The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: APT, Cyberespionage, Phishing, Ransomware, Sideloading, and Ukraine. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.

Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.
Trending Cyber News and Threat Intelligence
Tags: CVE-2022-1388, F5, Vulnerability, Remote code execution, Missing authentication
|
Tags: Android, Jocker, MobOk, Triada, Vesub, GriftHorse, Trojan, Subscription fraud, Subscription Trojan, Russia, target-country:RU, Middle East, Saudi Arabia, target-country:SA, Egypt, target-country:EG, Thailand, target-country:TH
| | |
(published: May 3, 2022)
Google researchers describe five advanced groups especially active in Eastern Europe in regard to the military conflict between Russia and Ukraine. Three Russian groups: Fancy Bear (APT28) targets Ukraine with phishing attachments delivering a new information stealer written in .Net. Another group, Turla, attributed to Russia’s Federal Security Services (FSB), targets defense and cybersecurity organizations in Baltic states with phishing links dropping a malicious DOCX that would download a malicious PNG file. GoldRiver (Callisto) group abuses Google and Microsoft services in their credential-stealing phishing attempts with targets including government and defense officials, journalists, NGOs and think tanks, and politicians. Belarus-sponsored group Ghostwriter spoofed Google to target Ukraine and Facebook to target Lithuania. Curious George, a group attributed to China’s The People's Liberation Army Strategic Support Force (PLASSF), is targeting government, logistics, manufacturing, and military organizations in Central Asia, Russia and Ukraine, including Russia’s Ministry of Foreign Affairs.
Analyst Comment: Defense-in-depth (layering of security mechanisms, redundancy, fail-safe defense processes) is the best way to ensure safety from advanced persistent threats (APTs), including a focus on both network and host-based security. Prevention and detection capabilities should also be in place. Many advanced attacks start with basic techniques such as unwarranted email with malicious attachment that requires the user interaction. It is important to teach your users basic online hygiene and phishing awareness.
MITRE ATT&CK: |
Tags: Ukraine, target-country:UA, Russia, source-country:RU, Belarus, source-country:BY, China, source-country:CN, Lithuania, target-country:LT, APT28, Fancy Bear, Turla, FSB, GoldRiver, Callisto, Ghostwriter, Curious George, PLA SSF, Phishing, Windows, Ukraine-Russia Conflict 2022
| | |
Tags: Moshen Dragon, Gunters, PlugX, Shadowpad, China, source-country:CN, Central Asia, Windows, DLL search order hijacking, Sideloading triad, Impacket, wmiexec, SecureFilter
| | | | | | | | | |
(published: May 1, 2022)
The REvil (Sodinokibi, Pinchy Spider) ransomware group resumed its operations. In October 2021, the group shut down after a law enforcement operation hijacked their Tor servers, and Russian police arrested some of its members. At the end of April 2022, the group became active on its ransom websites listing new and old victims, and on April 29, 2022, researchers detected a new sample of their encryptor compiled from its source code that includes new changes. The new REvil sample is highly targeted: it includes a new configuration field, 'accs,' with credentials for the specific victim (specified accounts and Windows domains), preventing encryption on devices outside of the intended target.
Analyst Comment: It is crucial that your company ensure that servers are always running the most current software version. Your company should have policies in place in regards to the proper configurations needed for your servers in order to conduct your business needs safely. Additionally, always practice defense-in-depth (do not rely on single security mechanisms - security measures should be layered, redundant, and failsafe). Furthermore, a business continuity plan should be in place in the case of a ransomware infection.
MITRE ATT&CK:
Tags: Pinchy Spider, Sodinokibi, REvil, Ransomware, Windows, Russia, source-country:RU
| | | | | | | | | | | | | | | | | | | | | | | | | | | |
The Advanced Persistent Threat (APT) group “APT28” is believed to be a Russian-sponsored group that has been active since at least 2007. The group displays high levels of sophistication in the multiple campaigns that they have been attributed to, and various malware and tools used to conduct the operations align with the strategic interests of the Russian government. The group is believed to operate under the Main Intelligence Directorate (GRU), the foreign intelligence agency of the Russian armed forces.
Pinchy Spider is a Russian-speaking threat group that run a Ransomware-as-a-Service (RaaS). The threat group has been active since January 2018 when they announced the GandCrab RaaS on the “exploit[.]in” forum. The GandCrab RaaS was discontinued in June 2019 in favour of the newer RaaS Sodinokibi/REvil.
CVE-2022-1388
On F5 BIG-IP 16.1.x versions prior to 16.1.2.2, 15.1.x versions prior to 15.1.5.1, 14.1.x versions prior to 14.1.4.6, 13.1.x versions prior to 13.1.5, and all 12.1.x and 11.6.x versions, undisclosed requests may bypass iControl REST authentication. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Community-Analysen & Experten-Meinungen 0
Verwandte Story-Cluster & Quellen (Vektor-KI)
Ähnliche Beiträge
Auch interessante Nachrichten Anomali Cyber Watch: Moshen Dragon Abused Anti-Virus Software, Raspberry Robin Worm Jumps from USB, UNC3524 Uses Internet-of-Things to Steal Emails, and More
Thematisch verwandte Begriffe: Anomali, Cyber, Watch, Moshen · 6 Treffer
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
The Gentlemen Ransomware Analysis: Go Obfuscated
Detect Credential Access with Elastic Security
Detecting and responding to Dirty Pipe with Elastic
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
Beiträge werden geladen ...
Videos werden geladen ...
SOCIAL SHARE CARD GENERATOR