This web content provides a comprehensive guide on creating a free cybersecurity home lab to analyze WannaCry ransomware using tools like Elastic SIEM, Sysmon, Autopsy, and Volatility. It covers static and dynamic analysis, threat hunting, and forensic techniques to detect and respond to ransomware threats. #WannaCry #ElasticSIEM
Tag: THREAT HUNTING
SentinelLABS research identified multiple examples of malware that embed prompts and API keys to leverage LLMs at runtime, including a likely early LLM-enabled sample dubbed MalTerminal and LameHug (PROMPTSTEAL) linked to APT28. The team found prompt structures, embedded HuggingFace and OpenAI keys, and reuse of standard API libraries that enabled reliable hunting by API-key and prompt detection. #MalTerminal #LameHug
The threat actor gained access via a compromised SonicWall VPN, discovered plaintext Huntress recovery codes on a user desktop, used them to log into the Huntress portal, remediate incident reports, and uninstall agents while Akira ransomware was executed on a workstation. Proper handling of recovery codes and credentials is critical to prevent MFA bypass and suppression of detection; this incident involved Akira, a malicious IP 104.238.221[.]69, and the Huntress platform. #Akira #104.238.221[.]69
Attackers abused ConnectWise ScreenConnect installers and open directories to stage and deliver AsyncRAT and a custom PowerShell RAT using dual execution paths, repacked installers, and aggressive scheduled tasks for persistence. Infrastructure included multiple open-directory hosts, /Bin/ ClickOnce redirect chains, and high-ephemeral port C2s enabling resilient, evasive AsyncRAT operations. #AsyncRAT #ScreenConnect
Trend Research describes a targeted NPM supply chain attack where threat actors phished maintainer accounts to inject malicious code into widely used JavaScript packages, leading to credential theft, secret exfiltration, and cryptocurrency diversion. The report details a self-replicating worm called Shai-hulud and related Cryptohijacker payloads, provides attack chain analysis and mitigation…
Palo Alto Networks Unit 42 identified a novel, self-replicating npm supply chain worm called “Shai-Hulud” that has compromised over 180 packages by harvesting developer credentials and using stolen npm tokens to publish malicious updates. Unit 42 also assessed with moderate confidence that an LLM assisted in generating the malicious bash script,…
Wazuh and Zeek can be integrated to provide unified, real-time network visibility by ingesting Zeek logs into Wazuh for enrichment, correlation, alerting, and automated response. The integration supports use cases such as detecting brute-force attempts, DoS, reconnaissance/port scans, suspicious DNS queries, and SSL/TLS certificate issues. #Wazuh #Zeek…
Silent Push, a threat intelligence company based in Virginia, has raised $10 million in Series B funding to expand its global reach and enhance its platform. The company’s platform offers proactive threat detection by identifying malicious infrastructure and providing indicators of future compromise to help organizations defend against cyber threats. #SilentPush…
Validin introduced Dashboard Feeds (Threat Indicator Feed and Project Updates Feed) to surface newly reported IOCs and team activity directly on the homepage, improving analyst workflows and situational awareness. They also added daily PTR (reverse DNS) scanning across IPv4 to capture short-lived reverse DNS entries, illustrated by detection of rotating PTR records for 91.247.36[.]102, including free.friendhosting[.]net. #91.247.36.102 #free.friendhosting.net
Sysdig TRT discovered a new Go-based remote access trojan named ZynorRAT that uses a Telegram bot as its command-and-control channel to perform file exfiltration, system enumeration, screenshots, persistence via systemd, process control, and arbitrary shell execution on Linux (with an incomplete Windows build). Analysis of binaries, Telegram chats, VirusTotal submissions, and network telemetry suggests the developer is Turkish, actively refining the RAT, and likely preparing it for sale on underground markets. #ZynorRAT #lraterrorsbot
A new ToneShell backdoor variant tied to Mustang Panda was delivered via DLL sideloading inside ZIP archives and uses anti-analysis stalling, GUID-based host IDs, a rolling-XOR C2 scheme, and a minimal command set while targeting Myanmar. New indicators include DLL and archive hashes and a C2 at 146.70.29[.]229:443 that can aid…
A Chinese APT compromised a Philippine military company using a new fileless malware framework called EggStreme that injects payloads into memory and abuses DLL sideloading for persistent espionage. The core EggStremeAgent backdoor (with an injected EggStremeKeylogger) supports 58 commands for reconnaissance, lateral movement, and data exfiltration. #EggStreme #EggStremeAgent…
The article analyzes the Backdoor.Win32.Buterat sample, detailing its persistence, obfuscated strings and API usage (notably SetThreadContext and ResumeThread), dropped files, hashes, and C2 infrastructure. It also provides technical controls and remediation steps including indicators like file hashes and the C2 domain. #Backdoor.Win32.Buterat #ginomp3.mooo.com
This article emphasizes the importance of addressing detection gaps in SOC operations, which are often overlooked in favor of reducing false positives. Closing these blind spots improves visibility, threat detection, and overall security posture. #PowerShell #MLHTA
EvilAI is an active global campaign that disguises Node.js-based trojans as legitimate AI or productivity applications—using professional UIs and code-signing—to steal browser credentials, maintain AES-encrypted C2 communications, and persist via scheduled tasks, registry Run keys, and Start Menu shortcuts. Telemetry shows rapid, widespread infections across Europe, the Americas, and AMEA, heavily…