Just Another Blue Teamer · @LeeArchinal
121 followers · 182 posts · Server ioc.exchange

Good day everyone! The ReliaQuest Threat Research team recently provided a wrap up of the most commonly used loaders, the top 80% which comprised of only three different malware! These big three are , , and . THEN, they not only provided the data sheet to provide to your management or C-suite, they broke them down even further to include technical details as well! Thank you to the Threat Research team for such a great report, I hope you enjoy it as much as I did, and Happy Hunting!

The 3 Malware Loaders Behind 80% of Incidents
reliaquest.com/blog/the-3-malw

#qbot #SocGholish #RaspberryRobin #cybersecurity #itsecurity #infosec #blueteam #threatintel #threathunting #ThreatDetection #happyhunting #readoftheday

Last updated 1 year ago

Aida Akl · @AAKL
261 followers · 439 posts · Server noc.social
Opalsec :verified: · @Opalsec
59 followers · 26 posts · Server infosec.exchange

I've read and analysed last week's infosec news, so you don't have to - get up to speed on the latest in hacks, malware, tradecraft and more with this week's newsletter:

opalsec.substack.com/p/soc-gou

A vulnerability in the widely-used, open-source JsonWebToken package has highlighted the continued reliance on vendors for supply chain security.

It's not just APTs - cyber crims are eyeing off kernel space, with /#UNC3944 abusing the technique in an attempt to load their malicious driver into kernel space and subvert EDR controls.

We take a look at research into infrastructure - it's multi-tiered, growing, and highly flexible...but also vulnerable to takeover. Will this be the next , still spreading and hijacked by a 3rd-party in 10 years time?

warns an unknown, stealth-conscious actor with a "deep understanding of " has been seen exploiting the month-old FortiOS vulnerability (CVE-2022-42475) to drop additional malware & subvert logging.

There's a tonne more interesting reporting and tradecraft that I can't get to in this post, but you can find them in the newsletter - check it out, and subscribe to get the latest issues straight to your inbox, and support my work!

opalsec.substack.com/p/soc-gou

#scatteredspider #byovd #RaspberryRobin #andromeda #fortinet #fortios #infosec #cyberattack #hacked #cyber #news #cybernews #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #redteam #soc

Last updated 2 years ago

Anonymous :verified_neko:🏴 · @YourAnonRiots
5102 followers · 29443 posts · Server mstdn.social

A new analysis reveals that 's attack infrastructure can be repurposed by other threat actors for their own malicious activities, making it an even greater threat to watch out for.

thehackernews.com/2023/01/new-

#Tech #CyberAttack #Hacking #CyberSecurity #InfoSec #RaspberryRobin

Last updated 2 years ago

Aida Akl · @AAKL
171 followers · 738 posts · Server noc.social

🪱 (REF: blog.sekoia.io/raspberry-robin)

'Clean' C2 domains:
/a7k.ro
/a5az.com
/v4a3.com
/4w.pm
/hlv1.com
/ubv5.com
/c43p.com
/2ipn.com

'Clean' compromised QNAP:
151.83.67.5
84.97.18.146
88.130.94.229
188.10.57.97

'New' exploited QNAP:
61.93.39.13
94.14.45.160

#RaspberryRobin #evilcorp

Last updated 2 years ago

Opalsec :verified: · @Opalsec
53 followers · 26 posts · Server infosec.exchange

Catch up on last week's infosec news with our latest newsletter: opalsec.substack.com/p/soc-gou

continues to improve its evasion mechanisms, extracting more data from victims in the Financial sector.

developers look to be dabbling in creating a Mac variant - but aren't quite there yet.

is being used increasingly over the past few months by heavy-hitting first stage malware such as Qakbot, IcedID and BumbleBee - make sure you understand how it works and how to spot it.

#RaspberryRobin #dridex #htmlsmuggling #infosec #cyberattack #hacked #cyber #cybernews #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities

Last updated 2 years ago

Anonymous :verified_neko:🏴 · @YourAnonRiots
5065 followers · 29302 posts · Server mstdn.social

worm is targeting financial and insurance sectors in Europe, and has evolved its post-exploitation capabilities to resist analysis and collect more data from infected computers.

thehackernews.com/2023/01/rasp

#Malware #Hacking #Technology #InfoSec #RaspberryRobin

Last updated 2 years ago

Sova · @sova
9 followers · 51 posts · Server infosec.exchange

How aren't blocking and controlling USB devices is beyond me. However, that is how a worm is spreading in Latin America and Europe right now.

securityaffairs.co/wordpress/1

#telecoms #tor #RaspberryRobin

Last updated 2 years ago

Anonymous :verified_neko:🏴 · @YourAnonRiots
4902 followers · 28711 posts · Server mstdn.social
Anonymous :verified_neko:🏴 · @YourAnonRiots
4972 followers · 28930 posts · Server mstdn.social
AA · @AAKL
151 followers · 2491 posts · Server noc.social
arb0ur · @arb0ur
10 followers · 4 posts · Server infosec.exchange

I've published a blog post examining the malware distribution behaviours in Microsoft's recent reporting of Raspberry Robin. The post intends to help analysts make sense of the loader landscape.

arb0ur.substack.com/p/examinin

#loader #RaspberryRobin #evilcorp #WizardSpider

Last updated 2 years ago

ITSEC News · @itsecbot
988 followers · 32791 posts · Server schleuss.online

Breaking the silence - Recent Truebot activity - Since August 2022, we have seen an increase in infections of Truebot (aka Silence.... blog.talosintelligence.com/bre -2022-31199

#ta505 #grace #botnet #truebot #RaspberryRobin #cve

Last updated 2 years ago

heval · @heval
3 followers · 16 posts · Server infosec.exchange

everywhere!!

#RaspberryRobin

Last updated 2 years ago

heval · @heval
3 followers · 16 posts · Server infosec.exchange

everywhere!

#RaspberryRobin

Last updated 2 years ago

MathieuB · @MathieuB
28 followers · 484 posts · Server mastodon.xyz
Parliamo di news! · @parliamodinews
15 followers · 87553 posts · Server masthead.social
Tarnkappe.info · @tarnkappeinfo
1529 followers · 3787 posts · Server social.tchncs.de
gaby_wald · @gaby_wald
70 followers · 16249 posts · Server framapiaf.org