home.social

#sentinellabs — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sentinellabs, aggregated by home.social.

fetched live
  1. Fresh from #SentinelLABS: our story on how #dprk threat actors try to leverage threat intel platforms and leak their own secrets. 🕵️‍♂️🤦‍♂️
    s1.ai/nk-ops

  2. Fresh from #SentinelLABS: our story on how #dprk threat actors try to leverage threat intel platforms and leak their own secrets. 🕵️‍♂️🤦‍♂️
    s1.ai/nk-ops

  3. Fresh from #SentinelLABS: our story on how #dprk threat actors try to leverage threat intel platforms and leak their own secrets. 🕵️‍♂️🤦‍♂️
    s1.ai/nk-ops

  4. Fresh from #SentinelLABS: our story on how #dprk threat actors try to leverage threat intel platforms and leak their own secrets. 🕵️‍♂️🤦‍♂️
    s1.ai/nk-ops

  5. Fresh from #SentinelLABS: our story on how #dprk threat actors try to leverage threat intel platforms and leak their own secrets. 🕵️‍♂️🤦‍♂️
    s1.ai/nk-ops

  6. #SentinelLABS researcher #TomHegel writes about an extension of the long-running #Ghostwriter campaign targeting opposition activists in #Belarus as well as #Ukrainian military and government organizations with weaponized #Excel documents lures.

    🔗 sentinelone.com/labs/ghostwrit

  7. #SentinelLABS researcher #TomHegel writes about an extension of the long-running #Ghostwriter campaign targeting opposition activists in #Belarus as well as #Ukrainian military and government organizations with weaponized #Excel documents lures.

    🔗 sentinelone.com/labs/ghostwrit

  8. #SentinelLABS researcher #TomHegel writes about an extension of the long-running #Ghostwriter campaign targeting opposition activists in #Belarus as well as #Ukrainian military and government organizations with weaponized #Excel documents lures.

    🔗 sentinelone.com/labs/ghostwrit

  9. ha descubierto como BlueNoroff (subgrupo de hackers norcoreanos que pertenecen a Lazarus Group) ha lanzado la campaña 'Hidden Risk' dirigida a usuarios de

    mecambioamac.com/hackers-norco

  10. #SentinelLabs ha descubierto como BlueNoroff (subgrupo de hackers norcoreanos que pertenecen a Lazarus Group) ha lanzado la campaña 'Hidden Risk' dirigida a usuarios de #macOS

    #ciberseguridad #tech

    mecambioamac.com/hackers-norco

  11. #SentinelLabs ha descubierto como BlueNoroff (subgrupo de hackers norcoreanos que pertenecen a Lazarus Group) ha lanzado la campaña 'Hidden Risk' dirigida a usuarios de #macOS

    #ciberseguridad #tech

    mecambioamac.com/hackers-norco

  12. #SentinelLabs ha descubierto como BlueNoroff (subgrupo de hackers norcoreanos que pertenecen a Lazarus Group) ha lanzado la campaña 'Hidden Risk' dirigida a usuarios de #macOS

    #ciberseguridad #tech

    mecambioamac.com/hackers-norco

  13. #SentinelLabs ha descubierto como BlueNoroff (subgrupo de hackers norcoreanos que pertenecen a Lazarus Group) ha lanzado la campaña 'Hidden Risk' dirigida a usuarios de #macOS

    #ciberseguridad #tech

    mecambioamac.com/hackers-norco

  14. Threat Actor Masquerades as Hacktivist Group Rebelling Against AI

    SentinelLabs identified a cybercriminal group, NullBulge, targeting AI- and gaming-focused entities. The group injects malware into public code repositories and gaming mods, leading victims to import malicious libraries. NullBulge uses tools like Async RAT and Xworm before delivering customized LockBit payloads. Despite projecting an anti-AI activism persona, the group's activities indicate a financial motive through data theft and ransomware attacks.

