The Internet is full of cats—and in this case, malware-delivering fake cat websites used for very targeted search engine optimization.
Tag: THREAT HUNTING
Team Axon discovered a design flaw in Google Workspace’s Domain-Wide delegation—named “DeleFriend”—that can be abused to escalate privileges and access Workspace APIs without Super Admin rights. The issue was responsibly disclosed to Google in August 2023 and …
The article examines ransomware campaigns that target cloud storage—especially Microsoft OneDrive—showing how attackers use stolen credentials, abused application permissions, and external services to encrypt or delete cloud files. It highlights detection and …
Although not a new concept, Operational Relay Box (ORB) networks—often referred to as “covert,” “mesh,” or “obfuscated” networks—are…
Sophos X-Ops documents a multi-year campaign by China-linked actors exploiting Sophos/Cyberoam devices using zero-days, command injection, rootkits, and firmware-level persistence to maintain stealthy access and pivot to cloud assets. Notable tooling and impla…
Nearly 1 million individuals’ information was stolen and exposed when threat actors launched a BlackSuit ransomware attack on 10 April 2024. The investigation revealed that the compromised data included the victims’ Social Security numbers (SSNs), birthdays, and insurance claim information.
Trend Micro’s Threat Hunting Team discovered EDRSilencer, a red team tool that threat actors are attempting to abuse for its ability to block EDR traffic and conceal malicious activity….
Peter Manev of Stamus Networks is a long-time Suricata contributor, creator of the Threat Hunting platform SELKS, and co-founder of Stamus Networks. Join us for an informal discussion around network security monitoring, managing a popular Linux distribution, some threat hunting tips and much more!
🔥 Join this channel to get access to perks:
https://www.youtube.com/channel/UCI8zwug_Lv4_-KPT62oeDUA/join
Cybersecurity, reverse engineering, malware analysis and ethical hacking content!
🎓 Courses on Pluralsight 👉🏻 https://www.pluralsight.com/authors/josh-stroschein
🌶️ YouTube 👉🏻 Like, Comment & Subscribe!
🙏🏻 Support my work 👉🏻 https://patreon.com/JoshStroschein
🌎 Follow me 👉🏻 https://twitter.com/jstrosch, https://www.linkedin.com/in/joshstroschein/
⚙️ Tinker with me on Github 👉🏻 https://github.com/jstrosch
🤝 Join the Discord community and more 👉🏻 https://www.thecyberyeti.com
22:00 MS/AD Lataeral Movement with SamrEnumerate
24:30 Steps to complete to follow along
28:00 Getting into SELKS
30:00 Filter sets to help hunt in traffic
36:00 Detections methods and IDS alerts
40:30 Kibana and SELKS dashboards
46:00 File Transactions
54:00 Q&A
Akira is a Ransomware-as-a-Service active since March 2023 that performs double extortion by exfiltrating data before encrypting victims’ files and has infected over 196 organizations. Its operators reuse Conti-derived tooling and techniques, including ChaCha …
Remote access trojans (RATs) can be considered the malware of choice by the world’s most notorious advanced persistent threat (APT) groups. And there’s a good reason for that. They are hard to detect, making them ideal for lateral movement, and also difficult to get rid of.
How Kaspersky implemented machine learning for threat hunting in Kaspersky Security Network (KSN) global threat data.
Summary: Microsoft has reported a multi-staged attack by the threat actor Storm-0501, which compromised hybrid cloud environments leading to data exfiltration, credential theft, and ransomware deployment across various sectors in the United States. This financially motivated cybercriminal group has…
Summary: DCRat, a modular remote access Trojan (RAT) offered as malware-as-a-service, has been delivered through innovative techniques such as HTML smuggling, targeting Russian-speaking users. This blog analyzes the methods used in a recent campaign, highlighting the malware’s evasion tactics and ex…
Navigating the world of cybersecurity education can be overwhelming. With so many certifications, academic programs, and free resources, it’s easy to get lost. But how do you find the right path without breaking the bank or wasting time?
Join us for a live AMA with cybersecurity experts Ryan Chapman and Aaron Rosenumd. They’ll discuss everything from online training platforms and in-person options like Pluralsight and SANS to advanced PhD programs. Have questions about specific certifications, academic paths, or free resources? Ask away!
Don’t miss this chance to get expert advice and learn how to make the most of your cybersecurity education. Subscribe, like, and share to stay updated on the latest cybersecurity news and insights.”
Black Basta operates as ransomware-as-a-service (RaaS) and uses double extortion, demanding payment for decryption and the non-release of stolen data. It has impacted 500+ organizations globally, with initial access commonly gained via phishing, Qakbot, Cobalt…