🕵️ SicherheitslückenWhat continuous operational resilience looks like under DORA(09.09.2026 um 17:53 Uhr)
🔧 AI Nachrichten OpenAI seeks tougher AI rules. CIOs may feel the ripple effects(10.09.2026 um 12:11 Uhr)
🔧 AI Nachrichten Mistral valued at €21bn after €3bn Series D funding round(08.09.2026 um 10:19 Uhr)
🪟 Windows TippsWindows XP's Cursor Indicator Is Getting a Windows 11 Refresh(25.08.2026 um 13:00 Uhr)
🕵️ SicherheitslückenWhat continuous operational resilience looks like under DORA(09.09.2026 um 17:53 Uhr)
🔧 AI Nachrichten OpenAI seeks tougher AI rules. CIOs may feel the ripple effects(10.09.2026 um 12:11 Uhr)
🔧 AI Nachrichten Mistral valued at €21bn after €3bn Series D funding round(08.09.2026 um 10:19 Uhr)
🪟 Windows TippsWindows XP's Cursor Indicator Is Getting a Windows 11 Refresh(25.08.2026 um 13:00 Uhr)

📰 IT Security Nachrichten 🕛 vor 3 Jahren 8 Min Lesezeit SECURITY-FEED
0

Anomali Cyber Watch: Sandworm Uses HTML Smuggling and Commodity RATs, BlackCat Ransomware Adds New Features, Domain Shadowing Is Rarely Detected, and More

↗ Quelle (anomali.com)
🗣️ Stimme:
📑 Inhaltsübersicht

The various threat intelligence stories in this iteration of the Anomali Cyber Watch discuss the following topics: APT, China, Fraud, Inbound connectors, Phishing, Ransomware, Russia, and Ukraine. The IOCs related to these stories are attached to Anomali Cyber Watch and can be used to check your logs for potential malicious activity.




Figure 1 - IOC Summary Charts. These charts summarize the IOCs attached to this magazine and provide a glimpse of the threats discussed.



Trending Cyber News and Threat Intelligence






(published: September 22, 2022)



Microsoft researchers described a relatively stealthy abuse of a compromised Exchange server used to send fraud spam emails. After using valid credentials to get access, the actor deployed a malicious OAuth application, gave it admin privileges and used it to change Exchange settings. The first modification created a new inbound connector allowing mails from certain actor IPs to flow through the victim’s Exchange server and look like they originated from the compromised Exchange domain. Second, 12 new transport rules were set to delete certain anti-spam email headers.
Analyst Comment: If you manage an Exchange server, strengthen account credentials and enable multifactor authentication. Investigate if receiving alerts regarding suspicious email sending and removal of antispam header.
MITRE ATT&CK:
Tags: Exchange, Microsoft, PowerShell, Inbound connector, Transport rule, Fraud, Spam





| |



(published: September 22, 2022)



From 2015 to August 2022, Check Point researchers observed China-affiliated group Scarlet Mimic using more than 20 different variations of Android malware targeting the Uyghur community. This malware, dubbed MobileOrder, can steal data, record audio, track the victim's location, and send messages on behalf of the infected user. MobileOrder is being spread outside of the official Google Store with Uyghur and Muslim-related baits masquerading as PDF, photo or audio files. This threat group often hides their real command-and-control (C2) infrastructure behind dead drop resolvers: MobileOrder starts by querying different posts on the Chinese Sina blog platform to find a matching pattern and an encoded second-level C2.
Analyst Comment: It is important to only use the Google Play Store to obtain your software (for Android users), and avoid installing software from unverified sources because it is easier for malicious applications to get into third-party stores. Applications that ask for additional permissions outside of their normal functionality should be treated with suspicion, and normal functionality for the applications should be reviewed carefully prior to installation. Antivirus applications, if available, should be deployed on devices, particularly those that could contain sensitive information.
Tags: mitre-group:Scarlet Mimic, ScarletMimic, Uyghurs, detection:MobileOrder, Dead drop resolver, China, source-country:CN






Tags: Domain shadowing, DNS hijacking, Phishing, Australia, target-country:AU, USA, target-country:US, Phishing, Microsoft





|
Tags: actor:BlackCat, detection:BlackCat, detection:ALPHV, detection:Noberus, malware-type:Ransomware, Darkside, BlackMatter, Ransomware-as-a-service, detection:Exmatter, malware-type:Data exfiltration tool, detection:Infostealer.Eamfo, malware-type:Infostealer, detection:GMER, malware-type:Rootkit scanner, Veeam, Rust, Windows, EXSI, Debian, Linux, ReadyNAS, Synology





| | | | | | [MITRE ATT&CK] Scheduled Task - T1053
Tags: mitre-group:Sandworm Team, Russia, source-country:RU, GRU, Foreign military intelligence service, APT, Cyberesionage, Ukraine, target-country:UA, HTML smuggling, file-type:ISO, detection:DarkCrystal RAT, detection:Colibri Loader, detection:Warzone RAT, malware-type:RAT, Windows, target-industry:Telecommunications NAICS 517


Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf anomali.com.
↗ Original-Artikel auf anomali.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
Sam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for access
1 Quelle
Swiss government explores replacing Microsoft 365 with open-source software
1 Quelle
What continuous operational resilience looks like under DORA
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Anomali Cyber Watch: Sandworm Uses HTML Smuggling and Commodity RATs, BlackCat Ransomware Adds New Features, Domain Shadowing Is Rarely Detected, and More

Thematisch verwandte Begriffe: Anomali, Cyber, Watch, Sandworm · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...