Opalsec :verified: · @Opalsec
175 followers · 85 posts · Server infosec.exchange

Happy Monday folks, I hope you had a restful weekend and managed to take a breather from all things cyber! Time to get back into it though, so let me give you hand - catch up on the week’s infosec news with the latest issue of our newsletter:

opalsec.substack.com/p/soc-gou

are back and are using…OneNote lures? ISO disk images? Malvertising? Nah – they’re sticking with tier tried and true TTPs – their Red Dawn maldoc template from last year; macro-enabled documents as lures, and null-byte padding to evade automated scanners.

We’ve highlighted a report on the Xenomorph Banking Trojan, which added support for targeting accounts of over 400 banks; automated bypassing of MFA-protected app logins, and a Session Token stealer module. With capabilities like these becoming the norm, is it time to take a closer look at the threat Mobile Malware could pose to enterprise networks?

North Korean hackers have demonstrated yet again that they’re tracking and integrating the latest techniques, and investing in malware development. A recent campaign saw eight new pieces of malware distributed throughout the kill chain, leveraging to deliver payloads and an in-memory dropper to abuse the technique and evade EDR solutions.

A joint investigation by and has unearthed a two-year campaign by Chinese actors, enabled through exploitation of unpatched SMA100 appliances and delivery of tailored payloads. A critical vulnerability reported by this week helps reinforce the point that perimeter devices need to be patched with urgency, as it’s a well-documented target for Chinese-affiliated actors.

is a novel malware targeting routers, sniffing network traffic and proxying C2 traffic to forward-deployed implants. TTPs employed in recent and campaigns are also worth taking note of, as is , a new malware family targeting specific web server applications to brute force logins and deploy an IRC bot for C2.

Those in Vulnerability Management should take particular note of the vulnerability, which appears trivial to exploit and actually delivers plaintext credentials to the attacker. CISA have also taken note of nearly 40k exploit attempts of a 2 year old code-exec-as-root vulnerability in the Cloud Foundation product in the last two months, so make sure you’re patched against it.

members have some excellent reading to look forward to, looking at HTTP request smuggling to harvest AD credentials and persisting with a MitM Exchange server, as well as a detailed post that examines ’s reflective loading capability;

The has some great tradecraft tips from @inversecos on DFIR, as well as tools to help scan websites for malicious objects, and to combat the new and well-established Raccoon Stealer.

Catch all this and much more in this week's newsletter:

opalsec.substack.com/p/soc-gou

#emotet #android #microsoft #intune #byovd #mandiant #sonicwall #fortinet #hiatusrat #draytek #batloader #qakbot #gobruteforcer #veeam #vmware #redteam #cobaltstrike #blueteam #azure #stealc #infostealer #infosec #cyber #news #cybernews #infosecnews #informationsecurity #cybersecurity #newsletter #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #soc #threatintel #threatintelligence #darkweb #mdm #dprk #fortios #FortiProxy

Last updated 2 years ago

lazarusholic · @lazarusholic
2 followers · 29 posts · Server infosec.exchange

"Stealing the LIGHTSHOW (Part Two) — LIGHTSHIFT and LIGHTSHOW" published by Mandiant. , , , , , , , mandiant.com/resources/blog/li

#unc2970 #lightshift #lightshow #byovd #yara #cti #osint #lazarus

Last updated 2 years ago

lazarusholic · @lazarusholic
2 followers · 28 posts · Server infosec.exchange

"Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970" published by Mandiant. , , , , , , mandiant.com/resources/blog/li

#unc2970 #lightshow #byovd #yara #cti #osint #lazarus

Last updated 2 years ago

ESET research · @ESETresearch
1200 followers · 21 posts · Server infosec.exchange

BlackLotus brings legit but vulnerable binaries to the victim’s system () to exploit -2022-21894 and bypass UEFI Secure Boot on up-to-date Windows systems. In some samples, these binaries are downloaded directly from the MS Symbol Store. cve.mitre.org/cgi-bin/cvenam… 2/11

#byovd #cve

Last updated 2 years ago

Virus Bulletin · @VirusBulletin
1260 followers · 232 posts · Server infosec.exchange

ESET's Martin Smolár (@smolar_m) analyses the BlackLotus UEFI bootkit, which bypasses UEFI Secure Boot even on fully updated Windows 11 systems. BlackLotus brings legitimate but vulnerable binaries to the victim’s system () to exploit -2022-21894 and bypass UEFI Secure Boot. welivesecurity.com/2023/03/01/

#byovd #cve

Last updated 2 years ago

lazarusholic · @lazarusholic
0 followers · 21 posts · Server infosec.exchange

"공공 기관 및 대학 등에 널리 사용하는 공인인증서 소프트웨어 취약점을 이용한 Lazarus 공격 그룹 공격 사례" published by Ahnlab. , , , , asec.ahnlab.com/ko/48416/

#byovd #lazardoor #cti #osint #lazarus

Last updated 2 years ago

Opalsec :verified: · @Opalsec
59 followers · 26 posts · Server infosec.exchange

I've read and analysed last week's infosec news, so you don't have to - get up to speed on the latest in hacks, malware, tradecraft and more with this week's newsletter:

opalsec.substack.com/p/soc-gou

A vulnerability in the widely-used, open-source JsonWebToken package has highlighted the continued reliance on vendors for supply chain security.

It's not just APTs - cyber crims are eyeing off kernel space, with /#UNC3944 abusing the technique in an attempt to load their malicious driver into kernel space and subvert EDR controls.

We take a look at research into infrastructure - it's multi-tiered, growing, and highly flexible...but also vulnerable to takeover. Will this be the next , still spreading and hijacked by a 3rd-party in 10 years time?

warns an unknown, stealth-conscious actor with a "deep understanding of " has been seen exploiting the month-old FortiOS vulnerability (CVE-2022-42475) to drop additional malware & subvert logging.

There's a tonne more interesting reporting and tradecraft that I can't get to in this post, but you can find them in the newsletter - check it out, and subscribe to get the latest issues straight to your inbox, and support my work!

opalsec.substack.com/p/soc-gou

#scatteredspider #byovd #RaspberryRobin #andromeda #fortinet #fortios #infosec #cyberattack #hacked #cyber #news #cybernews #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #redteam #soc

Last updated 2 years ago

Tech News Worldwide · @TechNews
11255 followers · 97977 posts · Server aspiechattr.me
IT News · @itnewsbot
1661 followers · 238595 posts · Server schleuss.online

How a Microsoft blunder opened millions of PCs to potent malware attacks - Enlarge (credit: Getty Images)

For almost two years, Microsoft... - arstechnica.com/?p=1889745 &it

#byovd #biz #features #microsoft #windowsdriverblocking #bringyourownvulnerabledriver

Last updated 2 years ago