home.social

#charmingkitten — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #charmingkitten, aggregated by home.social.

fetched live
  1. 0day Browser RCE von Charming Kitten / APT35 oder schlechte Berichterstattung?

    Angeblich wurde auf einen Link geklickt und dadurch™ der Rechner infiziert.

    archive.is/QkX57

    #Berlin #Badenberg #CharmingKitten #apt35

  2. 0day Browser RCE von Charming Kitten / APT35 oder schlechte Berichterstattung?

    Angeblich wurde auf einen Link geklickt und dadurch™ der Rechner infiziert.

    archive.is/QkX57

    #Berlin #Badenberg #CharmingKitten #apt35

  3. Our team just released a report on #CharmingKitten/#APT35: harfanglab.io/insidethelab/cyc

    We discovered a new malware family called Cyclops, written in Go. It launches a local web server which exposes a REST API used to control the malware. The port is forwarded to the C2 via SSH.

    We believe Cyclops was developed as a replacement for the (burnt) BellaCiao implant.
    There seem to be very few samples in existence and we'd be curious to know if anyone else can find some. Suspected area of activity is the Middle-East since December 2023.

    Reverse-engineering was a challenge due to the malware expecting mashalled objects from the network. How do you figure out their expected structure with Golang when there's no constructor? If there's any interest, I may write a separate blog post or thread on the subject.

    IOCs and more in the full post. Enjoy!

  4. Our team just released a report on #CharmingKitten/#APT35: harfanglab.io/insidethelab/cyc

    We discovered a new malware family called Cyclops, written in Go. It launches a local web server which exposes a REST API used to control the malware. The port is forwarded to the C2 via SSH.

    We believe Cyclops was developed as a replacement for the (burnt) BellaCiao implant.
    There seem to be very few samples in existence and we'd be curious to know if anyone else can find some. Suspected area of activity is the Middle-East since December 2023.

    Reverse-engineering was a challenge due to the malware expecting mashalled objects from the network. How do you figure out their expected structure with Golang when there's no constructor? If there's any interest, I may write a separate blog post or thread on the subject.

    IOCs and more in the full post. Enjoy!

  5. Happy Thursday everyone!

    The Volexity team share their findings from a recent incident that involved the APT known as #CharmingKitten (aka #CharmingCypress) and what lengths this group went to make their attack look as convincing as possible. The Volexity team also shared technical details about the malware that was used, specific commands seen, and TTPs used. Enjoy and Happy Hunting!

    CharmingCypress: Innovating Persistence
    volexity.com/blog/2024/02/13/c

    As always, I don't want to leave you empty handed! So take this Community Hunt Package from Cyborg Security to help you identify discovery behavior from adversaries!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    volexity.com/blog/2024/02/13/c

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #huntoftheday #gethunting

  6. Happy Thursday everyone!

    The Volexity team share their findings from a recent incident that involved the APT known as #CharmingKitten (aka #CharmingCypress) and what lengths this group went to make their attack look as convincing as possible. The Volexity team also shared technical details about the malware that was used, specific commands seen, and TTPs used. Enjoy and Happy Hunting!

    CharmingCypress: Innovating Persistence
    volexity.com/blog/2024/02/13/c

    As always, I don't want to leave you empty handed! So take this Community Hunt Package from Cyborg Security to help you identify discovery behavior from adversaries!

    Excessive Windows Discovery and Execution Processes - Potential Malware Installation
    volexity.com/blog/2024/02/13/c

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting #readoftheday #huntoftheday #gethunting

  7. "🌪️ Mint Sandstorm: Sophisticated Phishing Campaign Unleashed by APT35 🚨"

    Microsoft's security blog reveals an intricate phishing campaign, "Mint Sandstorm," by the subgroup PHOSPHORUS (also known as APT35 and Charming Kitten), linked to Iran's Islamic Revolutionary Guard Corps. This campaign targets individuals in universities and research organizations involved in Middle Eastern affairs across various countries. Unique tactics include bespoke phishing lures, using compromised legitimate email accounts, and deploying custom backdoors like MediaPl and MischiefTut. These tools allow for encrypted communications, reconnaissance, and persistence in target environments. Microsoft suggests using Attack Simulator in Defender for Office 365, enabling SmartScreen on browsers, and activating cloud-delivered protection to mitigate risks.

