zoom or Slack. Such infection chains are usually used by threat actors distributing infostealers (Raccoon, Vidar, Redline, Aurora, etc.)
⬇️
#Vidar stealer (botnet 1821) distributed using a fake website that mimics MSI Afterburner software and uses Google Ads
mslaftrebunrer.]us (ping @Namecheap)
https://t.co/MGTwF9MShl