Novel KimJongRAT stealer variants identified: One implements in Portable Executable (PE) format and the other leverages PowerShell. We compare these variants to previous versions of the malware. https://t.co/j05t6KjkXW
Unit 42 researchers shed light on a #phishing campaign that peaked in mid-2024, targeting approximately 20k users across European companies. The campaign utilized fake forms created through the HubSpot Free Form Builder service. https://t.co/KmdAzqgvrs
#NorthKorea#APT#xianliming#China#Russia#Vanuatu
North Korean threat actors have set up infrastructure in Russia using Chinese login names. The vu country code is Vanuatu.
- xianliming
- 西安立明
Sample is now on VT!
🚩Hash: 0f6b9d2ada67cebc8c0f03786c442c61c05cef5b92641ec4c1bdd8f5baeb2ee1
🎯Actor name: COLDRIVER
🔹Comment: Recently, TAG has observed COLDRIVER continue this evolution by going beyond phishing for credentials, to delivering malware via campaigns using PDFs as lure documents. TAG has disrupted the following campaign by adding all known domains and hashes…
🌐URL: https://t.co/ar2fKBGrNO
🔎OnVT: https://t.co/mLyTPUHeO6
This research focuses on how attackers can exploit Google Vertex AI by injecting harmful code or deploying poisoned models, resulting in unauthorized access and extraction of ML models and sensitive data. https://t.co/sl07AoQY46
SnipBot, a #RomCom#malware variant, is analyzed by our researchers for its complex infection mechanisms. It leverages fake websites and employs disguise tactics to manipulate registry entries, adding layers of difficulty for detection. Read more: https://t.co/OtWmaQf3un
Cloud cybersecurity can be a moving target. Recent activities by Bling Libra — the group behind #ShinyHunters#ransomware — underscore this. Using the MITRE ATT&CK framework, we walk through their novel cloud tactics in an extortion case. https://t.co/rexfIuDsRf
2024-07-30 #OlympicScam Alert: We found an 2024 Olympics-themed investment scam that started a few days ago. This scam uses an Android app and is presented as an official Olympics investment program related to cryptocurrency. Details at https://t.co/RXq1tD6r5e #crypto#scam
@cryptoron@adejoode Lage KYC (know your customer) maatregelen, redelijk un-attrib achtige betalingsmethodes, gunstig nationaal juridisch & politiek klimaat.
Met dat laatste doel ik op gebrek aan tactisch/strategische/pro-actieve aanpak vanuit NCSC/NP/Politiek
JavaScript-based malware #GootLoader is being distributed via fake forum posts. Unit 42 researchers have analyzed several samples this year alone, and in this article explain how to leverage Node.js to analyze its evasion techniques in a particular sample. https://t.co/QDtg9Jxm3A
@danielverlaan Ik ben het ook niet eens met deze ontwikkeling. Maar ik denk dat jou uitspraak gebrekt aan nuance. Vooral gezien je bereik lijkt mij dat iets zorgelijks.
2024-06-11 (Tuesday): Our telemetry reveals ongoing exploitation attempts of #CVE20244577 in #PHP on Windows. Our customers are protected from these exploits including the "auto_append_file" method. More information we found on this vulnerability at https://t.co/fKqTBOwJ4G
Analyzing about 6k malicious Microsoft OneNote files with a phishing-like theme, we cover how attackers can plant malicious payloads by embedding objects in certain extensions. https://t.co/gYToKb1wD7
Malicious redirection, logging victim activities, and more — a close analysis of how attackers use DNS tunneling for scanning and tracking in three observed campaigns exhibits how these understudied methods work. https://t.co/JUfR4e4vI1
2024-04-30 (Tuesday): We've found several seemingly legitimate websites hosting JavaScript-based #webskimmers. List of associated file hashes for examples of skimmer code and domains used by endpoints collecting the stolen data are available at https://t.co/vxXNJdXFi7
Sisense is experiencing a security event that may involve the exposure of customer credentials, login details, tokens, and other sensitive data.
If you are a Sisense customer, we recommend rotating all keys, credentials, or other secrets as appropriate. https://t.co/I2HrF2SrvT
The issue is fixed in hotfix releases of PAN-OS 10.2.9-h1, PAN-OS 11.0.4-h1, PAN-OS 11.1.2-h3, and in all later PAN-OS versions. Hotfixes for other commonly deployed maintenance releases will also be made available to address this issue. Details: https://t.co/gqdBUHOkrp
Our telemetry revealed an interesting case of #BoggySerpens (#MuddyWater) against a Middle East target: Persistence through scheduled task that runs PowerShell to abuse AutodialDLL registry key. AutodialDLL loads DLL for C2 framework. Details at https://t.co/AHR4Z77PLz