#sentinellabs — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #sentinellabs, aggregated by home.social.
-
Discover how Iranian hackers maintain covert, long-term access to critical systems for espionage, influence operations, and potential disruption.
#IranianHackers #CyberEspionage #SentinelLABS #CyberSecurity #APT
-
Discover how Iranian hackers maintain covert, long-term access to critical systems for espionage, influence operations, and potential disruption.
#IranianHackers #CyberEspionage #SentinelLABS #CyberSecurity #APT
-
PhantomCaptcha RAT Attack Targets Aid Groups Supporting Ukraine https://hackread.com/phantomcaptcha-rat-attack-targets-ukraine/ #PhantomCaptcha #Cybersecurity #CyberAttacks #SentinelLABS #CyberAttack #Security #RedCross #Ukraine #Russia #Unicef
-
PhantomCaptcha RAT Attack Targets Aid Groups Supporting Ukraine https://hackread.com/phantomcaptcha-rat-attack-targets-ukraine/ #PhantomCaptcha #Cybersecurity #CyberAttacks #SentinelLABS #CyberAttack #Security #RedCross #Ukraine #Russia #Unicef
-
PhantomCaptcha RAT Attack Targets Aid Groups Supporting Ukraine https://hackread.com/phantomcaptcha-rat-attack-targets-ukraine/ #PhantomCaptcha #Cybersecurity #CyberAttacks #SentinelLABS #CyberAttack #Security #RedCross #Ukraine #Russia #Unicef
-
PhantomCaptcha RAT Attack Targets Aid Groups Supporting Ukraine https://hackread.com/phantomcaptcha-rat-attack-targets-ukraine/ #PhantomCaptcha #Cybersecurity #CyberAttacks #SentinelLABS #CyberAttack #Security #RedCross #Ukraine #Russia #Unicef
-
Lazarus Group Deploys Malware With ClickFix Scam in Fake Job Interviews https://hackread.com/lazarus-group-malware-clickfix-scam-fake-job-interview/ #ScamsandFraud #Cybersecurity #SentinelLABS #CyberAttack #NorthKorea #VirusTotal #Security #ClickFix #Maltrail #security #Malware #Lazarus #Validin #Fraud #Scam
-
Lazarus Group Deploys Malware With ClickFix Scam in Fake Job Interviews https://hackread.com/lazarus-group-malware-clickfix-scam-fake-job-interview/ #ScamsandFraud #Cybersecurity #SentinelLABS #CyberAttack #NorthKorea #VirusTotal #Security #ClickFix #Maltrail #security #Malware #Lazarus #Validin #Fraud #Scam
-
Lazarus Group Deploys Malware With ClickFix Scam in Fake Job Interviews https://hackread.com/lazarus-group-malware-clickfix-scam-fake-job-interview/ #ScamsandFraud #Cybersecurity #SentinelLABS #CyberAttack #NorthKorea #VirusTotal #Security #ClickFix #Maltrail #security #Malware #Lazarus #Validin #Fraud #Scam
-
Lazarus Group Deploys Malware With ClickFix Scam in Fake Job Interviews https://hackread.com/lazarus-group-malware-clickfix-scam-fake-job-interview/ #ScamsandFraud #Cybersecurity #SentinelLABS #CyberAttack #NorthKorea #VirusTotal #Security #ClickFix #Maltrail #security #Malware #Lazarus #Validin #Fraud #Scam
-
Fresh from #SentinelLABS: our story on how #dprk threat actors try to leverage threat intel platforms and leak their own secrets. 🕵️♂️🤦♂️
https://s1.ai/nk-ops -
Fresh from #SentinelLABS: our story on how #dprk threat actors try to leverage threat intel platforms and leak their own secrets. 🕵️♂️🤦♂️
https://s1.ai/nk-ops -
Fresh from #SentinelLABS: our story on how #dprk threat actors try to leverage threat intel platforms and leak their own secrets. 🕵️♂️🤦♂️
https://s1.ai/nk-ops -
Fresh from #SentinelLABS: our story on how #dprk threat actors try to leverage threat intel platforms and leak their own secrets. 🕵️♂️🤦♂️
https://s1.ai/nk-ops -
Fresh from #SentinelLABS: our story on how #dprk threat actors try to leverage threat intel platforms and leak their own secrets. 🕵️♂️🤦♂️
https://s1.ai/nk-ops -
Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS – Source:hackread.com https://ciso2ciso.com/chinese-linked-hackers-targeted-70-global-organizations-sentinellabs-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #CyberAttacks #SentinelLABS #SentinelOne #PurpleHaze #Hackread #security #UNC5174 #APT15 #China
-
Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS – Source:hackread.com https://ciso2ciso.com/chinese-linked-hackers-targeted-70-global-organizations-sentinellabs-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #CyberAttacks #SentinelLABS #SentinelOne #PurpleHaze #Hackread #security #UNC5174 #APT15 #China
-
Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS – Source:hackread.com https://ciso2ciso.com/chinese-linked-hackers-targeted-70-global-organizations-sentinellabs-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #CyberAttacks #SentinelLABS #SentinelOne #PurpleHaze #Hackread #security #UNC5174 #APT15 #China
-
Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS – Source:hackread.com https://ciso2ciso.com/chinese-linked-hackers-targeted-70-global-organizations-sentinellabs-sourcehackread-com/ #1CyberSecurityNewsPost #CyberSecurityNews #CyberAttacks #SentinelLABS #SentinelOne #PurpleHaze #Hackread #security #UNC5174 #APT15 #China
-
Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS https://hackread.com/chinese-linked-hackers-targeted-global-organizations/ #CyberAttacks #SentinelLABS #SentinelOne #PurpleHaze #Security #UNC5174 #APT15 #China
-
Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS https://hackread.com/chinese-linked-hackers-targeted-global-organizations/ #CyberAttacks #SentinelLABS #SentinelOne #PurpleHaze #Security #UNC5174 #APT15 #China
-
Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS https://hackread.com/chinese-linked-hackers-targeted-global-organizations/ #CyberAttacks #SentinelLABS #SentinelOne #PurpleHaze #Security #UNC5174 #APT15 #China
-
Chinese-Linked Hackers Targeted 70+ Global Organizations, SentinelLABS https://hackread.com/chinese-linked-hackers-targeted-global-organizations/ #CyberAttacks #SentinelLABS #SentinelOne #PurpleHaze #Security #UNC5174 #APT15 #China
-
Chinese Espionage Crews Circle SentinelOne in Year-Long Reconnaissance Campaign https://www.securityweek.com/chinese-espionage-crews-circle-sentinelone-in-year-long-reconnaissance-campaign/ #IncidentResponse #Malware&Threats #SentinelLabs #NationState #SentinelOne #PurpleHaze #Shadowpad #APT41 #China
-
Chinese Espionage Crews Circle SentinelOne in Year-Long Reconnaissance Campaign https://www.securityweek.com/chinese-espionage-crews-circle-sentinelone-in-year-long-reconnaissance-campaign/ #IncidentResponse #Malware&Threats #SentinelLabs #NationState #SentinelOne #PurpleHaze #Shadowpad #APT41 #China
-
Chinese Espionage Crews Circle SentinelOne in Year-Long Reconnaissance Campaign https://www.securityweek.com/chinese-espionage-crews-circle-sentinelone-in-year-long-reconnaissance-campaign/ #IncidentResponse #Malware&Threats #SentinelLabs #NationState #SentinelOne #PurpleHaze #Shadowpad #APT41 #China
-
Chinese Espionage Crews Circle SentinelOne in Year-Long Reconnaissance Campaign https://www.securityweek.com/chinese-espionage-crews-circle-sentinelone-in-year-long-reconnaissance-campaign/ #IncidentResponse #Malware&Threats #SentinelLabs #NationState #SentinelOne #PurpleHaze #Shadowpad #APT41 #China
-
Chinese Espionage Crews Circle SentinelOne in Year-Long Reconnaissance Campaign https://www.securityweek.com/chinese-espionage-crews-circle-sentinelone-in-year-long-reconnaissance-campaign/ #IncidentResponse #Malware&Threats #SentinelLabs #NationState #SentinelOne #PurpleHaze #Shadowpad #APT41 #China
-
Chinese Espionage Crews Circle SentinelOne in Year-Long Reconnaissance Campaign https://www.securityweek.com/chinese-espionage-crews-circle-sentinelone-in-year-long-reconnaissance-campaign/ #IncidentResponse #Malware&Threats #SentinelLabs #NationState #SentinelOne #PurpleHaze #Shadowpad #APT41 #China
