Showing posts with label APT Group. Show all posts
Showing posts with label APT Group. Show all posts

New APT Group 'Dark Pink' Discovered Targeting Military Branches and Government Agencies in APAC and Europe

Source@goup-ib

A new APT group, known as Dark Pink, has been discovered by cybersecurity firm Group-IB. The group, which has been active since mid-2021, has been found to be targeting military branches, government ministries, and agencies in the APAC region, as well as one organization in Europe. As of December 2022, Dark Pink had successfully breached the defenses of six organizations in five APAC countries (Cambodia, Indonesia, Malaysia, Philippines, and Vietnam), and one organization in Europe (Bosnia and Herzegovina).

Ageius wiper targeting Israeli HR and IT consulting firms


ESET researchers discovered a new wiper and its execution tool, both attributed to the Agrius APT group, while analyzing a supply-chain attack abusing an Israeli software developer. The group is known for its destructive operations.

APT37 North Korean APT using Internet Explorer 0 day exploit


Once again North Korean threat actor dubbed APT37 was seen using another 0-day exploit of Internet explorer (CVE-2022-41128)in the wild by the google TAG team. This is not the first time APT37 using any 0-day exploit they are targeting South Korean users for years. TAG team reported the issue to Microsoft and Microsoft has already taken the necessary steps and released the patch.

'BackdoorDiplomacy' Cyber-espionage targets middle eastern telecommunication firms


Bitdefender identified a cyber espionage activity that targets telecommunications firms of the middle east and is operated by Chinese threat actors during his research of analyzing the unknown binaries. Bitdefender believes that this group operate since 2017 and know for attacking the Middle East and Africa and the United States.
ProxyShell Exploit was used to gain initial access to the target's network and it seems that the attack started on 19-08-2021 with the two types of web shell including ReGeorg and another shell created by GitHub user grCod.

Cyber criminal group 'SCATTERED SPIDER' Target Telco and BPO


A financially  motivated, very active and fast evolving cyber-crime group dubbed as 'SCATTERED SPIDER' by CrowdStrike was under radar of this security company and now they published a detailed report of the activity and techniques used by this group.
"In this attack campaign, the adversary demonstrates persistence in trying to gain access to victim environments and performs constant, and typically daily, activity within the target environment once access is gained. It is imperative for organizations to swiftly implement containment and mitigation actions if this adversary is in the environment. In multiple investigations, CrowdStrike observed the adversary become even more active, setting up additional persistence mechanisms, i.e. VPN access and/or multiple RMM tools, if mitigation measures are slowly implemented. And in multiple instances, the adversary reverted some of the mitigation measures by re-enabling accounts previously disabled by the victim organization.

 Chinese Cyberespionage group target Philippines with USB drive as initial vector


Security Researcher from Mandiant (Part of Google Cloud) Identified a threat group which use USB devices as initial vector of infection and mainly targeted to Philippines audience. Also Mandiant found a Chinese connection in this activity and identifies this activity as UNC4191.

OPERA1ER APT Active Cybercriminal Group Targeting Africa .


Recently Group-IB discover APT OPERA1ER Cybercriminal which operate from Africa and active from 5 years.

Group-IB Threat Intelligence team investigate targeted attack on financial Organizations in Africa including more than 30 attack and over 30 million USD estimated damage by this cyber criminal group in his five years of operation.

Group-IB attributed this to threat actor codename OPERA1ER (Other name DESKTOP GROUP ,Common Raven, NXSMS)

Bahamut Cyber criminal group actively targeting users with fake VPN application


Looks like Bahamut cyber criminal group is still active and resides low with limited or filtered targeting to prevent beging caught in the wild. ESET researcher identified activity of this group since January 2022 where the group targeting android users with a fake SecureVPN application website and the website only provide the android version of the application.
"ESET researchers discovered at least eight versions of the Bahamut spyware. The malware is distributed through a fake SecureVPN website as trojanized versions of two legitimate apps – SoftVPN and OpenVPN. These malicious apps were never available for download from Google Play.

“Moldova Leaks “ caused biggest political scandal, Moldova Government quake after the hack

 


Moldova Government top official compromised by a hacking operation including Moldova’s President , Prime Minister and many member of the senior party.
Authorities said that Telegram account of President , Deputy PM and other officials were hacked on Wednesday and fake messages placed on telegram Now a newly registered domain called “Moldova Leaks” released the conversation of two big political person caused major political scandal.
Initially few private conversation from telegram of Sergiu Litvinenco Minister of justice leaked last week and Dorin Recean, the current Defense and National Security Advisor to the President and former Minister of Internal Affairs of Moldova, became the next victim this week

CYJAX uncover a sophisticated state sponsored larger scale phishing campaign


"Cyjax has investigated a sophisticated, large-scale phishing campaign that exploits the reputation of
international, trusted brands. It targets businesses in multiple verticals including retail, banking, travel,
and energy. Promised financial or physical incentives are used to trick victims into further spreading the
campaign via WhatsApp. Once victims are psychologically invested in the phish, they are redirected through

Certificate Authority being targeted by the State-sponsored chinese cyberespionage (Billbug)


Billbug
Stat-sponsored Chinese cyber-espionage targets certificate authorities and Government agencies in multiple Asian countries Symantec said in his report.
previously known Lotus Blossom , Billbug cyber-espionage is advance persistent threat actor active since 2009 and Symantec reported this type of activity 2018 and 2019  under the name Thrip . Now Symantec is sure that Thrip and Billbug is most likely the same group and no tracking all activity under the name Billbug.

Lazarus Attack Activities Targeting Japan (VSingle/ValeforBeta)

 


The attack group Lazarus (also known as Hidden Cobra) conducts various attack operations. This article introduces malware (VSingle and ValeforBeta) and tools used in attacks against Japanese organisations.

Microsoft: Ongoing, Expanding Campaign Bypassing Phishing Protections


 A phishing email campaign detailed earlier this month is expanding with the use of additional email services to hide malicious intent, according to a warning from software giant Microsoft.

Operation North Star – North-Korea hackers targeted US defense and aerospace companies

North Korea-linked hackers continue to be very active in this period, researchers reported a campaign aimed at the US defense and aerospace sectors.

ITG18 Hackers exposed his 40GB data accidentally

IBM X-Force Incident Response Intelligence Services (IRIS) has uncovered rare details on the operations of the suspected Iranian threat group ITG18, which overlaps with Charming Kitten and Phosphorous. In the past few weeks, ITG18 has been associated with targeting of  pharmaceutical companies and the U.S. presidential campaigns. Now, due to operational errors—a basic misconfiguration—by suspected ITG18 associates, a server with more than 40 gigabytes of data on their operations has been analyzed by X-Force IRIS analysts.

Evilnum APT group applied more sophistication in his operation

Today ESET published a report about the APT group Evilnum (active since at-least 2018) and its toolset . in the report ESET join the multiple links to track the activity of this group.

Bitdefender researcher discovered potentially state-sponsored APT group StrongPity.

Recently Bitdefender researcher (Radu tudorica, Cristina vatamanu, Alexandru maximcicus) discovered APT group StrongPity who is targeting victims in Turkey and Syria. The attacker uses watering hole tactics to infect target and install 3 tier C&C to avoid forensic investigation.

Critical FFmpeg Vulnerability in Home Assistant: File Theft & Root Access Explained

  Critical Home Assistant FFmpeg Vulnerability Allows File Theft and Root Command Execution A newly disclosed security vulnerability in Home...