New Blog: Sponsored by Russian military intelligence, APT44 is a dynamic and operationally mature threat actor that is actively engaged in the full spectrum of espionage, attack, and influence operations. https://t.co/fEBboG3Zmu
UNC6671 has targeted dozens of orgs across using a distinct subdomain-based infrastructure model (.enrollms[.]com), new GTIG blog digs into their TTPs: https://t.co/TRbOXmdhow
So, this is what I was busy working on.. A really interesting (and sophisticated) Adobe Reader PDF "fingerprinting" exploit involving zero-day and allowing to launch additional maybe RCE/SBX exploitation!
https://t.co/k3Rmy8k4rS
The #axios maintainer just confirmed #UNC1069 🇰🇵 used the same playbook we documented in February.
Cloned a founder's identity. Built a convincing Slack workspace. Scheduled a call. Fake "update" deployed WAVESHAPER.V2. npm creds stolen. Trojanized axios update pushed.
Shout out to Mandiant Threat Defense and all the teams in GTIG that quickly neutralized this at dozens of clients overnight: North Korea-Nexus Threat Actor Compromises Widely Used Axios NPM Package in Supply Chain Attack https://t.co/nRB5kylmyC
I received a suspicious email with a weird link yesterday.
My first thought was this is yet another phishing attempt, albeit well-tailored.
I was wrong: researchers with whom I shared this email told me I was targeted by a very recent DarkSword attack used by the GRU.
If I were to click the link in that email, my phone would be compromised — without entering any passwords or doing anything else.
Fun fact: the attack would be launched only if I would access the link using an iPhone registered in Lithuania (which is indeed my case). Luckily, I didn’t click.
Beware!
Technical details about this exploit and how to stay protected: https://t.co/6m2ewFRk0d
@borealissaves I’m skeptical of that report because it conflates "intrusion attempts" with actual intrusions. 2.6M "attempts" a day usually means automated pings and port scans, not millions of unique breaches.
UPDATE: New guidance due to the recent Salesforce advisory regarding Gainsight applications.
Get hardening, logging, and detection recommendations for programmatic credentials.
https://t.co/26ncbjyba3
Mandiant: "In many cases, the average dwell time of 393 days exceeded log retention periods and the artifacts of the initial intrusion were no longer available."
The FBI has released a FLASH alert on the targeting of Salesforce platforms by the cybercriminal groups UNC6040 and UNC6395, which are responsible for a surge in data theft and extortion attempts. Click for indicators of compromise (IOCs) and protect your organization: https://t.co/CNCBWbMzMj