-
Chinese Espionage Crews Circle SentinelOne in Year-Long Reconnaissance Campaign https://www.securityweek.com/chinese-espionage-crews-circle-sentinelone-in-year-long-reconnaissance-campaign/ #IncidentResponse #Malware&Threats #SentinelLabs #NationState #SentinelOne #PurpleHaze #Shadowpad #APT41 #China
-
Chinese Espionage Crews Circle SentinelOne in Year-Long Reconnaissance Campaign https://www.securityweek.com/chinese-espionage-crews-circle-sentinelone-in-year-long-reconnaissance-campaign/ #IncidentResponse #Malware&Threats #SentinelLabs #NationState #SentinelOne #PurpleHaze #Shadowpad #APT41 #China
-
#SentinelLABS researcher #TomHegel writes about an extension of the long-running #Ghostwriter campaign targeting opposition activists in #Belarus as well as #Ukrainian military and government organizations with weaponized #Excel documents lures.
-
#SentinelLABS researcher #TomHegel writes about an extension of the long-running #Ghostwriter campaign targeting opposition activists in #Belarus as well as #Ukrainian military and government organizations with weaponized #Excel documents lures.
-
#SentinelLABS researcher #TomHegel writes about an extension of the long-running #Ghostwriter campaign targeting opposition activists in #Belarus as well as #Ukrainian military and government organizations with weaponized #Excel documents lures.
-
#SentinelLabs ha descubierto como BlueNoroff (subgrupo de hackers norcoreanos que pertenecen a Lazarus Group) ha lanzado la campaña 'Hidden Risk' dirigida a usuarios de #macOS
-
#SentinelLabs ha descubierto como BlueNoroff (subgrupo de hackers norcoreanos que pertenecen a Lazarus Group) ha lanzado la campaña 'Hidden Risk' dirigida a usuarios de #macOS
-
#SentinelLabs ha descubierto como BlueNoroff (subgrupo de hackers norcoreanos que pertenecen a Lazarus Group) ha lanzado la campaña 'Hidden Risk' dirigida a usuarios de #macOS
-
#SentinelLabs ha descubierto como BlueNoroff (subgrupo de hackers norcoreanos que pertenecen a Lazarus Group) ha lanzado la campaña 'Hidden Risk' dirigida a usuarios de #macOS
-
#SentinelLabs ha descubierto como BlueNoroff (subgrupo de hackers norcoreanos que pertenecen a Lazarus Group) ha lanzado la campaña 'Hidden Risk' dirigida a usuarios de #macOS
-
CHAMELGANG & FRIENDS | CYBERESPIONAGE GROUPS ATTACKING CRITICAL INFRASTRUCTURE WITH RANSOMWARE https://ciso2ciso.com/chamelgang-friends-cyberespionage-groups-attacking-critical-infrastructure-with-ransomware/ #0-CT-CISOStrategics-CybercrimeEcosystem #CISO2CISONotepadSeries2 #SentinelLABS
-
CHAMELGANG & FRIENDS | CYBERESPIONAGE GROUPS ATTACKING CRITICAL INFRASTRUCTURE WITH RANSOMWARE https://ciso2ciso.com/chamelgang-friends-cyberespionage-groups-attacking-critical-infrastructure-with-ransomware/ #0-CT-CISOStrategics-CybercrimeEcosystem #CISO2CISONotepadSeries2 #SentinelLABS
-
CHAMELGANG & FRIENDS | CYBERESPIONAGE GROUPS ATTACKING CRITICAL INFRASTRUCTURE WITH RANSOMWARE https://ciso2ciso.com/chamelgang-friends-cyberespionage-groups-attacking-critical-infrastructure-with-ransomware/ #0-CT-CISOStrategics-CybercrimeEcosystem #CISO2CISONotepadSeries2 #SentinelLABS
-
Threat Actor Masquerades as Hacktivist Group Rebelling Against AI
SentinelLabs identified a cybercriminal group, NullBulge, targeting AI- and gaming-focused entities. The group injects malware into public code repositories and gaming mods, leading victims to import malicious libraries. NullBulge uses tools like Async RAT and Xworm before delivering customized LockBit payloads. Despite projecting an anti-AI activism persona, the group's activities indicate a financial motive through data theft and ransomware attacks.
