The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: APT35, CrescentImp, Follina, Gallium, Phosphorous, and Sandworm. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.

Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.
Trending Cyber News and Threat Intelligence
|
(published: June 15, 2022)
F5 Labs researchers describe a novel Android trojan, dubbed MaliBot. Based on re-written SOVA malware code, MaliBot is maintaining its Background Service by setting itself as a launcher. Its code has some unused evasion portions for emulation environment detection and setting the malware as a hidden app. MaliBot spreads via smishing, takes control of the device and monetizes using overlays for certain Italian and Spanish banks, stealing cryptocurrency, and sometimes sending Premium SMS to paid services.
Analyst Comment: Users should be wary of following links in unexpected SMS messages. Try to avoid downloading apps from third-party websites. Be cautious with enabling accessibility options.
MITRE ATT&CK:
Tags: MaliBot, Android, MFA bypass, SMS theft, Premium SMS, Smishing, Binance, Trust wallet, VNC, SOVA, Sality, Cryptocurrency, Financial, Italy, target-country:IT, Spain, target-country:ES
(published: June 15, 2022)
Ukraine's Computer Emergency Response Team (CERT-UA) reported a new campaign by Russia-sponsored group Sandworm that targeted 500 Ukrainians across the mass media sector. The observed malicious attachment was exploiting the Follina (CVE-2022-30190) vulnerability, a remote code execution (RCE) vulnerability in the Microsoft Support Diagnostic Tool (MSDT) that went unpatched until the June 14, 2022 cumulative update. Opening of the attached DOCX file leads to loading of the HTML-file and executing JavaScript-code, which, in turn, will download and execute the final executable: CrescentImp. The CrescentImp trojan has capabilities to steal sensitive information and download additional malware.
Analyst Comment: Install June 2022 cumulative Windows Updates to address the Follina zero-day vulnerability. Educate your users on the handling of suspected spearphishing emails.
MITRE ATT&CK:
Tags: Follina, CrescentImp, Windows, CVE-2022-30190, UAC-0113, Sandworm, DOCX, HTML, JavaScript, Russia, source-country:RU, Ukraine, target-country:UA, Mass media
|
Tags: Charming Kitten, APT35, Phosphorous, Iran, source-country:IR, Israel, target-country:IL, USA, target-country:US, Spearphishing, Email chains, Yahoo, OneDrive, Google Drive, Validation.com
Tags: DDoS, HTTPS DDoS, TLS, Cloud, CSP
|
Tags: DragonForce Malaysia, OpsPatuk, OpsIndia, Hacktivism, India, target-country:IN, Malaysia, source-country:MY, DDoS, Defacement, Atlassian, Confluence, CVE-2022-26134, Slowloris, DDoSTool, DDoS-Ripper, Hammer
| | | |
Tags: Gallium, China, source-country:CN, APT, PingPull, ICMP, Raw TCP, RAT, Softcell, Soft Cell, Windows, Telecommunications, Government, Finance, Southeast Asia, Europe, Africa, Afghanistan, Australia, Belgium, Cambodia, Malaysia, Mozambique, Philippines, Russia, Vietnam
|
Tags: Syslogk, Kernel rootkit, Adore-Ng, Rekoobe, Magic packet, TinySHell, Linux
Observed Threats
Additional information regarding the threats discussed in this week's Weekly Threat Briefing can be found below:
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability. A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights.
Atlassian Confluence CVE-2022-26134
CVE-2022-26134 is a critical severity unauthenticated remote code execution (RCE) vulnerability.1 The vulnerability affects Confluence Server version 7.18.0 and all Confluence Data Center versions >= 7.4.0 (as of June 3d, 2022).2 It was exploited as a 0-day vulnerability by multiple threat groups likely based in China since the end of May 2022.
SOCIAL SHARE CARD GENERATOR