The Turla group, a state-sponsored cyber threat actor, has launched a sophisticated campaign targeting Pakistan’s critical infrastructure, including energy, telecommunications, and government networks. Using advanced techniques like phishing and malware, Turla…
Tag: THREAT HUNTING
The article discusses the ongoing cyber operations of the Russian Foreign Intelligence Service (SVR), particularly their exploitation of JetBrains TeamCity CVE-2023-42793 to target technology companies globally. The SVR’s tactics include host reconnaissance, D…
This publication outlines a significant threat campaign targeting Chrome extension developers, highlighting a phishing attack that led to maliciously tampered extensions. It provides insights for organizations to detect and respond to this threat, along with a…
### #CrossDomainDefense #IdentityExploitation #UnifiedSecurityApproach Summary: Cross-domain attacks are increasingly being utilized by adversaries to exploit vulnerabilities across interconnected environments, emphasizing the critical need for a unified approach to identity security. Organizations…
Kimsuky, a North Korean cyber threat group, has been active since at least 2013, focusing on espionage against political, economic, and military targets. Their sophisticated tactics include spear phishing, malware deployment, and advanced evasion techniques, m…
Threat Actor: Identity Fraud Criminals | Identity Fraud Criminals Victim: Individuals Selling Biometric Data | Individuals Selling Biometric Data Price: Varies (Individuals compensated for their data) Exfiltrated Data Type: Authentic identity documents and biometric data Key Points : The operation i…
TRAC Labs discovered “WikiKit,” a credential‑harvesting phishing kit active since October 2024 that uses Jimdo‑hosted landing pages mimicking targeted company branding to steal corporate credentials. The campaign leverages href.li and app.salesforceiq‑style re…
The Monthly Intelligence Insights report from Securonix Threat Labs highlights significant cyber threats and vulnerabilities identified in November 2024, including Lunar Peek vulnerabilities, zero-day exploits in Windows, and emerging phishing campaigns. The r…
Major cybersecurity vendors like CrowdStrike release comprehensive annual threat hunting reports that detail attack trends, adversary techniques, and sector-specific insights. Key statistics include a 55% increase in interactive intrusions and a 75% rise in cloud environment attacks, emphasizing the evolving tactics of threat actors such as FAMOUS CHOLLIMA and SCATTERED SPIDER. #CrowdStrike #FAMOUSHOLLIMA
Annual cybersecurity reports from major vendors like CrowdStrike typically include an overview of the threat landscape, detailed analysis of threat actors and attack techniques, and strategic recommendations for defense. CrowdStrike’s 2024 report highlights surges in cloud-conscious intrusions, increased use of identity-based attacks, and the evolving tactics of nation-state adversaries such as Fancy Bear and Jackbot Panda, emphasizing the importance of proactive and adversary-focused cybersecurity. #CrowdStrike #FancyBear #JackbotPanda
Annual cybersecurity reports, like the Red Canary 2023 Threat Detection Report, typically comprise sections such as introduction, methodology, trends, and threat analysis, providing insights into threat statistics, techniques, and organizational impacts. Key findings highlight the rise of cloud and identity attacks, emergence of new malware families, and evolving adversary tradecraft, emphasizing the importance of early detection and mitigation strategies. #RaspberryRobin #CobaltStrike
This report provides a comprehensive overview of recent cyber threats, emphasizing identity breaches, cloud attack techniques, and malware-free intrusions. It highlights key trends such as the surge in Kerberoasting attacks and adversaries’ proficiency across multiple operating systems. #Kerberoasting #IndrikSpider
The 2023 Dragos Year in Review highlights increased cyber threat activity driven by global conflicts, including rising ransomware attacks on industrial sectors. It emphasizes the evolving threat landscape, notable vulnerabilities, and the importance of proactive defenses for critical infrastructure. #ELECTRUM #VOLTZITE
Summary : PUMAKIT is a sophisticated Linux malware featuring a multi-stage architecture, advanced stealth mechanisms, and unique privilege escalation techniques. It employs syscall hooking and memory-resident execution to evade detection, making it a significa…
Researchers attribute a new Linux-targeting campaign to the Romanian-speaking Diicot group that uses modified UPX packing, cloud-aware payloads, SSH brute-forcing, reverse shells, and crontab persistence to spread across cloud and non-cloud hosts. The campaign…