Redhotcyber · @redhotcyber
533 followers · 1488 posts · Server mastodon.bida.im
Thomas Keepout · @arpwatch
17 followers · 168 posts · Server ioc.exchange
Aida Akl · @AAKL
337 followers · 628 posts · Server noc.social
Just Another Blue Teamer · @LeeArchinal
88 followers · 143 posts · Server ioc.exchange

everyone and it's always a good start when the new The DFIR Report drops! This one includes , , and ends in data exfiltration and the deployment of the . Enjoy and Happy Hunting!

Link in the comments!

***I am going to leave one of the MITRE ATT&CK blank. I would like to see if any of you that see this can help FILL in that blank! If so, leave your thoughts in the comments OR send me a DM!***

TA0001 - Initial Access
T1566.002 - Phishing: Spearphishing Link

TA0002 - Execution
T1053.005 - Scheduled Task/Job: Scheduled Task
T1204.002 - User Execution: Malicious File

TA0003 - Persistence
T1053.005 - Scheduled Task/Job: Scheduled Task
T1078.003 - Valid Accounts: Local Accounts

TA0008 - Lateral Movement
[Here is your chance to fill in the blanks! Enjoy!]

#happymonday #truebot #cobaltstrike #mbrkiller #cybersecurity #itsecurity #infosec #blueteam #threatintel #threathunting #ThreatDetection #happyhunting

Last updated 1 year ago

Salvatore Lombardo · @Slvlombardo
5 followers · 188 posts · Server mstdn.social

, allarme per una nuova pericolosa attività rilevata - The Computer Security News (BLOG)
computersecuritynews.it/truebo

#Hacking #CyberSecurity #truebot

Last updated 1 year ago

Joe Słowik · @jfslowik
2711 followers · 1280 posts · Server infosec.exchange

Some analysis from my team and the Huntress Threat ops folks on recent exploitation of software, with a link to malware and potential deployment:
huntress.com/blog/investigatin

#goanywheremft #truebot #ransomware

Last updated 2 years ago

Security researchers have noticed a spike in devices infected with the downloader created by a Russian-speaking hacking group known as Silence.

The threat actor is also using a new custom tool called . Analysis of Silence's attacks over the past months revealed that the gang delivered Clop typically deployed by TA505 hackers, which are associated with the FIN11 group.

bleepingcomputer.com/news/secu

#truebot #malware #dataexfiltration #teleport #ransomware #cybersecurity #infosec

Last updated 2 years ago

securityaffairs · @securityaffairs
147 followers · 85 posts · Server infosec.exchange
ITSEC News · @itsecbot
988 followers · 32791 posts · Server schleuss.online

Breaking the silence - Recent Truebot activity - Since August 2022, we have seen an increase in infections of Truebot (aka Silence.... blog.talosintelligence.com/bre -2022-31199

#ta505 #grace #botnet #truebot #RaspberryRobin #cve

Last updated 2 years ago