Pulse ID: 669688f7ddc51e4228efb190
Pulse Link: https://otx.alienvault.com/pulse/669688f7ddc51e4228efb190
Pulse Author: AlienVault
Created: 2024-07-16 14:51:35Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #DataTheft #Hacktivist #InfoSec #LockBit #Malware #OTX #OpenThreatExchange #RAT #RansomWare #SentinelLabs #Worm #XWorm #bot #AlienVault
-
The #AcidPour malware is a new variant of #AcidRain targeting #Linux x86 systems in #Ukraine, as discovered by #SentinelLabs researchers. Unlike its predecessor designed for #MIPS architecture, AcidPour specifically targets x86 Linux distributions such as #Ubuntu, #Mint, #Fedora, and #Debian. It introduces new capabilities, including references to Unsorted Block Images (#UBI) and #Logical Volume Manager (LVM) virtual block devices, suggesting an expansion in the range of potential targets. AcidPour's distinct codebase and wiping logic, particularly for devices like LVMs, indicate an evolved threat strategy. Despite the evolving nature of malware threats, SentinelLabs has alerted stakeholders in Ukraine, though the full scope and specific targets of AcidPour remain undisclosed. Users and organizations are advised to enhance cybersecurity measures and educate on phishing and malware threats.
Source: New AcidRain Linux Malware Variant “AcidPour” Found Targeting Ukraine
-
The #AcidPour malware is a new variant of #AcidRain targeting #Linux x86 systems in #Ukraine, as discovered by #SentinelLabs researchers. Unlike its predecessor designed for #MIPS architecture, AcidPour specifically targets x86 Linux distributions such as #Ubuntu, #Mint, #Fedora, and #Debian. It introduces new capabilities, including references to Unsorted Block Images (#UBI) and #Logical Volume Manager (LVM) virtual block devices, suggesting an expansion in the range of potential targets. AcidPour's distinct codebase and wiping logic, particularly for devices like LVMs, indicate an evolved threat strategy. Despite the evolving nature of malware threats, SentinelLabs has alerted stakeholders in Ukraine, though the full scope and specific targets of AcidPour remain undisclosed. Users and organizations are advised to enhance cybersecurity measures and educate on phishing and malware threats.
Source: New AcidRain Linux Malware Variant “AcidPour” Found Targeting Ukraine
-
The #AcidPour malware is a new variant of #AcidRain targeting #Linux x86 systems in #Ukraine, as discovered by #SentinelLabs researchers. Unlike its predecessor designed for #MIPS architecture, AcidPour specifically targets x86 Linux distributions such as #Ubuntu, #Mint, #Fedora, and #Debian. It introduces new capabilities, including references to Unsorted Block Images (#UBI) and #Logical Volume Manager (LVM) virtual block devices, suggesting an expansion in the range of potential targets. AcidPour's distinct codebase and wiping logic, particularly for devices like LVMs, indicate an evolved threat strategy. Despite the evolving nature of malware threats, SentinelLabs has alerted stakeholders in Ukraine, though the full scope and specific targets of AcidPour remain undisclosed. Users and organizations are advised to enhance cybersecurity measures and educate on phishing and malware threats.
