The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: APT, China, Fraud, Inbound connectors, Phishing, Ransomware, Russia, and Ukraine. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.

Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.
Trending Cyber News and Threat Intelligence
(published: September 22, 2022)
Microsoft researchers described a relatively stealthy abuse of a compromised Exchange server used to send fraud spam emails. After using valid credentials to get access, the actor deployed a malicious OAuth application, gave it admin privileges and used it to change Exchange settings. The first modification created a new inbound connector allowing mails from certain actor IPs to flow through the victim’s Exchange server and look like they originated from the compromised Exchange domain. Second, 12 new transport rules were set to delete certain anti-spam email headers.
Analyst Comment: If you manage an Exchange server, strengthen account credentials and enable multifactor authentication. Investigate if receiving alerts regarding suspicious email sending and removal of antispam header.
MITRE ATT&CK:
Tags: Exchange, Microsoft, PowerShell, Inbound connector, Transport rule, Fraud, Spam
| |
(published: September 22, 2022)
From 2015 to August 2022, Check Point researchers observed China-affiliated group Scarlet Mimic using more than 20 different variations of Android malware targeting the Uyghur community. This malware, dubbed MobileOrder, can steal data, record audio, track the victim's location, and send messages on behalf of the infected user. MobileOrder is being spread outside of the official Google Store with Uyghur and Muslim-related baits masquerading as PDF, photo or audio files. This threat group often hides their real command-and-control (C2) infrastructure behind dead drop resolvers: MobileOrder starts by querying different posts on the Chinese Sina blog platform to find a matching pattern and an encoded second-level C2.
Analyst Comment: It is important to only use the Google Play Store to obtain your software (for Android users), and avoid installing software from unverified sources because it is easier for malicious applications to get into third-party stores. Applications that ask for additional permissions outside of their normal functionality should be treated with suspicion, and normal functionality for the applications should be reviewed carefully prior to installation. Antivirus applications, if available, should be deployed on devices, particularly those that could contain sensitive information.
Tags: mitre-group:Scarlet Mimic, ScarletMimic, Uyghurs, detection:MobileOrder, Dead drop resolver, China, source-country:CN
SOCIAL SHARE CARD GENERATOR