home.social

#emotet — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #emotet, aggregated by home.social.

fetched live
  1. JPCERT/CC、マルウェア「Emotet」のチェックツールの配布を終了 ~脆弱性あり、ただちに利用の停止を/オープンソースの「EmoCheck」
    forest.watch.impress.co.jp/doc

    #forest_watch_impress #Emotet #EmoCheck #セキュリティ #脆弱性 #Windows

  2. @thebuggers
    Nein, #Emotet hat mit "veraltet" nichts zu tun, sondern mit #Microsoft #Windows und höchstwahrscheinlich #Outlook. Ok, wenn du dieses Biotop "veraltet" nennen möchtest, bin ich dabei. pc-fluesterer.info/wordpress/2
    Die Tragik: Bei der erforderlichen Neueinrichtung der Systeme wurde natürlich nicht auf #FOSS gesetzt, sondern auf das "bewährte" 😂 alte. Die Lobby-Macht von M$ scheint weitgehend unüberwindlich. 😠

  3. @thebuggers
    Nein, #Emotet hat mit "veraltet" nichts zu tun, sondern mit #Microsoft #Windows und höchstwahrscheinlich #Outlook. Ok, wenn du dieses Biotop "veraltet" nennen möchtest, bin ich dabei. pc-fluesterer.info/wordpress/2
    Die Tragik: Bei der erforderlichen Neueinrichtung der Systeme wurde natürlich nicht auf #FOSS gesetzt, sondern auf das "bewährte" 😂 alte. Die Lobby-Macht von M$ scheint weitgehend unüberwindlich. 😠

  4. 🚨#IcedID, #Smokeloader, #SystemBC, #Pikabot and #Bumblebee botnets have been disrupted by Operation Endgame!! This is the largest operation EVER against botnets involved with ransomware, with gargantuan thanks to a coordinated effort led by international agencies 👏👏

    As with the #Qakbot and #Emotet takedowns, Spamhaus are again providing remediation support - those affected will be contacted from today with steps to take.

    👉 For more information, read our write-up here: spamhaus.org/resource-hub/malw

    #OperationENDGAME

  5. 🚨#IcedID, #Smokeloader, #SystemBC, #Pikabot and #Bumblebee botnets have been disrupted by Operation Endgame!! This is the largest operation EVER against botnets involved with ransomware, with gargantuan thanks to a coordinated effort led by international agencies 👏👏

    As with the #Qakbot and #Emotet takedowns, Spamhaus are again providing remediation support - those affected will be contacted from today with steps to take.

    👉 For more information, read our write-up here: spamhaus.org/resource-hub/malw

    #OperationENDGAME

  6. Introducing the newest major @tidalcyber TTP intelligence content roundup, the Initial Access & Malware Delivery Landscape matrix, now live in our free Community Edition platform: app.tidalcyber.com/share/43836

    The matrix covers 25 major & emerging #malware typically used to gain early footholds in victim environments, often leading to ingress of more impactful threats, especially #ransomware, #infostealers, cryptominers, & more. It includes many recognizable names (#QakBot, #IcedID, #Emotet, #Bumblebee, #Gootloader) plus several newer and less-discussed threats

    The matrix includes 13 custom Technique Sets for threats not currently tracked in the #mitreattack knowledge base. All technique references derive from a large volume of recent, public #threat reporting (click the labels in the ribbon at the top of the matrix to view relevant source URLs for each threat)

    An interactive link analysis visualization of connections among these threats, also derived from public reports, is also available here: onodo.org/visualizations/23506

    Community Edition matrices support easy identification of shared (and outlier) techniques among multiple threats, and quick & easy overlay or pivoting to defensive & offensive security capabilities relevant to your own #security stack. We’ll have a blog out soon reviewing our analysis of top & trending techniques common among these initial access threats

    Tidal’s #Adversary Intelligence team remains focused on providing up-to-date #TTPintelligence, especially around traditionally under-represented yet widely relevant threats like crimeware. Other popular matrices in this theme include our Ransomware & Data Extortion Landscape matrix (app.tidalcyber.com/share/9a0fd) and Major & Emerging Infostealers matrix (app.tidalcyber.com/share/ec62f), which each cover 20+ threats

    Financially motivated adversaries often display a rapid pace of #TTP evolution, and this is especially apparent for #initialaccess threats. Register for our webinar on May 31 dedicated to TTP evolution, its drivers, and discussion around what defenders can do to address it and its implications: hubs.la/Q01NC23k0