    Microsoft's security blog

    Tags: #CyberSecurity #Phishing #APT35 #CharmingKitten #MintSandstorm #MicrosoftSecurity #InfoSec #ThreatIntelligence

    Mitre - APT35

  8. "🌪️ Mint Sandstorm: Sophisticated Phishing Campaign Unleashed by APT35 🚨"

    Microsoft's security blog reveals an intricate phishing campaign, "Mint Sandstorm," by the subgroup PHOSPHORUS (also known as APT35 and Charming Kitten), linked to Iran's Islamic Revolutionary Guard Corps. This campaign targets individuals in universities and research organizations involved in Middle Eastern affairs across various countries. Unique tactics include bespoke phishing lures, using compromised legitimate email accounts, and deploying custom backdoors like MediaPl and MischiefTut. These tools allow for encrypted communications, reconnaissance, and persistence in target environments. Microsoft suggests using Attack Simulator in Defender for Office 365, enabling SmartScreen on browsers, and activating cloud-delivered protection to mitigate risks.

    Microsoft's security blog

    Tags: #CyberSecurity #Phishing #APT35 #CharmingKitten #MintSandstorm #MicrosoftSecurity #InfoSec #ThreatIntelligence

    Mitre - APT35

  9. "🔍 Charming Kitten Strikes with 'Sponsor' Malware! 🕵️"
    The notorious APT group 'Charming Kitten' (also known as Phosphorus, TA453, APT35/42) has unveiled a new backdoor malware named 'Sponsor'. This malware has already targeted 34 global companies. Stay vigilant! 🌍🔥

    A nation-state threat actor, known by various aliases including 'Charming Kitten,' 'Phosphorus,' 'TA453,' and 'APT35/42,' has recently executed a sophisticated cyber campaign using a previously undisclosed backdoor malware named 'Sponsor.' ESET researchers have identified this campaign, which targeted 34 companies worldwide between March 2021 and June 2022, encompassing government and healthcare organizations, financial services, engineering, manufacturing, technology, law, telecommunications, and more. The primary targets were located in Israel, Brazil, and the United Arab Emirates.

    Key Findings:

    1. Concealed Configuration Files: The 'Sponsor' backdoor is notable for its ability to hide configuration files on the victim's system, making it stealthy and difficult to detect. These files are deployed discreetly through malicious batch scripts.

    2. Initial Access via Microsoft Exchange Vulnerability: The threat actor primarily exploited the CVE-2021-26855 vulnerability in Microsoft Exchange to gain initial access to targeted networks.

    3. Tool Usage: Charming Kitten utilized various open-source tools for data exfiltration, system monitoring, network infiltration, and maintaining access to compromised computers.

    4. Payload Deployment: Prior to deploying the 'Sponsor' backdoor, the attackers dropped batch files on specific file paths, creating seemingly innocuous files named config.txt, node.txt, and error.txt to avoid arousing suspicion.

    5. Functionality of 'Sponsor' Backdoor: 'Sponsor' is a C++ backdoor that establishes a service upon launch based on instructions from the configuration file. The configuration file contains encrypted command and control (C2) server addresses, C2 contacting intervals, and the RC4 decryption key. The malware collects system information and sends it to the C2, receiving a unique node ID in return. It then enters a loop to receive and execute commands from the C2, including process ID reporting, command execution, file retrieval and execution, and more.

    6. Disguised Second Version: ESET identified a second version of 'Sponsor' with code optimizations and camouflage features, making it appear as an updater tool.