Source: New AcidRain Linux Malware Variant “AcidPour” Found Targeting Ukraine
-
The #AcidPour malware is a new variant of #AcidRain targeting #Linux x86 systems in #Ukraine, as discovered by #SentinelLabs researchers. Unlike its predecessor designed for #MIPS architecture, AcidPour specifically targets x86 Linux distributions such as #Ubuntu, #Mint, #Fedora, and #Debian. It introduces new capabilities, including references to Unsorted Block Images (#UBI) and #Logical Volume Manager (LVM) virtual block devices, suggesting an expansion in the range of potential targets. AcidPour's distinct codebase and wiping logic, particularly for devices like LVMs, indicate an evolved threat strategy. Despite the evolving nature of malware threats, SentinelLabs has alerted stakeholders in Ukraine, though the full scope and specific targets of AcidPour remain undisclosed. Users and organizations are advised to enhance cybersecurity measures and educate on phishing and malware threats.
Source: New AcidRain Linux Malware Variant “AcidPour” Found Targeting Ukraine
-
The #AcidPour malware is a new variant of #AcidRain targeting #Linux x86 systems in #Ukraine, as discovered by #SentinelLabs researchers. Unlike its predecessor designed for #MIPS architecture, AcidPour specifically targets x86 Linux distributions such as #Ubuntu, #Mint, #Fedora, and #Debian. It introduces new capabilities, including references to Unsorted Block Images (#UBI) and #Logical Volume Manager (LVM) virtual block devices, suggesting an expansion in the range of potential targets. AcidPour's distinct codebase and wiping logic, particularly for devices like LVMs, indicate an evolved threat strategy. Despite the evolving nature of malware threats, SentinelLabs has alerted stakeholders in Ukraine, though the full scope and specific targets of AcidPour remain undisclosed. Users and organizations are advised to enhance cybersecurity measures and educate on phishing and malware threats.
Source: New AcidRain Linux Malware Variant “AcidPour” Found Targeting Ukraine
-
Researchers Flag FBot Hacking Tool Hijacking Cloud, Payment Services – Source: www.securityweek.com https://ciso2ciso.com/researchers-flag-fbot-hacking-tool-hijacking-cloud-payment-services-source-www-securityweek-com/ #rssfeedpostgeneratorecho #Fraud&IdentityTheft #CyberSecurityNews #securityweekcom #securityweek #SentinelLabs #Cybercrime #PayPal #Fbot #aws
-
Researchers Flag FBot Hacking Tool Hijacking Cloud, Payment Services – Source: www.securityweek.com https://ciso2ciso.com/researchers-flag-fbot-hacking-tool-hijacking-cloud-payment-services-source-www-securityweek-com/ #rssfeedpostgeneratorecho #Fraud&IdentityTheft #CyberSecurityNews #securityweekcom #securityweek #SentinelLabs #Cybercrime #PayPal #Fbot #aws
-
Researchers Flag FBot Hacking Tool Hijacking Cloud, Payment Services https://www.securityweek.com/researchers-flag-fbot-hacking-tool-hijacking-cloud-payment-services/ #Fraud&IdentityTheft #SentinelLabs #Cybercrime #PayPal #Fbot #AWS
-
Researchers Flag FBot Hacking Tool Hijacking Cloud, Payment Services https://www.securityweek.com/researchers-flag-fbot-hacking-tool-hijacking-cloud-payment-services/ #Fraud&IdentityTheft #SentinelLabs #Cybercrime #PayPal #Fbot #AWS
-
Researchers Flag FBot Hacking Tool Hijacking Cloud, Payment Services https://www.securityweek.com/researchers-flag-fbot-hacking-tool-hijacking-cloud-payment-services/ #Fraud&IdentityTheft #SentinelLabs #Cybercrime #PayPal #Fbot #AWS
-
Researchers Flag FBot Hacking Tool Hijacking Cloud, Payment Services https://www.securityweek.com/researchers-flag-fbot-hacking-tool-hijacking-cloud-payment-services/ #Fraud&IdentityTheft #SentinelLabs #Cybercrime #PayPal #Fbot #AWS
-
Sandman APT | China-Based Adversaries Embrace Lua
SentinelLabs, Microsoft, and PwC threat intelligence researchers provide attribution-relevant information on the Sandman APT cluster.
