The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: Chromeloader, Goodwill, MageCart, Saitama, Turla and Yashma. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.

Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.
Trending Cyber News and Threat Intelligence
|
Tags: MageCart, skimmer, JavaScript Magento, PsiGate, AJAX
|
(published: May 25, 2022)
A new ransomware named Cheers (Cheerscrypt) has been targeting vulnerable VMware ESXi servers since March 2022. It uses SOSEMANUK stream cipher to encrypt files and ECDH to generate the SOSEMANUK key. Cheers targets its victims with double extortion for decryption and for keeping the stolen data private.
Analyst Comment: Server virtualization systems are heavily targeted and require protection and disaster recovery planning. Backup important information, and keep your systems updated and securely configured.
MITRE ATT&CK:
Tags: Cheerscrypt, Cheers, Ransomware, Double extortion, VMware ESXi, Linux
| |
Tags: ChromeLoader, Browser hijacker, Loader, PowerShell, Chrome, Windows, Safari, MacOS
|
Tags: BPFDoor, Telecommunications, Logistics, DecisiveArchitect, Red Menshen, JustForFun, CVE-2019-3010, China, Windows, ldapdomaindump, Impacket, Solaris, Linux
|
Tags: Yashma, Onyx, Ryuk, ransomware, Chaos, wiper
| | | |
Tags: APT, Russia, target-country:RU, Cyberespionage, Spearphishing, RAT, Typosquatting, Deep Panda, Windows, VBS, DLL, OLLVM, Control flow flattening, Blake2b-256, WolfSSL, Rostec, Government, Defense, Military, China, Ukraine
|
(published: May 23, 2022)
Sekoia researchers expanded on indicators shared by Google and discovered a new campaign by Russia-sponsored group Turla. Threat actors use typosquatted domains to host documents that are used for reconnaissance. Embedded external PNG file is being requested from an attacker-controlled server via the HTTP protocol. It allows the attackers to collect the victim's IP address and the Word application version and type. Phishing documents were themed around topics of war and sanctions on Russia and targeting included Austrian Federal Economic Chamber, Baltic Defence College, and NATO Joint Advanced Distributed Learning.
Analyst Comment: It’s important to keep a watchful eye on suspicious domain registration activity related to your brand and companies from your supply chain. Anomali Targeted Threat Monitoring service can help you detect and block such suspicious domain registrations.
MITRE ATT&CK: [MITRE ATT&CK] Phishing - T1566
Tags: Turla, Reconnaissance, Phishing, Typosquatting, Russia, source-country:RU, FSB
SOCIAL SHARE CARD GENERATOR