    7. Indicators of Compromise (IOCs): Although the IP addresses used in this campaign are no longer active, ESET has shared comprehensive IOCs to assist in defending against potential future threats that may reuse the tools or infrastructure deployed by Charming Kitten.

    Organizations worldwide, particularly those in the targeted sectors and regions, should remain vigilant and ensure their cybersecurity defenses are up-to-date and capable of detecting advanced threats like 'Sponsor' used by nation-state actors like Charming Kitten. Regular patching and network monitoring are essential to mitigate such cyber risks.

    Source: BleepingComputer.com
    Mitre - Charming Kitten
    Tags: #APT #CharmingKitten #SponsorMalware #CyberAttack

  10. "🔍 Charming Kitten Strikes with 'Sponsor' Malware! 🕵️"
    The notorious APT group 'Charming Kitten' (also known as Phosphorus, TA453, APT35/42) has unveiled a new backdoor malware named 'Sponsor'. This malware has already targeted 34 global companies. Stay vigilant! 🌍🔥

    A nation-state threat actor, known by various aliases including 'Charming Kitten,' 'Phosphorus,' 'TA453,' and 'APT35/42,' has recently executed a sophisticated cyber campaign using a previously undisclosed backdoor malware named 'Sponsor.' ESET researchers have identified this campaign, which targeted 34 companies worldwide between March 2021 and June 2022, encompassing government and healthcare organizations, financial services, engineering, manufacturing, technology, law, telecommunications, and more. The primary targets were located in Israel, Brazil, and the United Arab Emirates.

    Key Findings:

    1. Concealed Configuration Files: The 'Sponsor' backdoor is notable for its ability to hide configuration files on the victim's system, making it stealthy and difficult to detect. These files are deployed discreetly through malicious batch scripts.

    2. Initial Access via Microsoft Exchange Vulnerability: The threat actor primarily exploited the CVE-2021-26855 vulnerability in Microsoft Exchange to gain initial access to targeted networks.

    3. Tool Usage: Charming Kitten utilized various open-source tools for data exfiltration, system monitoring, network infiltration, and maintaining access to compromised computers.

    4. Payload Deployment: Prior to deploying the 'Sponsor' backdoor, the attackers dropped batch files on specific file paths, creating seemingly innocuous files named config.txt, node.txt, and error.txt to avoid arousing suspicion.

    5. Functionality of 'Sponsor' Backdoor: 'Sponsor' is a C++ backdoor that establishes a service upon launch based on instructions from the configuration file. The configuration file contains encrypted command and control (C2) server addresses, C2 contacting intervals, and the RC4 decryption key. The malware collects system information and sends it to the C2, receiving a unique node ID in return. It then enters a loop to receive and execute commands from the C2, including process ID reporting, command execution, file retrieval and execution, and more.

    6. Disguised Second Version: ESET identified a second version of 'Sponsor' with code optimizations and camouflage features, making it appear as an updater tool.

    7. Indicators of Compromise (IOCs): Although the IP addresses used in this campaign are no longer active, ESET has shared comprehensive IOCs to assist in defending against potential future threats that may reuse the tools or infrastructure deployed by Charming Kitten.

    Organizations worldwide, particularly those in the targeted sectors and regions, should remain vigilant and ensure their cybersecurity defenses are up-to-date and capable of detecting advanced threats like 'Sponsor' used by nation-state actors like Charming Kitten. Regular patching and network monitoring are essential to mitigate such cyber risks.

    Source: BleepingComputer.com
    Mitre - Charming Kitten
    Tags: #APT #CharmingKitten #SponsorMalware #CyberAttack

  11. Nach Erkenntnissen des Bundesamtes für #Verfassungsschutz (#BfV) ist seit Ende 2022 von konkreten Ausspähversuchen der #APT-Gruppe #CharmingKitten gegen iranische Personen und Organisationen in Deutschland auszugehen.

