Mr.Trunk · @mrtrunk
5 followers · 8781 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
5 followers · 8708 posts · Server dromedary.seedoubleyou.me
Mr.Trunk · @mrtrunk
5 followers · 8609 posts · Server dromedary.seedoubleyou.me
Bob Carver · @cybersecboardrm
86 followers · 103 posts · Server infosec.exchange

The malware downloader known as BATLOADER has been observed abusing Google Ads to deliver secondary payloads like Vidar Stealer and Ursnif. thehackernews.com/2023/03/batl

#cybersecurity #googleads #batloader #malware #VidarStealer #ursnif

Last updated 1 year ago

Opalsec :verified: · @Opalsec
175 followers · 85 posts · Server infosec.exchange

Happy Monday folks, I hope you had a restful weekend and managed to take a breather from all things cyber! Time to get back into it though, so let me give you hand - catch up on the week’s infosec news with the latest issue of our newsletter:

opalsec.substack.com/p/soc-gou

are back and are using…OneNote lures? ISO disk images? Malvertising? Nah – they’re sticking with tier tried and true TTPs – their Red Dawn maldoc template from last year; macro-enabled documents as lures, and null-byte padding to evade automated scanners.

We’ve highlighted a report on the Xenomorph Banking Trojan, which added support for targeting accounts of over 400 banks; automated bypassing of MFA-protected app logins, and a Session Token stealer module. With capabilities like these becoming the norm, is it time to take a closer look at the threat Mobile Malware could pose to enterprise networks?

North Korean hackers have demonstrated yet again that they’re tracking and integrating the latest techniques, and investing in malware development. A recent campaign saw eight new pieces of malware distributed throughout the kill chain, leveraging to deliver payloads and an in-memory dropper to abuse the technique and evade EDR solutions.

A joint investigation by and has unearthed a two-year campaign by Chinese actors, enabled through exploitation of unpatched SMA100 appliances and delivery of tailored payloads. A critical vulnerability reported by this week helps reinforce the point that perimeter devices need to be patched with urgency, as it’s a well-documented target for Chinese-affiliated actors.

is a novel malware targeting routers, sniffing network traffic and proxying C2 traffic to forward-deployed implants. TTPs employed in recent and campaigns are also worth taking note of, as is , a new malware family targeting specific web server applications to brute force logins and deploy an IRC bot for C2.

Those in Vulnerability Management should take particular note of the vulnerability, which appears trivial to exploit and actually delivers plaintext credentials to the attacker. CISA have also taken note of nearly 40k exploit attempts of a 2 year old code-exec-as-root vulnerability in the Cloud Foundation product in the last two months, so make sure you’re patched against it.

members have some excellent reading to look forward to, looking at HTTP request smuggling to harvest AD credentials and persisting with a MitM Exchange server, as well as a detailed post that examines ’s reflective loading capability;

The has some great tradecraft tips from @inversecos on DFIR, as well as tools to help scan websites for malicious objects, and to combat the new and well-established Raccoon Stealer.

Catch all this and much more in this week's newsletter:

opalsec.substack.com/p/soc-gou

#emotet #android #microsoft #intune #byovd #mandiant #sonicwall #fortinet #hiatusrat #draytek #batloader #qakbot #gobruteforcer #veeam #vmware #redteam #cobaltstrike #blueteam #azure #stealc #infostealer #infosec #cyber #news #cybernews #infosecnews #informationsecurity #cybersecurity #newsletter #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #soc #threatintel #threatintelligence #darkweb #mdm #dprk #fortios #FortiProxy

Last updated 1 year ago

Scripter :verified_flashing: · @scripter
218 followers · 965 posts · Server social.tchncs.de

BATLOADER Malware Uses Google Ads to Deliver Vidar Stealer and Ursnif Payloads
thehackernews.com/2023/03/batl

#batloader #malware #cybercrime

Last updated 1 year ago

S3rv0240X · @s3rv0240x
0 followers · 2 posts · Server infosec.exchange

The Hacker News: BATLOADER Malware Uses Google Ads to Deliver Vidar Stealer and Ursnif Payloads

thehackernews.com/2023/03/batl

#cybersecurity #malware #batloader #vidarstealers #ursnif

Last updated 1 year ago

ericWadeFord · @ericWadeFord
0 followers · 2 posts · Server infosec.exchange

OneNote Attachment Used to Deliver New Variant of

Source: blog.cyble.com/2023/02/02/new-

Targeted Industries: Manufacturing, Retail Trade; Potential to target all industries

Cyble recently observed a using a OneNote attachment (.one) in spam emails to deliver a .bat file that exhibits the same behavior as a new variant of . Deepwatch has observed cybercriminals using OneNote attachments to deliver ATI's Cyber Threat Intel team cannot find any reference to BatLoader being sold or offered through publicly available sources, which may suggest that a single cybercriminal or group operates BATLoader; this may indicate that the cybercriminal behind the phishing campaign is the same cybercriminal behind BATLoader. Cybercriminals using OneNote attachments could be an emerging trend. However, as of yet, it appears to be an isolated usage and not a widespread threat and may indicate that cybercriminals are testing out this distribution method.