    Pulse ID: 669688f7ddc51e4228efb190
    Pulse Link: otx.alienvault.com/pulse/66968
    Pulse Author: AlienVault
    Created: 2024-07-16 14:51:35

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #DataTheft #Hacktivist #InfoSec #LockBit #Malware #OTX #OpenThreatExchange #RAT #RansomWare #SentinelLabs #Worm #XWorm #bot #AlienVault

  15. The #AcidPour malware is a new variant of #AcidRain targeting #Linux x86 systems in #Ukraine, as discovered by #SentinelLabs researchers. Unlike its predecessor designed for #MIPS architecture, AcidPour specifically targets x86 Linux distributions such as #Ubuntu, #Mint, #Fedora, and #Debian. It introduces new capabilities, including references to Unsorted Block Images (#UBI) and #Logical Volume Manager (LVM) virtual block devices, suggesting an expansion in the range of potential targets. AcidPour's distinct codebase and wiping logic, particularly for devices like LVMs, indicate an evolved threat strategy. Despite the evolving nature of malware threats, SentinelLabs has alerted stakeholders in Ukraine, though the full scope and specific targets of AcidPour remain undisclosed. Users and organizations are advised to enhance cybersecurity measures and educate on phishing and malware threats.

    Source: New AcidRain Linux Malware Variant “AcidPour” Found Targeting Ukraine

  16. The #AcidPour malware is a new variant of #AcidRain targeting #Linux x86 systems in #Ukraine, as discovered by #SentinelLabs researchers. Unlike its predecessor designed for #MIPS architecture, AcidPour specifically targets x86 Linux distributions such as #Ubuntu, #Mint, #Fedora, and #Debian. It introduces new capabilities, including references to Unsorted Block Images (#UBI) and #Logical Volume Manager (LVM) virtual block devices, suggesting an expansion in the range of potential targets. AcidPour's distinct codebase and wiping logic, particularly for devices like LVMs, indicate an evolved threat strategy. Despite the evolving nature of malware threats, SentinelLabs has alerted stakeholders in Ukraine, though the full scope and specific targets of AcidPour remain undisclosed. Users and organizations are advised to enhance cybersecurity measures and educate on phishing and malware threats.

    Source: New AcidRain Linux Malware Variant “AcidPour” Found Targeting Ukraine

  17. The #AcidPour malware is a new variant of #AcidRain targeting #Linux x86 systems in #Ukraine, as discovered by #SentinelLabs researchers. Unlike its predecessor designed for #MIPS architecture, AcidPour specifically targets x86 Linux distributions such as #Ubuntu, #Mint, #Fedora, and #Debian. It introduces new capabilities, including references to Unsorted Block Images (#UBI) and #Logical Volume Manager (LVM) virtual block devices, suggesting an expansion in the range of potential targets. AcidPour's distinct codebase and wiping logic, particularly for devices like LVMs, indicate an evolved threat strategy. Despite the evolving nature of malware threats, SentinelLabs has alerted stakeholders in Ukraine, though the full scope and specific targets of AcidPour remain undisclosed. Users and organizations are advised to enhance cybersecurity measures and educate on phishing and malware threats.

    Source: New AcidRain Linux Malware Variant “AcidPour” Found Targeting Ukraine

  18. The #AcidPour malware is a new variant of #AcidRain targeting #Linux x86 systems in #Ukraine, as discovered by #SentinelLabs researchers. Unlike its predecessor designed for #MIPS architecture, AcidPour specifically targets x86 Linux distributions such as #Ubuntu, #Mint, #Fedora, and #Debian. It introduces new capabilities, including references to Unsorted Block Images (#UBI) and #Logical Volume Manager (LVM) virtual block devices, suggesting an expansion in the range of potential targets. AcidPour's distinct codebase and wiping logic, particularly for devices like LVMs, indicate an evolved threat strategy. Despite the evolving nature of malware threats, SentinelLabs has alerted stakeholders in Ukraine, though the full scope and specific targets of AcidPour remain undisclosed. Users and organizations are advised to enhance cybersecurity measures and educate on phishing and malware threats.