Pulse ID: 657880e45fb217d3766c1f55
Pulse Link: https://otx.alienvault.com/pulse/657880e45fb217d3766c1f55
Pulse Author: AlienVault
Created: 2023-12-12 15:48:52Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Microsoft #China #SentinelLabs #AlienVault
-
"🔍 Unveiling Sandman APT: The Silent Menace Targeting Global Telcos 🎯"
SentinelLabs has unearthed a new threat actor dubbed Sandman APT, primarily targeting telecommunication providers across the Middle East, Western Europe, and South Asia. This enigmatic group employs a novel modular backdoor named LuaDream, utilizing the LuaJIT platform, a rarity in the threat landscape. The meticulous movements and minimal engagements hint at a strategic approach to minimize detection risks. The LuaDream malware, a well-orchestrated and actively developed project, is designed for system and user info exfiltration, paving the way for precision attacks. The intriguing part? The attribution remains elusive, hinting at a private contractor or a mercenary group akin to Metador. The activities observed are espionage-driven, with a pronounced focus on telcos due to the sensitive data they harbor. The meticulous design of LuaDream showcases the continuous innovation in the cyber espionage realm, urging for a collaborative effort within the threat intelligence community to navigate the shadows of the threat landscape.
Source: SentinelOne Labs
Tags: #SandmanAPT #LuaDream #TelecomSecurity #CyberEspionage #ThreatActor #CyberSecurity #LuaJIT #SentinelLabs #APT 🌐🔐🎯
Indicators of Compromise (IoCs):
- Domains: mode.encagil[.]com, ssl.explorecell[.]com
- File Paths: %ProgramData%\FaxConfig, %ProgramData%\FaxLib
- SHA1:
- fax.dat: 1cd0a3dd6354a3d4a29226f5580f8a51ec3837d4
- fax.Application: 27894955aaf082a606337ebe29d263263be52154
- ualapi.dll: 5302c39764922f17e4bc14f589fa45408f8a5089
- fax.cache: 77e00e3067f23df10196412f231e80cec41c5253
- UpdateCheck.dll: b9ea189e2420a29978e4dc73d8d2fd801f6a0db2
- updater.ver: fb1c6a23e8e0693194a365619b388b09155c2183
- fax.module: ff2802cdbc40d2ef3585357b7e6947d42b875884
Author: Aleksandar Milenkoski, a seasoned threat researcher at SentinelLabs, has meticulously dissected the activities of Sandman APT, shedding light on the LuaDream backdoor. His expertise in reverse engineering and malware research is evident in the detailed analysis provided.
-
"🔍 Unveiling Sandman APT: The Silent Menace Targeting Global Telcos 🎯"
SentinelLabs has unearthed a new threat actor dubbed Sandman APT, primarily targeting telecommunication providers across the Middle East, Western Europe, and South Asia. This enigmatic group employs a novel modular backdoor named LuaDream, utilizing the LuaJIT platform, a rarity in the threat landscape. The meticulous movements and minimal engagements hint at a strategic approach to minimize detection risks. The LuaDream malware, a well-orchestrated and actively developed project, is designed for system and user info exfiltration, paving the way for precision attacks. The intriguing part? The attribution remains elusive, hinting at a private contractor or a mercenary group akin to Metador. The activities observed are espionage-driven, with a pronounced focus on telcos due to the sensitive data they harbor. The meticulous design of LuaDream showcases the continuous innovation in the cyber espionage realm, urging for a collaborative effort within the threat intelligence community to navigate the shadows of the threat landscape.
