Our follow up blog on the mysterious RotaJakiro backdoor we published on Apr 28, RotaJakiro appears to be the Linux version of the OceanLotus APT. https://t.co/0ByKpGiokD
Our latest blog, a mysterious trojan that has been active for more than 3 years with 0 Vt detection, we don't exactly know the motive behind this trojan though, ping us if anyone has more details on this.https://t.co/fe9x55Dsvr
Two follow-ups about Exchange vulnerability attacks:
1. The target email address include: [email protected] , [email protected]
2. An attacker frequently attacks through the original webshell planting another webshell(http://182.160.112.151/test/2.aspx
).
Our latest blog, a new botnet, ZHtrap, turns infected devices into honeypot to help it find more victims, as well as using process whitelist and taking snapshot of the system processes to prevent new program running, this is something we rarely see. https://t.co/7FeZYlrF6c
Our latest blog, QNAP NAS users, check your firmware now, we started to see attack targeting QNAP NAS 4 days ago, and the attacker uses tricks to make sure you don't see high CPU usage https://t.co/aucvD9N4PN
We have seen #Fbot#botnet using multiple 0 days before(some of them we have not disclosed yet) and it has been targeting various IoT devices, now, it is aiming a new category, traffic and transportation smart devices.