    Source: New AcidRain Linux Malware Variant “AcidPour” Found Targeting Ukraine

  19. The #AcidPour malware is a new variant of #AcidRain targeting #Linux x86 systems in #Ukraine, as discovered by #SentinelLabs researchers. Unlike its predecessor designed for #MIPS architecture, AcidPour specifically targets x86 Linux distributions such as #Ubuntu, #Mint, #Fedora, and #Debian. It introduces new capabilities, including references to Unsorted Block Images (#UBI) and #Logical Volume Manager (LVM) virtual block devices, suggesting an expansion in the range of potential targets. AcidPour's distinct codebase and wiping logic, particularly for devices like LVMs, indicate an evolved threat strategy. Despite the evolving nature of malware threats, SentinelLabs has alerted stakeholders in Ukraine, though the full scope and specific targets of AcidPour remain undisclosed. Users and organizations are advised to enhance cybersecurity measures and educate on phishing and malware threats.

    Source: New AcidRain Linux Malware Variant “AcidPour” Found Targeting Ukraine

  20. Sandman APT | China-Based Adversaries Embrace Lua

    SentinelLabs, Microsoft, and PwC threat intelligence researchers provide attribution-relevant information on the Sandman APT cluster.

    Pulse ID: 657880e45fb217d3766c1f55
    Pulse Link: otx.alienvault.com/pulse/65788
    Pulse Author: AlienVault
    Created: 2023-12-12 15:48:52

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Microsoft #China #SentinelLabs #AlienVault

  21. "🔍 Unveiling Sandman APT: The Silent Menace Targeting Global Telcos 🎯"

    SentinelLabs has unearthed a new threat actor dubbed Sandman APT, primarily targeting telecommunication providers across the Middle East, Western Europe, and South Asia. This enigmatic group employs a novel modular backdoor named LuaDream, utilizing the LuaJIT platform, a rarity in the threat landscape. The meticulous movements and minimal engagements hint at a strategic approach to minimize detection risks. The LuaDream malware, a well-orchestrated and actively developed project, is designed for system and user info exfiltration, paving the way for precision attacks. The intriguing part? The attribution remains elusive, hinting at a private contractor or a mercenary group akin to Metador. The activities observed are espionage-driven, with a pronounced focus on telcos due to the sensitive data they harbor. The meticulous design of LuaDream showcases the continuous innovation in the cyber espionage realm, urging for a collaborative effort within the threat intelligence community to navigate the shadows of the threat landscape.

    Source: SentinelOne Labs

    Tags: #SandmanAPT #LuaDream #TelecomSecurity #CyberEspionage #ThreatActor #CyberSecurity #LuaJIT #SentinelLabs #APT 🌐🔐🎯

    Indicators of Compromise (IoCs):

    • Domains: mode.encagil[.]com, ssl.explorecell[.]com
    • File Paths: %ProgramData%\FaxConfig, %ProgramData%\FaxLib
    • SHA1:
      • fax.dat: 1cd0a3dd6354a3d4a29226f5580f8a51ec3837d4
      • fax.Application: 27894955aaf082a606337ebe29d263263be52154
      • ualapi.dll: 5302c39764922f17e4bc14f589fa45408f8a5089
      • fax.cache: 77e00e3067f23df10196412f231e80cec41c5253
      • UpdateCheck.dll: b9ea189e2420a29978e4dc73d8d2fd801f6a0db2
      • updater.ver: fb1c6a23e8e0693194a365619b388b09155c2183
      • fax.module: ff2802cdbc40d2ef3585357b7e6947d42b875884

    Author: Aleksandar Milenkoski, a seasoned threat researcher at SentinelLabs, has meticulously dissected the activities of Sandman APT, shedding light on the LuaDream backdoor. His expertise in reverse engineering and malware research is evident in the detailed analysis provided.

  22. "🔍 Unveiling Sandman APT: The Silent Menace Targeting Global Telcos 🎯"

    SentinelLabs has unearthed a new threat actor dubbed Sandman APT, primarily targeting telecommunication providers across the Middle East, Western Europe, and South Asia. This enigmatic group employs a novel modular backdoor named LuaDream, utilizing the LuaJIT platform, a rarity in the threat landscape. The meticulous movements and minimal engagements hint at a strategic approach to minimize detection risks. The LuaDream malware, a well-orchestrated and actively developed project, is designed for system and user info exfiltration, paving the way for precision attacks. The intriguing part? The attribution remains elusive, hinting at a private contractor or a mercenary group akin to Metador. The activities observed are espionage-driven, with a pronounced focus on telcos due to the sensitive data they harbor. The meticulous design of LuaDream showcases the continuous innovation in the cyber espionage realm, urging for a collaborative effort within the threat intelligence community to navigate the shadows of the threat landscape.