    Insbesondere warnt das BfV im "Cyber-Brief Nr. 01/2023" vom 10. August 23 vor #Phishing-Angriffen gegen #Dissidenten-Organisationen und Einzelpersonen – wie Juristen, Journalisten oder #Menschenrechtsaktivisten – innerhalb und außerhalb des #Iran.

    verfassungsschutz.de/SharedDoc

  12. Good day everyone! I hope everyone is enjoying their Wednesday!

    In a recent report by Bitdefender Labs, they took a deep-dive into the threat group #CharmingKitten and their latest malware, #BellaCiao. It is a great read, but some main behaviors that I pulled from the report included:

    #DefenseEvasion:
    T1562.001 - Impair Defenses: Disable or Modify Tools
    Charming Kitten used powershell to disable real-time monitoring on the machine to avoid detection.

    #Persistence:
    T1053.005 - Scheduled Task/Job: Scheduled Task
    They also created scheduled tasks to run on start and used the technique of masquerading their process names to blend in.

    #Execution:
    The Bitdefender team provided the locations that the executables were written to.

    You should go and check out this #readoftheday, it contains great technical details that you can use to improve your threat hunting skill.
    Enjoy and Happy Hunting!

    #CyberSecurity #ITSecurity #InfoSec #BlueTeam #ThreatIntel #ThreatHunting #ThreatDetection #HappyHunting

  13. CW: Thoughts on new #TA453/CharmingKitten Blog

    What happens when a TA’s consistent TTPs change? Today we (#CristaNeedsAMastadon and I) released a blog detailing examples of weird and wacky techniques and targeting from #TA453.

    proofpoint.com/us/blog/threat-

    With the current situation (#MahsaAmini) in Iran, I think it’s important to note that the Government of Iran (GOI) has had an intelligence interest in Gender Studies and Women’s Rights experts since AT LEAST 2021.

    If we want to see how high they rank in interest, we just need to look at how they likely deployed the same malware (GhostEcho/CharmPower) against some of those researchers and activists that they did against Foreign Government embassy personnel.

    When we pivot to look at Samantha, you see a persona that’s targeted MENA energy, a US based academic that’s an Iranian HVT, and senior US & European government officials, all using confrontational lures not typically seen from TA453.

    Is this an actor gone rogue, willing to do anything to successfully phish at any cost? Maybe. Is it the intern or conscriptee just trying to meet a quota?

    We don’t know but it’s definitely interesting to track.

    We talked about confrontational conversational phishing, but nothing really says confrontational like compromising multiple email accounts just to deliver a JPEG of intimidation to a target. That, along with the compromise of a close affiliate of one of the former officials targeted in the IRGC Murder For Hire plot, leads us to believe that a subset of TA453 activity is more aggressive than we’ve seen historically.

    Please go read it! Let us know what you think. #APT #Iran #IRGC #APT42 #Phosphorus #charmingKitten

  14. When talking to people, one of the biggest questions i get is what does #TA453/ #CharmingKitten do once they send their phishing links.

    This is great work from @abirghattas!

    hrw.org/news/2022/12/05/iran-s #Iran #APT

  15. Most controversial opinions…

    Avocados (and Guac) are gross.
    Coffee is overrrated.
    #APT35 is not #CharmingKitten.

  16. #introduction
    I’m Josh/Yoshi.
    I work as a Senior Threat Researcher hunting for state aligned cyber threat actors (aka APTs).
    I focus on threats suspected of originating in the Middle East & North Africa Region, primarily Iranian aligned threats like #TA453 (#CharmingKitten), #TA450 (#Muddywater), and #TA456 (#Tortoiseshell).

    Before this, I did #threatIntel work in healthcare. Before that, I worked for the #FBI.

    I live in Chicago(land) with 3 kids, 2 dogs and my beautiful wife.

    I’m a huge fan of #StarWars and the #LAChargers

    This seems like a pretty cool place, excited to see how it grows.