Summary : NotLockBit is an advanced ransomware family targeting both macOS and Windows systems, utilizing sophisticated techniques for file encryption and data exfiltration. Its ability to mimic the behavior of existing ransomware like LockBit poses a signific…
Tag: THREAT HUNTING
Summary : YARA is a powerful tool for malware detection and classification, extensively used by Sekoia.io’s Threat Detection and Research team. The integration of YARA into their workflows enhances threat hunting and malware analysis, and the release of their …
Summary : ReversingLabs researchers have identified a rising trend of malicious activities targeting the VSCode Marketplace, particularly through npm packages. This shift highlights the vulnerability of development environments and the need for stringent secur…
Cybereason Security Services issues Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them. In this Threat Analysis report, Cybereason Security Services investigate the rising activity of the malware LummaStealer….
Analysis of packer-as-a-service (PaaS) HeartCrypt reveals its use in over 2k malicious payloads across 45 malware families since its early 2024 appearance.
The post Crypted Hearts: Exposing the HeartCrypt Packer-as-a-Service Operation appeared first on Unit 42….
Summary : Threat actors have utilized DLL side-loading techniques to deploy the Yokai backdoor, which was discovered during threat hunting activities. This backdoor exploits legitimate applications to evade detection and execute malicious payloads. #YokaiBackd…
In this blog entry, we discuss a social engineering attack that tricked the victim into installing a remote access tool, triggering DarkGate malware activities and an attempted C&C connection….
### #SpywareDetection #MobileSecurity #PegasusThreat Summary: A recent hunt on 2,500 mobile devices revealed a concerning prevalence of NSO Group’s Pegasus malware, with several users unknowingly compromised. The findings highlight the need for enhanced mobile security measures, especially among hig…
Summary : Silent Push Threat Analysts are tracking a campaign named “Payroll Pirates,” which involves a payroll redirection phishing scam targeting employees of various organizations, particularly Workday users. The group employs sophisticated tactics, includi…
Summary: ReversingLabs detected a malicious Python package named aiocpa, designed to compromise cryptocurrency wallets. Unlike typical attacks, this campaign involved the publication of a legitimate-looking crypto client tool that later delivered malicious upd…
Summary: In early November 2024, Huntress SOC uncovered a threat actor’s use of brute force attacks on an RD-Web instance to gain initial access to a network. The actor employed common tools like PsExec for lateral movement and installed a renamed malicious Me…
### #IdentityManagement #AutomationInnovation #EnterpriseGrowth Summary: Haveli has acquired a majority stake in AppViewX to enhance its certificate lifecycle management capabilities, driven by increasing demand for automation and non-human identity management. This partnership aims to scale operati…
Summary: Aqua Nautilus researchers discovered a new attack vector during a threat-hunting operation, revealing that threat actors exploit misconfigured JupyterLab and Jupyter Notebook applications to hijack streaming sports events. By deploying honeypots and a…
Summary: Security researchers from Hunt.io have identified a cyber operation utilizing the Sliver command-and-control framework and Ligolo-ng tunneling tool, targeting victims by impersonating Y Combinator. The operation highlights the evolving tactics of cybercriminals leveraging trusted brands to…
Summary: Lumifi has announced its acquisition of Critical Insight, marking its third acquisition in 13 months, which enhances its incident response capabilities and strengthens its position in the healthcare and critical infrastructure cybersecurity sectors. This strategic move aims to meet the grow…