Source: SentinelOne Labs
Tags: #SandmanAPT #LuaDream #TelecomSecurity #CyberEspionage #ThreatActor #CyberSecurity #LuaJIT #SentinelLabs #APT 🌐🔐🎯
Indicators of Compromise (IoCs):
- Domains: mode.encagil[.]com, ssl.explorecell[.]com
- File Paths: %ProgramData%\FaxConfig, %ProgramData%\FaxLib
- SHA1:
- fax.dat: 1cd0a3dd6354a3d4a29226f5580f8a51ec3837d4
- fax.Application: 27894955aaf082a606337ebe29d263263be52154
- ualapi.dll: 5302c39764922f17e4bc14f589fa45408f8a5089
- fax.cache: 77e00e3067f23df10196412f231e80cec41c5253
- UpdateCheck.dll: b9ea189e2420a29978e4dc73d8d2fd801f6a0db2
- updater.ver: fb1c6a23e8e0693194a365619b388b09155c2183
- fax.module: ff2802cdbc40d2ef3585357b7e6947d42b875884
Author: Aleksandar Milenkoski, a seasoned threat researcher at SentinelLabs, has meticulously dissected the activities of Sandman APT, shedding light on the LuaDream backdoor. His expertise in reverse engineering and malware research is evident in the detailed analysis provided.
-
"🔍 Unveiling Sandman APT: The Silent Menace Targeting Global Telcos 🎯"
SentinelLabs has unearthed a new threat actor dubbed Sandman APT, primarily targeting telecommunication providers across the Middle East, Western Europe, and South Asia. This enigmatic group employs a novel modular backdoor named LuaDream, utilizing the LuaJIT platform, a rarity in the threat landscape. The meticulous movements and minimal engagements hint at a strategic approach to minimize detection risks. The LuaDream malware, a well-orchestrated and actively developed project, is designed for system and user info exfiltration, paving the way for precision attacks. The intriguing part? The attribution remains elusive, hinting at a private contractor or a mercenary group akin to Metador. The activities observed are espionage-driven, with a pronounced focus on telcos due to the sensitive data they harbor. The meticulous design of LuaDream showcases the continuous innovation in the cyber espionage realm, urging for a collaborative effort within the threat intelligence community to navigate the shadows of the threat landscape.
Source: SentinelOne Labs
Tags: #SandmanAPT #LuaDream #TelecomSecurity #CyberEspionage #ThreatActor #CyberSecurity #LuaJIT #SentinelLabs #APT 🌐🔐🎯
Indicators of Compromise (IoCs):
- Domains: mode.encagil[.]com, ssl.explorecell[.]com
- File Paths: %ProgramData%\FaxConfig, %ProgramData%\FaxLib
- SHA1:
- fax.dat: 1cd0a3dd6354a3d4a29226f5580f8a51ec3837d4
- fax.Application: 27894955aaf082a606337ebe29d263263be52154
- ualapi.dll: 5302c39764922f17e4bc14f589fa45408f8a5089
- fax.cache: 77e00e3067f23df10196412f231e80cec41c5253
- UpdateCheck.dll: b9ea189e2420a29978e4dc73d8d2fd801f6a0db2
- updater.ver: fb1c6a23e8e0693194a365619b388b09155c2183
- fax.module: ff2802cdbc40d2ef3585357b7e6947d42b875884
Author: Aleksandar Milenkoski, a seasoned threat researcher at SentinelLabs, has meticulously dissected the activities of Sandman APT, shedding light on the LuaDream backdoor. His expertise in reverse engineering and malware research is evident in the detailed analysis provided.
-
"🔍 Unveiling Sandman APT: The Silent Menace Targeting Global Telcos 🎯"
SentinelLabs has unearthed a new threat actor dubbed Sandman APT, primarily targeting telecommunication providers across the Middle East, Western Europe, and South Asia. This enigmatic group employs a novel modular backdoor named LuaDream, utilizing the LuaJIT platform, a rarity in the threat landscape. The meticulous movements and minimal engagements hint at a strategic approach to minimize detection risks. The LuaDream malware, a well-orchestrated and actively developed project, is designed for system and user info exfiltration, paving the way for precision attacks. The intriguing part? The attribution remains elusive, hinting at a private contractor or a mercenary group akin to Metador. The activities observed are espionage-driven, with a pronounced focus on telcos due to the sensitive data they harbor. The meticulous design of LuaDream showcases the continuous innovation in the cyber espionage realm, urging for a collaborative effort within the threat intelligence community to navigate the shadows of the threat landscape.
