#redtail — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #redtail, aggregated by home.social.
-
The Industrialization of Botnets Automation and Scale as a New Threat Infrastructure
#RondoDox #RedTail #Androxgh0stBotnet
https://www.trendmicro.com/vinfo/us/security/news/threat-landscape/the-industrialization-of-botnets-automation-and-scale-as-a-new-threat-infrastructure -
The Industrialization of Botnets Automation and Scale as a New Threat Infrastructure
#RondoDox #RedTail #Androxgh0stBotnet
https://www.trendmicro.com/vinfo/us/security/news/threat-landscape/the-industrialization-of-botnets-automation-and-scale-as-a-new-threat-infrastructure -
Saw the Turner Classic Movies 2025 remembrance video again and just had to find the music used. Also the current ear worm and I think I may check out his band “Trampled By Turtles.”
#MusicOfMastodon
#DaveSimonett
#RedTailDecompression holding
Bought it like I sold it
You tell it like you told it way back when
Remember when
We turned it in
In the Western Wind And The Sunrise -
Saw the Turner Classic Movies 2025 remembrance video again and just had to find the music used. Also the current ear worm and I think I may check out his band “Trampled By Turtles.”
#MusicOfMastodon
#DaveSimonett
#RedTailDecompression holding
Bought it like I sold it
You tell it like you told it way back when
Remember when
We turned it in
In the Western Wind And The Sunrise -
Want in on the #UFC313 action? 🙋
Join us for the #UFC313 Official Viewing Party at #RedTail – located inside Resorts World Las Vegas
Book your table now: http://UFC.ac/3DkTosN
-
CVE-2021-41773 oraz CVE-2021-42013 kończące się kopaniem krypto przez RedTail ( https://nfsec.pl/ai/6597 ) #cryptominer #botnet #redtail #linux #security #twittermigration
-
CVE-2021-41773 oraz CVE-2021-42013 kończące się kopaniem krypto przez RedTail ( https://nfsec.pl/ai/6597 ) #cryptominer #botnet #redtail #linux #security #twittermigration
-
2024-11-24 (Sunday): I'm trying something new by spinning up some Linux VMs and infecting them using information I get from the scans hitting my web servers.
For example, I found the latest #Redtail bash script leading to #Linux #ELF #malware, this time from 45.202.35[.]190.
I've posted a #pcap of the infection traffic from a Linux host, the associated malware samples, and another pcap with #scans & #probes hitting one of my web servers at https://www.malware-traffic-analysis.net/2024/11/24/index.html
-
2024-11-24 (Sunday): I'm trying something new by spinning up some Linux VMs and infecting them using information I get from the scans hitting my web servers.
For example, I found the latest #Redtail bash script leading to #Linux #ELF #malware, this time from 45.202.35[.]190.
I've posted a #pcap of the infection traffic from a Linux host, the associated malware samples, and another pcap with #scans & #probes hitting one of my web servers at https://www.malware-traffic-analysis.net/2024/11/24/index.html
-
出前館、3日続いた障害の原因は「暗号資産マイニングマルウェア『#RedTail』感染」 - CNET Japan
https://japan.cnet.com/article/35225479/『サービスの再開にあたっては、万全を期すために作業を慎重に実施したため、サービスの再開が想定より遅れたという。なお、現時点では個人情報の流出の恐れはないとしている』
-
New(ish) #cryptominer alert!
The #RedTail cryptominer has a new variant that exploits the recent critical PAN-OS vuln CVE-2024-3400. You may be aware of RedTail from its Log4Shell days, now it's going after at least 6 known vulnerabilities including the PAN-OS, recent Ivanti Connect Secure vulns, and ThinkPHP.
The write-up goes into a lot more technical detail and provides IoCs and mitigations. Here are the highlights:
🔐 Attackers behind this are using private cryptomining pools. It costs a loooootttt of money and time to do this. It also helps obfuscation. This can tell us some things about who is behind this.
👨💻 The tactics observed here mirror tactics previously seen by the Lazarus group. This nation-state theory is supported by the private pools point, but we cannot say that for certain.
🌐 The malware delivery infrastructure relies on multiple unrelated servers hosted by various ✨ legitimate ✨ hosting companies. It is robust and hard to classify as malicious without deeper examination.
Full write up includes IoCs and mitigations:
https://www.akamai.com/blog/security-research/2024-redtail-cryptominer-pan-os-cve-exploitIncredible work Ryan Barnett Stiv Kupchik and Maxim Zavodchik. I have the coolest job in the world thanks to these folks and their awesome research.
-
New(ish) #cryptominer alert!
The #RedTail cryptominer has a new variant that exploits the recent critical PAN-OS vuln CVE-2024-3400. You may be aware of RedTail from its Log4Shell days, now it's going after at least 6 known vulnerabilities including the PAN-OS, recent Ivanti Connect Secure vulns, and ThinkPHP.
The write-up goes into a lot more technical detail and provides IoCs and mitigations. Here are the highlights:
🔐 Attackers behind this are using private cryptomining pools. It costs a loooootttt of money and time to do this. It also helps obfuscation. This can tell us some things about who is behind this.
👨💻 The tactics observed here mirror tactics previously seen by the Lazarus group. This nation-state theory is supported by the private pools point, but we cannot say that for certain.
🌐 The malware delivery infrastructure relies on multiple unrelated servers hosted by various ✨ legitimate ✨ hosting companies. It is robust and hard to classify as malicious without deeper examination.
Full write up includes IoCs and mitigations:
https://www.akamai.com/blog/security-research/2024-redtail-cryptominer-pan-os-cve-exploitIncredible work Ryan Barnett Stiv Kupchik and Maxim Zavodchik. I have the coolest job in the world thanks to these folks and their awesome research.