The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: Data Theft, Backdoor, Ransomware, Targeted Ransomware Attacks and Vulnerabilities. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.

Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.
Trending Cyber News and Threat Intelligence
(published: April 30, 2021)
Codecov has disclosed multiple IP addresses as IOCs that were used by the threat actors to collect sensitive information (environment variables) from the affected customers. The company disclosed a supply-chain breach on April 15, 2021, and has now begun notifying customers. The breach went undiscovered for 2 months, and leveraged the Codecov Bash Uploader scripts used by a large number of projects.
Analyst Comment: In light of the increasing frequency and sophistication of supply chain attacks, companies should carefully audit, examine, and include in their threat modelling means of mitigating and detecting third party compromises. A resilient and tested backup and restore policy is an important part of the overall security strategy.
Tags: North America, Codecov, supply chain
(published: April 30, 2021)
The security research group for Azure Defender for IoT, dubbed Section 52, has found a batch of bad memory allocation operations that could lead to malicious code execution. The use of these functions gets problematic when passed external input that can cause an integer overflow or wraparound as values to the functions. The list of affected products in the advisory includes devices from Google Cloud, Arm, Amazon, Red Hat, Texas Instruments and Samsung Tizen.
Analyst Comment: IoT devices within an organization should be carefully considered, and where allowed need to be properly managed and segmented from sensitive networks. Considering the prevalence of IoT devices that employees doing remote work are exposed to, increased user education and endpoint monitoring is an important part of the overall security strategy.
Tags: Bad Memory Allocation, Malicious code execution
|
Tags: WeSteal, WeControl, Cryptocurrency
| |
(published: April 28, 2021)
The backdoor, dubbed RotaJakiro by researchers at Qihoo 360's Network Security Research Lab, remains undetected by VirusTotal's anti-malware engines. It is designed to operate as stealthy as possible, encrypting its communication channels using ZLIB compression and AES, XOR, ROTATE encryption. It also does its best to block malware analysts from dissecting it. RotaJakiro shares multiple functional similarities with the Torii IoT botnet first spotted in 2018.
Analyst Comment: Defense-in-depth (layering of security mechanisms, redundancy, fail-safe defense processes) is the best way to protect against the constantly evolving threat landscape, including a focus on both network and host-based security. Prevention and detection capabilities should also be in place, as well as patching and backup policies.
Tags: Torii, RotaJakiro backdoor,
Tags: DKIM, Net, Cobalt Strike, Pings, CVE-2019-0604,
|
(published: April 27, 2021)
The Babuk gang of threat actors claims to have stolen more than 250 gigabytes of data from the Washington D.C. Metropolitan Police Department (MPD) on Monday, including police reports, internal memos, and arrested people's mug shots and personal details. According to Vice, the attackers published the claim and the data on the official Babuk site. An MPD spokesperson acknowledged in an email sent to Threatpost Tuesday morning that the department's systems had been breached and that it had contacted the FBI. "We are aware of unauthorized access on our server," the spokesperson said.
Analyst Comment: EDR solutions can help tracking suspicious command line arguments and process creations to potentially detect such attacks. Customers should use backup solutions to be able recover encrypted files, as well as a well defined defense in depth strategy.
MITRE ATT&CK: [MITRE ATT&CK] Data Encrypted for Impact - T1486
Tags: Babuk, ThreatConnect, Government, Healthcare, Military
SOCIAL SHARE CARD GENERATOR