Zscaler Threat Hunting observed an SEO poisoning campaign on Bing distributing a signed, trojanized Ivanti Pulse Secure MSI to steal VPN credentials and exfiltrate them to a Microsoft Azure-hosted C2. The campaign uses lookalike domains, referrer-based conditional content delivery, and a credential-stealing DLL that targets connectionstore.dat; detected artifacts include the Ivanti-VPN.msi hash 6e258deec1e176516d180d758044c019 and C2 IP 4.239.95.1. #Ivanti-Pulse-Secure #Akira
Tag: THREAT HUNTING
Daily Recap, A new 8-byte write called RMPocalypse targets AMD SEV-SNP and an array of exploits including CVE-2025-61927 and a CL0P-linked Oracle EBS zero-day affecting Harvard, while threats persist across NTDS.dit credential harvesting and geo-mapping persistence. Threat actors also exploit SonicWall VPNs, mass RDP botnets target the US, and a UK rise in nationally significant attacks highlights evolving risk in critical infrastructure #RMPocalypse #CVE-2025-61927 #NTDSdit #OracleEBS #Harvard #SonicWall #RDPBotnet #UKAttacks
A webinar from ANY.RUN detailed evolving malware and phishing techniques—ClickFix, QR-code-enabled PhishKits (e.g., Tycoon2FA), and LOLBin abuse in DeerStealer—demonstrating why interactive sandboxing, automation, and fresh threat intelligence are critical for SOC detection and response. #ClickFix #Tycoon2FA #DeerStealer…
Security Awareness Month emphasizes the importance of proactive measures alongside traditional training to strengthen cybersecurity defenses. Threat hunting and continuous validation are essential to address vulnerabilities that awareness alone cannot fix. #CyberDefenseMatrix #ProactiveThreatHunting…
Proofpoint researchers identified TA585, a cybercriminal actor that manages its own infrastructure and delivery to install third-party malware such as MonsterV2, which acts as a RAT, stealer, and loader. The report details TA585’s ClickFix web-inject delivery, GitHub notification lures, SonicCrypt crypter usage, and multiple MonsterV2 indicators including file hashes and C2…
Threat actors (including APT28, APT29, Sandworm, and Gamaredon) use a range of living-off-the-land binaries, DLL side‑loading, scheduled task and autorun persistence, credential dumping (Mimikatz, LSASS access), lateral tools (PsExec, Impacket), and cloud/file-host exfiltration to conduct reconnaissance, lateral movement, and C2. Detection recommendations include targeted hunting alerts and queries (for masqueraded XML scheduled tasks, autorun key modifications, unsigned DLL loads, PowerShell/web requests, OAuth abuse in Microsoft 365, and more) plus broader controls like EDR/NDR, defense-in-depth, patching, and logging. #APT28 #APT29
Attackers used SEO poisoning and malicious ads to distribute fake Microsoft Teams installers that drop the Oyster (Broomstick) backdoor, providing persistent C2 access via a malicious DLL, scheduled task CaptureService, and rundll32.exe execution. Key IOCs include domains like teams-install.icu and nickbush24.com, IPs such as 185.28.119.228, and multiple malicious file hashes. #Oyster #nickbush24.com
A highly convincing invoice-and-W9 phishing email targeted a Validin employee and used a realistic company identity (Ignitecore Consulting LLC) and reply-to domain to try to collect payments. Investigators pivoted on HTML/CSS template hashes, registration and hosting patterns, self-signed certificates, and Cloudflare origin IPs to identify ~40 related domains and multiple origin IP addresses to block. #ignitecoreconsulting #Cloudflare
Microsoft observed a financially motivated group tracked as Storm-2657 using AITM phishing to steal MFA codes, compromise employee Exchange Online accounts, create inbox rules to hide Workday notifications, and redirect payroll to attacker-controlled bank accounts. The campaign targeted US universities and higher-education staff via tailored phishing themes and succeeded where phishing-resistant MFA was not enforced. #Storm-2657 #Workday
eSentire’s TRU discovered a novel Rust-based backdoor named ChaosBot that uses Discord for command-and-control, leverages compromised VPN and over-privileged Active Directory credentials, and can side-load via msedge_elf.dll. Observed capabilities include remote command execution via PowerShell, file transfer, screenshots, FRP-based reverse proxying, VM/ETW evasion, and attempted VS Code Tunnel deployment. #ChaosBot #frp
Trend Research and ZDI Threat Hunters have identified a large-scale RondoDox botnet campaign using an “exploit shotgun” that targets over 50 vulnerabilities across more than 30 vendors to compromise internet-exposed routers, DVRs, NVRs, CCTV systems, and web servers. Active exploitation has been observed globally since mid-2025, leveraging vulnerabilities including CVE-2023-1389, CVE-2024-3721,…
Oracle released a Security Alert for CVE-2025-61882, a remotely exploitable unauthenticated vulnerability in Oracle E-Business Suite’s Concurrent Processing (BI Publisher Integration) that can lead to remote code execution; customers are urged to apply provided updates and ensure prerequisite October 2023 Critical Patch Update is installed. Indicators of compromise and detection details (IPs, observed commands, and file hashes) are provided to support immediate hunting and containment. #CVE-2025-61882 #Oracle_E-Business_Suite
Artificial Intelligence is transforming cybersecurity by enabling faster detection and response to threats through automation and advanced analytics. Wazuh integrates AI features such as insights, vulnerability profiling, and threat hunting to strengthen defense mechanisms against sophisticated cyberattacks. #ClaudeHaiku #WazuhAI
Kaspersky integrated a machine-learning model for detecting DLL-hijacking (DLL sideloading) into its SIEM (Kaspersky SIEM), which analyzes loaded libraries with local attributes and Kaspersky Security Network validation to improve detection and reduce false positives. During pilot MDR testing the model detected multiple real incidents — including ToddyCat using Cobalt Strike via DLL sideloading, an infostealer masquerading as policymanager.dll, and a malicious loader (wsc.dll) on a USB drive — and flagged related IOCs. #ToddyCat #CobaltStrike #SystemSettings.dll #policymanager.dll #wsc.dll
The 2025 Cyber Threat Landscape Report highlights the rising concerns of nation-state attacks, AI-driven cyber threats, and insider risks impacting organizations worldwide. It also outlines strategic shifts like increased training, AI integration, and reliance on MSSPs to enhance cyber resilience. #NationStateAttacks #AIThreats #MSSP #InsiderThreats