    #SharedWithTidal #threatinformeddefense #malware #infostealer #cryptominer #IAB #blueteam #detectionengineering #purpleteam #cyber

  7. URLhaus is operational for over 5 years, notifying hosting providers + network operators about malware hosted in their network 🪲 It's a shame that some hosting providers ignore abuse reports, spreading malware for over four years 🤯

    Here's our current 💩-list 👇

    AS38841 kbro 🇹🇼, spreading #hajime:
    🌐 urlhaus.abuse.ch/url/86646/

    AS23520 Columbus Networks 🇧🇸, spreading #hajime:
    🌐 urlhaus.abuse.ch/url/91891/

    AS29873 Newfold Digital 🇺🇸, spreading #FormBook:
    🌐 urlhaus.abuse.ch/url/117832/

    AS58955 Bangmod 🇹🇭, spreading #Emotet:
    🌐 urlhaus.abuse.ch/url/200073/

  8. 📢 Tax season brings tax-related scams - The latest malspam attack infects targeted devices with the nasty #Emotet malware.

    Learn more: hackread.com/irs-tax-forms-w-9

    #Security #Malware #IRS #Scam #Cybersecurity

  9. Dark Cat, Anubis and Keyhole are three variants of IcedID VNC backdoors that are activated during the final initial-access stages to initiate hands-on-keyboard activity. Nviso covers the modus operandi and includes screen recordings of the actors activity. Interesting to see how they interact with Explorer, Outlook and other applications.
    #CTI #ThreatIntel #IcedID #Backdoor #Emotet
    blog.nviso.eu/2023/03/20/icedi

  10. #Emotet #Ransomware klingelt wieder an der Türe - verwendet #OneNote Notizbücher zur Verbreitung, nachdem Makros in Word oder Excel sicherheitstechnisch verbrannt sind.

    borncity.com/blog/2023/03/20/e

  11. Ransomware: Emotet kehrt zurück – als OneNote-E-Mail-Anhang

    Die hochentwickelte Schadsoftware Emotet ist wieder aktiv. Sie findet in Form von bösartigen OneNote-Dateien ihren Weg in den E-Mail-Eingang potenzieller Opfer.

    heise.de/news/Ransomware-Emote

    #Cybercrime #Emotet #OfficeSuite #Security #Trojaner #news

  12. Get up to speed on the week's infosec news before another week in the trenches:

    opalsec.substack.com/p/soc-gou

    Last week's patch Tuesday had SmartScreen bypasses and the Ping of Death, but nothing could beat the #Outlook zero-click credential leak that #Microsoft patche-er, uh, wait, no not quite patched - turns out you can still abuse it locally to harvest NTLM credentials, yikes!

    Non-transitive trusts have one job - to enable cross-domain authentication between only the two domains that maintain it. Turns out, that's not the case - you can actually pivot between domains and forests, authenticating to Services well outside the intended scope of the trust. And Microsoft aren't going to fix it.

    #Emotet have realised in week two of their return that there's more to life than Macros, and have joined in the abuse of #OneNote files to deliver their lures.

    In the world of ransomware, #BianLian have opted to focus on exfil-and-extortion campaigns, after Avast released a pesky decryptor for their ransomware in January this year. #CISA have opened their books and shared a detailed profile on #LockBit 3.0's favoured TTPs and tooling that's worth a read.

    #Google TAG have ousted Microsoft taking the easy way out in their previous patch of a SmartScreen bypass, opting to issue a half-baked patch that the #Magniber ransomware crew quickly circumvented, enabling them to deliver over 100,000 malicous lures unencumbered by the now-patched security control.

    If you're running Adobe's ColdFusion, Aruba ClearPass, or SAP software - you're going to want to make sure you caught and patched these vulnerabilities that debuted last week.

    #Redteam members have a new and improved AD lab environment to play in, as well as new evasion techniques for remote shells and macros to add to the toolkit!

    Offensive Security have a gift for the #blueteam in the defensive Kali Purple distro, and we've caught a bunch of awesome write-ups to help in scaling Detection Engineering and mitigating common initial access vectors.

    Catch all this and much more in this week's newsletter:

    opalsec.substack.com/p/soc-gou

    #infosec #cyber #news #cybernews #infosec #infosecnews #informationsecurity #cybersecurity #hacking #security #technology #hacker #vulnerability #vulnerabilities #malware #ransomware #dfir #soc #threatintel #threatintelligence #patchtuesday #adobe #ColdFusion #Aruba #ClearPass #SAP #Kali