    Source: SentinelOne Labs

    Tags: #SandmanAPT #LuaDream #TelecomSecurity #CyberEspionage #ThreatActor #CyberSecurity #LuaJIT #SentinelLabs #APT 🌐🔐🎯

    Indicators of Compromise (IoCs):

    • Domains: mode.encagil[.]com, ssl.explorecell[.]com
    • File Paths: %ProgramData%\FaxConfig, %ProgramData%\FaxLib
    • SHA1:
      • fax.dat: 1cd0a3dd6354a3d4a29226f5580f8a51ec3837d4
      • fax.Application: 27894955aaf082a606337ebe29d263263be52154
      • ualapi.dll: 5302c39764922f17e4bc14f589fa45408f8a5089
      • fax.cache: 77e00e3067f23df10196412f231e80cec41c5253
      • UpdateCheck.dll: b9ea189e2420a29978e4dc73d8d2fd801f6a0db2
      • updater.ver: fb1c6a23e8e0693194a365619b388b09155c2183
      • fax.module: ff2802cdbc40d2ef3585357b7e6947d42b875884

    Author: Aleksandar Milenkoski, a seasoned threat researcher at SentinelLabs, has meticulously dissected the activities of Sandman APT, shedding light on the LuaDream backdoor. His expertise in reverse engineering and malware research is evident in the detailed analysis provided.

  23. "🔍 Unveiling Sandman APT: The Silent Menace Targeting Global Telcos 🎯"

    SentinelLabs has unearthed a new threat actor dubbed Sandman APT, primarily targeting telecommunication providers across the Middle East, Western Europe, and South Asia. This enigmatic group employs a novel modular backdoor named LuaDream, utilizing the LuaJIT platform, a rarity in the threat landscape. The meticulous movements and minimal engagements hint at a strategic approach to minimize detection risks. The LuaDream malware, a well-orchestrated and actively developed project, is designed for system and user info exfiltration, paving the way for precision attacks. The intriguing part? The attribution remains elusive, hinting at a private contractor or a mercenary group akin to Metador. The activities observed are espionage-driven, with a pronounced focus on telcos due to the sensitive data they harbor. The meticulous design of LuaDream showcases the continuous innovation in the cyber espionage realm, urging for a collaborative effort within the threat intelligence community to navigate the shadows of the threat landscape.

    Source: SentinelOne Labs

    Tags: #SandmanAPT #LuaDream #TelecomSecurity #CyberEspionage #ThreatActor #CyberSecurity #LuaJIT #SentinelLabs #APT 🌐🔐🎯

    Indicators of Compromise (IoCs):

    • Domains: mode.encagil[.]com, ssl.explorecell[.]com
    • File Paths: %ProgramData%\FaxConfig, %ProgramData%\FaxLib
    • SHA1:
      • fax.dat: 1cd0a3dd6354a3d4a29226f5580f8a51ec3837d4
      • fax.Application: 27894955aaf082a606337ebe29d263263be52154
      • ualapi.dll: 5302c39764922f17e4bc14f589fa45408f8a5089
      • fax.cache: 77e00e3067f23df10196412f231e80cec41c5253
      • UpdateCheck.dll: b9ea189e2420a29978e4dc73d8d2fd801f6a0db2
      • updater.ver: fb1c6a23e8e0693194a365619b388b09155c2183
      • fax.module: ff2802cdbc40d2ef3585357b7e6947d42b875884

    Author: Aleksandar Milenkoski, a seasoned threat researcher at SentinelLabs, has meticulously dissected the activities of Sandman APT, shedding light on the LuaDream backdoor. His expertise in reverse engineering and malware research is evident in the detailed analysis provided.

