Summary: ReversingLabs researchers have uncovered a new malicious software campaign linked to North Korea’s Lazarus Group, targeting developers through fake job interviews and malicious Python packages. The campaign utilizes sophisticated techniques to lure victims into executing malware disguised a…
Tag: THREAT HUNTING
The article analyzes the Konni campaign linked to the Kimsuky cluster, highlighting how legitimate cloud and FTP services are used in a multi-stage infection chain that targets South Korea and Russian government agencies. It also notes the abuse of overseas fr…
OVERVIEW The MITRE ATT&CK framework is a comprehensive matrix of tactics, techniques, and procedures (TTPs) used by cyber adversaries to carry out attacks. It provides a common language and a structured way to describe and categorize cyber adversary behavior. Here’s an overview of the key compon…
Unit 42 discusses WikiLoader malware spoofing GlobalProtect VPN, detailing evasion techniques, malicious URLs, and mitigation strategies.
The post Spoofed GlobalProtect Used to Deliver Unique WikiLoader Variant appeared first on Unit 42….
Summary: This report details a sophisticated intrusion involving the APT32/OceanLotus threat actor targeting a Vietnamese human rights organization, utilizing advanced malware techniques for espionage and data exfiltration. The investigation uncovered persistent footholds, scheduled tasks, and malic…
Huntress uncovereda long-running intrusion on a Vietnamese human rights defender’s machine, with overlaps to APT32/OceanLotus techniques and tactics. The incident highlights how sophisticated threat actors pursue persistence and information gathering against n…
Short Summary: This publication outlines best practices for event logging to enhance cyber security and resilience against threats. Developed by the Australian Cyber Security Centre (ACSC) in collaboration with international partners, it emphasizes the importance of effective logging solutions to su…
Summary: Effectively managing and utilizing enterprise data is crucial for enhancing cybersecurity, yet many organizations struggle with data silos and the manual effort required to extract valuable insights. Implementing a security data fabric can streamline data analysis and improve security postu…
Summary: A significant 56% of security professionals express concern over AI-powered threats, highlighting a gap in structured AI training within organizations. As AI technology evolves, the urgency for cybersecurity professionals to upskill and adapt to these emerging challenges becomes increasingl…
Summary: Microsoft has patched a Mark of the Web security bypass vulnerability (CVE-2024-38213) that was exploited by attackers to bypass SmartScreen protection, highlighting ongoing threats from various cybercriminal groups. The vulnerability, discovered by Trend Micro, requires user interaction to…
Both ZPHP and DarkGate made their first appearance in the Top 10 Malware list for Q2 2024. Here’s what else the CIS Cyber Threat Intelligence team observed….
Summary: Security Operation Centers (SOCs) are increasingly turning to AI to manage the overwhelming volume of data and sophisticated threats, allowing human analysts to focus on more strategic tasks. While there are concerns about job displacement, AI is expected to create new roles and enhance the…
Mitigant Cloud Attack Emulation and Sekoia SOC demonstrate how to emulate and detect Scattered Spider-like attacks in an AWS environment, illustrating a Threat-Informed Defense approach that blends security measures, threat intelligence, and testing. The artic…
Volt Typhoon is a suspected state-sponsored group targeting critical infrastructure, exploiting vulnerabilities in common network apps to gain long-term, stealthy access across multiple sectors. The operation used a KV Botnet of compromised routers as proxies,…
The blog post “Linux Defense Evasion Techniques Detected by AhnLab EDR (1)” [1] covered methods where the threat actors and malware strains attacked Linux servers before incapacitating security services such as firewalls and security modules and then concealing the installed malware. This post will cover additional defense evasion techniques against Linux…