Mr.Trunk · @mrtrunk
6 followers · 12805 posts · Server dromedary.seedoubleyou.me
Redhotcyber · @redhotcyber
548 followers · 1645 posts · Server mastodon.bida.im
Anonymous Germany · @AnonNewsDE
58942 followers · 10794 posts · Server social.tchncs.de

CERT-UA (Ukraine) und skizzieren ein aktuelles Angriffsszenario auf den in der und Osteuropa durch die staatlich-russische -Gruppe .

Im Visier: .

E-Mails mit -Anhängen; enthaltene Makros führen einen -Befehl aus und erstellen eine geplante Aufgabe, die sich als Firefox-Browser-Updater ausgibt. Geladen wird Malware, die den Server auf und zu einem für die macht.

(EN)
bleepingcomputer.com/news/secu

#microsoft #Verteidigungssektor #ukraine #apt #turla #exchange #xlsm #powershell #C2Server #hacker

Last updated 2 years ago

Miguel Afonso Caetano · @remixtures
447 followers · 1646 posts · Server tldr.nettime.org

: "In fact, Turla has arguably been operating for at least 25 years, says Thomas Rid, a professor of strategic studies and cybersecurity historian at Johns Hopkins University. He points to evidence that it was Turla—or at least a kind of proto-Turla that would become the group we know today—that carried out the first-ever cyberspying operation by an intelligence agency targeting the US, a multiyear hacking campaign known as Moonlight Maze.

Given that history, the group will absolutely be back, says Rid, even after the FBI's latest disruption of its toolkit. “Turla is really the quintessential APT,” says Rid, using the abbreviation for “advanced persistent threat,” a term the cybersecurity industry uses for elite state-sponsored hacking groups. “Its tooling is very sophisticated, it’s stealthy, and it’s persistent. A quarter-century speaks for itself. Really, it’s adversary number one.”"

wired.com/story/turla-history-

#cybersecurity #russia #turla #hacking

Last updated 2 years ago

Ain Tohvri · @tekkie
545 followers · 1193 posts · Server mstdn.social
Tommy Skaug · @tom
5 followers · 275 posts · Server thought.no

But Turla it seems to be not:

> […] Turla and Tomiris are separate actors. Tomiris is undoubtedly Russian-speaking, but its targeting and tradecrafts are significantly at odds with what we have observed for Turla. In addition, Tomiris’s general approach to intrusion and limited interest in stealth are significantly at odds with documented Turla tradecraft. […]

#turla #threat #tomiris

Last updated 2 years ago

Jonathan D. Abolins · @JonAbolins
318 followers · 1015 posts · Server mastodonapp.uk
Altreconomia · @altreconomia
215 followers · 1136 posts · Server sociale.network
heise online · @heiseonline
45175 followers · 3086 posts · Server social.heise.de

Analyse: Warum die russischen Cybertruppen in der Ukraine gescheitert sind

Hinter der ukrainischen IT-Abwehr wirkt eine mächtige Allianz aus US-Behörden, den großen Internetkonzernen und spezialisierten Abwehrfirmen.

heise.de/hintergrund/Ukraine-K

#verpasstodon #cyberangriff #cyberwar #fancybear #russland #turla #ukrainekrieg

Last updated 2 years ago

Jonathan D. Abolins · @JonAbolins
21 followers · 153 posts · Server infosec.exchange

«: A Galaxy of Opportunity» | Mandiant.
Note: Some of malware related indicators have vulgar references.

mandiant.com/resources/blog/tu

#turla #malware #russianmalware #ukraine #malwareanalysis

Last updated 3 years ago

EnjoyAnon · @EnjoyAnon
98 followers · 117 posts · Server infosec.exchange

“Notorious Russian Spies Piggybacked on Other Hackers’ USB Infections
The infamous, FSB-connected Turla group took over other hackers’ servers, exploiting their USB drive malware for targeted espionage.”

wired.com/story/russia-turla-f

#hackers #fsb #turla #malware #espionage

Last updated 3 years ago

DarkOperator 🚀 · @DarkOperator
1178 followers · 1456 posts · Server infosec.exchange

Notorious group appears to resurface with fresh on bit.ly/3X84q8Y

#russian #hacking #turla #cyberattacks #ukraine

Last updated 3 years ago

Mufasa :paw: · @ne1for23
416 followers · 1060 posts · Server betweenthelions.link

Notorious Russian Spies Piggybacked on Other Hackers’ USB Infections

The infamous, FSB-connected cyber-espionage group took over other hackers' servers, exploiting their USB drive malware for targeted .

Turla became infamous in 2008 as the hackers behind agent.btz, a virulent piece of malware that spread through US Department of Defense systems, via infected USB drives plugged in by unsuspecting Pentagon staffers.


wired.com/story/russia-turla-f

#turla #espionage #russia #fsb #usb #malware #mandiant

Last updated 3 years ago

Another day, another report of “top tier” nation-states getting away with:
- running “0171ef74.exe” out of a temp directory
- executing local system executables like net.exe, arp.exe, whoami.exe, etc.
- Using C2 with RC4 encryption and base64
- Using blatantly malicious domain names I won’t write here
- exfiltrating data using tools like rar.exe

🤦‍♂️😑🤦‍♂️

mandiant.com/resources/blog/tu

#apt #malware #turla

Last updated 3 years ago

Curt Wilson · @CurtWilson
303 followers · 145 posts · Server mastodon.social

Nice work, mandiant. It’s been a while since I looked at Andromeda but I recall it being quite prolific at one point. Old domains don’t mean no risk! mandiant.com/resources/blog/tu

#turla

Last updated 3 years ago

PrivacyDigest · @PrivacyDigest
156 followers · 352 posts · Server mas.to

, a Group, Piggybacked on Other ' USB Infections

The infamous, -connected Turla group took over other hackers' servers, exploiting their drive for targeted espionage.

wired.com/story/russia-turla-f

#malware #usb #fsb #hackers #espionage #russian #turla

Last updated 3 years ago

CTIN · @ctin
74 followers · 93 posts · Server infosec.exchange
Zenbox analysis of a key cyber observable from the Mandiant #Turla report that came out today | #malwareanalysis | https://vtbehaviour.commondatastorage.googleapis.com/9535a9bb1ae8f620d7cbd7d9f5c20336b0fd2c78d1a7d892d76e4652dd8b2be7_Zenbox.html

#turla #malwareanalysis

Last updated 3 years ago

Kevin Beaumont · @GossiTheDog
10323 followers · 64 posts · Server cyberplace.social
Redhotcyber · @redhotcyber
144 followers · 71 posts · Server mastodon.bida.im

La Runet sta diventando un ricettacolo di siti di phishing. 18k domini fake sono stati rilevati

Gli specialisti di hanno rilevato nel 2022 circa 18.000 siti di nel segmento di , ovvero il 15% in più rispetto all’anno precedente, i quali si sono concentrati su truffe di phishing.

Di fatto stiamo parlando di quell'icona rappresentata dal concetto di “”, simbolo anche del famigerato gruppo di russi . Tale simbolo raffigura un serpente che morde la sua stessa coda.

lnkd.in/dTRPeZ3g

#infosecurity #privacy #CyberSecurityNews #cybersecuritytraining #CyberSecurityAwareness #cybercrime #cybersecurity #hacking #dataprotection #ethicalhacking #informationsecurity #redhotcyber #turla #hacker #Uroboros #internet #russo #phishing #groupib

Last updated 3 years ago

dispatch · @dispatch
472 followers · 2723 posts · Server ioc.exchange