  24. "🔍 Unveiling Sandman APT: The Silent Menace Targeting Global Telcos 🎯"

    SentinelLabs has unearthed a new threat actor dubbed Sandman APT, primarily targeting telecommunication providers across the Middle East, Western Europe, and South Asia. This enigmatic group employs a novel modular backdoor named LuaDream, utilizing the LuaJIT platform, a rarity in the threat landscape. The meticulous movements and minimal engagements hint at a strategic approach to minimize detection risks. The LuaDream malware, a well-orchestrated and actively developed project, is designed for system and user info exfiltration, paving the way for precision attacks. The intriguing part? The attribution remains elusive, hinting at a private contractor or a mercenary group akin to Metador. The activities observed are espionage-driven, with a pronounced focus on telcos due to the sensitive data they harbor. The meticulous design of LuaDream showcases the continuous innovation in the cyber espionage realm, urging for a collaborative effort within the threat intelligence community to navigate the shadows of the threat landscape.

    Source: SentinelOne Labs

    Tags: #SandmanAPT #LuaDream #TelecomSecurity #CyberEspionage #ThreatActor #CyberSecurity #LuaJIT #SentinelLabs #APT 🌐🔐🎯

    Indicators of Compromise (IoCs):

    • Domains: mode.encagil[.]com, ssl.explorecell[.]com
    • File Paths: %ProgramData%\FaxConfig, %ProgramData%\FaxLib
    • SHA1:
      • fax.dat: 1cd0a3dd6354a3d4a29226f5580f8a51ec3837d4
      • fax.Application: 27894955aaf082a606337ebe29d263263be52154
      • ualapi.dll: 5302c39764922f17e4bc14f589fa45408f8a5089
      • fax.cache: 77e00e3067f23df10196412f231e80cec41c5253
      • UpdateCheck.dll: b9ea189e2420a29978e4dc73d8d2fd801f6a0db2
      • updater.ver: fb1c6a23e8e0693194a365619b388b09155c2183
      • fax.module: ff2802cdbc40d2ef3585357b7e6947d42b875884

    Author: Aleksandar Milenkoski, a seasoned threat researcher at SentinelLabs, has meticulously dissected the activities of Sandman APT, shedding light on the LuaDream backdoor. His expertise in reverse engineering and malware research is evident in the detailed analysis provided.

  25. "🔍 Unveiling Sandman APT: The Silent Menace Targeting Global Telcos 🎯"

    SentinelLabs has unearthed a new threat actor dubbed Sandman APT, primarily targeting telecommunication providers across the Middle East, Western Europe, and South Asia. This enigmatic group employs a novel modular backdoor named LuaDream, utilizing the LuaJIT platform, a rarity in the threat landscape. The meticulous movements and minimal engagements hint at a strategic approach to minimize detection risks. The LuaDream malware, a well-orchestrated and actively developed project, is designed for system and user info exfiltration, paving the way for precision attacks. The intriguing part? The attribution remains elusive, hinting at a private contractor or a mercenary group akin to Metador. The activities observed are espionage-driven, with a pronounced focus on telcos due to the sensitive data they harbor. The meticulous design of LuaDream showcases the continuous innovation in the cyber espionage realm, urging for a collaborative effort within the threat intelligence community to navigate the shadows of the threat landscape.

    Source: SentinelOne Labs

    Tags: #SandmanAPT #LuaDream #TelecomSecurity #CyberEspionage #ThreatActor #CyberSecurity #LuaJIT #SentinelLabs #APT 🌐🔐🎯

    Indicators of Compromise (IoCs):

    • Domains: mode.encagil[.]com, ssl.explorecell[.]com
    • File Paths: %ProgramData%\FaxConfig, %ProgramData%\FaxLib
    • SHA1:
      • fax.dat: 1cd0a3dd6354a3d4a29226f5580f8a51ec3837d4
      • fax.Application: 27894955aaf082a606337ebe29d263263be52154
      • ualapi.dll: 5302c39764922f17e4bc14f589fa45408f8a5089
      • fax.cache: 77e00e3067f23df10196412f231e80cec41c5253
      • UpdateCheck.dll: b9ea189e2420a29978e4dc73d8d2fd801f6a0db2
      • updater.ver: fb1c6a23e8e0693194a365619b388b09155c2183
      • fax.module: ff2802cdbc40d2ef3585357b7e6947d42b875884

    Author: Aleksandar Milenkoski, a seasoned threat researcher at SentinelLabs, has meticulously dissected the activities of Sandman APT, shedding light on the LuaDream backdoor. His expertise in reverse engineering and malware research is evident in the detailed analysis provided.