Source: SentinelOne Labs
Tags: #SandmanAPT #LuaDream #TelecomSecurity #CyberEspionage #ThreatActor #CyberSecurity #LuaJIT #SentinelLabs #APT 🌐🔐🎯
Indicators of Compromise (IoCs):
- Domains: mode.encagil[.]com, ssl.explorecell[.]com
- File Paths: %ProgramData%\FaxConfig, %ProgramData%\FaxLib
- SHA1:
- fax.dat: 1cd0a3dd6354a3d4a29226f5580f8a51ec3837d4
- fax.Application: 27894955aaf082a606337ebe29d263263be52154
- ualapi.dll: 5302c39764922f17e4bc14f589fa45408f8a5089
- fax.cache: 77e00e3067f23df10196412f231e80cec41c5253
- UpdateCheck.dll: b9ea189e2420a29978e4dc73d8d2fd801f6a0db2
- updater.ver: fb1c6a23e8e0693194a365619b388b09155c2183
- fax.module: ff2802cdbc40d2ef3585357b7e6947d42b875884
Author: Aleksandar Milenkoski, a seasoned threat researcher at SentinelLabs, has meticulously dissected the activities of Sandman APT, shedding light on the LuaDream backdoor. His expertise in reverse engineering and malware research is evident in the detailed analysis provided.
-
"🔍 Unveiling Sandman APT: The Silent Menace Targeting Global Telcos 🎯"
SentinelLabs has unearthed a new threat actor dubbed Sandman APT, primarily targeting telecommunication providers across the Middle East, Western Europe, and South Asia. This enigmatic group employs a novel modular backdoor named LuaDream, utilizing the LuaJIT platform, a rarity in the threat landscape. The meticulous movements and minimal engagements hint at a strategic approach to minimize detection risks. The LuaDream malware, a well-orchestrated and actively developed project, is designed for system and user info exfiltration, paving the way for precision attacks. The intriguing part? The attribution remains elusive, hinting at a private contractor or a mercenary group akin to Metador. The activities observed are espionage-driven, with a pronounced focus on telcos due to the sensitive data they harbor. The meticulous design of LuaDream showcases the continuous innovation in the cyber espionage realm, urging for a collaborative effort within the threat intelligence community to navigate the shadows of the threat landscape.
Source: SentinelOne Labs
Tags: #SandmanAPT #LuaDream #TelecomSecurity #CyberEspionage #ThreatActor #CyberSecurity #LuaJIT #SentinelLabs #APT 🌐🔐🎯
Indicators of Compromise (IoCs):
- Domains: mode.encagil[.]com, ssl.explorecell[.]com
- File Paths: %ProgramData%\FaxConfig, %ProgramData%\FaxLib
- SHA1:
- fax.dat: 1cd0a3dd6354a3d4a29226f5580f8a51ec3837d4
- fax.Application: 27894955aaf082a606337ebe29d263263be52154
- ualapi.dll: 5302c39764922f17e4bc14f589fa45408f8a5089
- fax.cache: 77e00e3067f23df10196412f231e80cec41c5253
- UpdateCheck.dll: b9ea189e2420a29978e4dc73d8d2fd801f6a0db2
- updater.ver: fb1c6a23e8e0693194a365619b388b09155c2183
- fax.module: ff2802cdbc40d2ef3585357b7e6947d42b875884
Author: Aleksandar Milenkoski, a seasoned threat researcher at SentinelLabs, has meticulously dissected the activities of Sandman APT, shedding light on the LuaDream backdoor. His expertise in reverse engineering and malware research is evident in the detailed analysis provided.