#batloader #cybercriminal #qakbot #malwarere #cti #threatintelligence #threatintel

Last updated 2 years ago

Tony Lambert · @ForensicITGuy
119 followers · 44 posts · Server infosec.exchange

New blog post! In this one I look at a MSI sample referenced by @malwrhunterteam which resulted in and execution. Some fun twists and turns in this. forensicitguy.github.io/batloa

#batloader #ursnif #redline #malware

Last updated 2 years ago

Ian Kenefick · @ian_kenefick
148 followers · 25 posts · Server infosec.exchange

Found this new C&C Server - statisticpixels[.]com . Doesn't appear to be in use yet...

#batloader

Last updated 2 years ago

Colin Cowie · @th3_protoCOL
628 followers · 159 posts · Server infosec.exchange

Day 7️⃣​​ of : Detecting JavaScript malware

🔗​ github.com/colincowie/100DaysO

Todays rule was created using samples (from november) mentioned in Trend's new blog post:
📖​ "trendmicro.com/en_us/research/

I used the yara count module to help out with the detection!

#100DaysofYARA #batloader

Last updated 2 years ago

installationsoftware1.]com/0ssdt1/index/login

#threatintel #batloader

Last updated 2 years ago

Ian Kenefick · @ian_kenefick
44 followers · 3 posts · Server infosec.exchange

new c2 installationupgrade6[.]com

#batloader

Last updated 2 years ago

Ian Kenefick · @ian_kenefick
44 followers · 3 posts · Server infosec.exchange

@Viss True that :)

I actually forgot to tag this one as . Have fixed now.

#batloader

Last updated 2 years ago

Ian Kenefick · @ian_kenefick
44 followers · 3 posts · Server infosec.exchange

C2 grammarlycheck2[.]com

#batloader

Last updated 2 years ago

Colin Cowie · @th3_protoCOL
387 followers · 62 posts · Server infosec.exchange

More undetected
🎣 zoomfree[.]org

⬇️ File Download: ZoomInstallerFull_IIS_1.msi (hosted on 4sync)

🌐​ C2s:
archiverportal[.]space
onepdfreader[.]com

🔗 ​virustotal.com/gui/file/4fb32b
🔗 ​urlscan.io/result/6fb2da6c-341

CC @1ZRR4H

#batloader #malware #threatintel #cti

Last updated 2 years ago

MalwareLab :verified: · @malwarelab_eu
203 followers · 19 posts · Server infosec.exchange

Delivery of via by in malvertising campaign. This threat actor has used BATLOADER -> Beacon -> Royal .

Ref: microsoft.com/en-us/security/b

Footnote: adblocking solutions (e.g. , , @Raspberry_Pi) can prevent similar attacks

#batloader #malware #googleads #dev0569 #cobaltstrike #ransomware #ublockorigin #adblock #pihole

Last updated 2 years ago

Colin Cowie · @th3_protoCOL
387 followers · 62 posts · Server infosec.exchange

Undetected campaign themed around winrar ⚠️​

🎣​ extractor-rar[.]website/downlaod-1.html

⬇️ File Download: WinRar_ISS_6.1.11.msi

🌐​ C2: archiverportal[.]space

🔗 virustotal.com/gui/file/49a740
🔗 virustotal.com/gui/domain/arch

#batloader #threatintel #malware #ransomware #iocs #ioc

Last updated 2 years ago

a1 · @ar1
10 followers · 20 posts · Server mastodon.social

It's not the first time are used to distribute malware or some such malign code. The malware downloader, a strain referred to as , is a dropper that functions as a conduit to distribute next-stage payloads. It…lnkd.in/eZd29MNg lnkd.in/egKgUtMT

#googleads #batloader

Last updated 2 years ago

seadev · @seadev
136 followers · 71 posts · Server infosec.exchange

updates out today regarding DEV-0569 / Royal
+ DEV-0569 likely to continue malvertising and phishing for Initial Access
+ posed as installers for TeamViewer, Zoom, and AnyDesk
+ Malvertising campaign observed leveraging Google Ads to deliver Batloader selectively

microsoft.com/en-us/security/b

#MSTIC #ransomware #batloader #threatintel #infosec

Last updated 2 years ago