#sliver — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #sliver, aggregated by home.social.
-
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.
Pulse ID: 6a76515e8fbfccabf4dbb65b
Pulse Link: https://otx.alienvault.com/pulse/6a76515e8fbfccabf4dbb65b
Pulse Author: AlienVault
Created: 2026-08-07 21:42:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault
-
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.
Pulse ID: 6a76515e8fbfccabf4dbb65b
Pulse Link: https://otx.alienvault.com/pulse/6a76515e8fbfccabf4dbb65b
Pulse Author: AlienVault
Created: 2026-08-07 21:42:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault
-
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.
Pulse ID: 6a76515e8fbfccabf4dbb65b
Pulse Link: https://otx.alienvault.com/pulse/6a76515e8fbfccabf4dbb65b
Pulse Author: AlienVault
Created: 2026-08-07 21:42:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault
-
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.
Pulse ID: 6a76515e8fbfccabf4dbb65b
Pulse Link: https://otx.alienvault.com/pulse/6a76515e8fbfccabf4dbb65b
Pulse Author: AlienVault
Created: 2026-08-07 21:42:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault
-
Russian AI Slopsquatting Publishes 700+ Malicious NPM Packages
A threat actor published over 700 malicious packages to the NPM registry within 48 hours using AI-generated typo-squatting package names. These packages deploy a cross-platform RAT and infostealer without requiring install scripts, executing immediately upon import via require(). The downloader supports Windows, Linux, and macOS, rotating through three Cloudflare Workers hosts for payload delivery with a DNS TXT record fallback under wel1.ru. The macOS payload establishes persistence via LaunchAgents and downloads additional beacons. The Linux version delivers what appears to be a Sliver implant. The campaign shows connections to the earlier Moika malware operation, with shared tradecraft including focus on Russian financial institutions, fake telemetry camouflage, and similar kill switch mechanisms. The malware includes anti-analysis capabilities detecting debuggers, virtualization, and packet capture tools.
Pulse ID: 6a76515e8fbfccabf4dbb65b
Pulse Link: https://otx.alienvault.com/pulse/6a76515e8fbfccabf4dbb65b
Pulse Author: AlienVault
Created: 2026-08-07 21:42:54Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Cloud #CyberSecurity #DNS #InfoSec #InfoStealer #Linux #Mac #MacOS #Malware #NPM #OTX #OpenThreatExchange #RAT #Russia #SMS #Sliver #Windows #bot #AlienVault
-
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.
Pulse ID: 6a72f3bde4df792f5fa8956d
Pulse Link: https://otx.alienvault.com/pulse/6a72f3bde4df792f5fa8956d
Pulse Author: AlienVault
Created: 2026-08-05 08:26:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault
-
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.
Pulse ID: 6a72f3bde4df792f5fa8956d
Pulse Link: https://otx.alienvault.com/pulse/6a72f3bde4df792f5fa8956d
Pulse Author: AlienVault
Created: 2026-08-05 08:26:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault
-
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.
Pulse ID: 6a72f3bde4df792f5fa8956d
Pulse Link: https://otx.alienvault.com/pulse/6a72f3bde4df792f5fa8956d
Pulse Author: AlienVault
Created: 2026-08-05 08:26:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault
-
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.
Pulse ID: 6a72f3bde4df792f5fa8956d
Pulse Link: https://otx.alienvault.com/pulse/6a72f3bde4df792f5fa8956d
Pulse Author: AlienVault
Created: 2026-08-05 08:26:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault
-
The Gentlemen Affiliate Deploys EtherRAT Across Windows Networks Using Ethereum Smart Contract C2
An exposed open directory at a staging server revealed an active intrusion by operators linked to The Gentlemen ransomware group. The operation involved establishing persistent access through privileged account creation, credential theft via LSASS dumping, and lateral movement across a Windows domain. Attackers deployed multiple implants including EtherRAT, which retrieves command-and-control domains from an Ethereum smart contract, alongside Sliver and custom Go reverse shells. Lateral movement was achieved through remote scheduled tasks distributing MSI payloads, while security products were disabled and reverse tunnels established for persistent access. The infrastructure and tactics align with previously documented The Gentlemen campaigns, including a ClickFix operation deploying EtherRAT.
Pulse ID: 6a72f3bde4df792f5fa8956d
Pulse Link: https://otx.alienvault.com/pulse/6a72f3bde4df792f5fa8956d
Pulse Author: AlienVault
Created: 2026-08-05 08:26:37Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RansomWare #Sliver #Windows #bot #AlienVault
-
Movie TV Tech Geeks #Movie #ColorofNight #Sliver 10 Worst Twists in '90s Thrillers, Ranked http://dlvr.it/TSmTyD
-
Movie TV Tech Geeks #Movie #ColorofNight #Sliver 10 Worst Twists in '90s Thrillers, Ranked http://dlvr.it/TSmTyD
-
Sliver | The blockbuster whose big finale nearly killed three people – then got cut
-
«Ждите гостей»: новые инструменты и тактики PhantomCore в атаках на российские компании
На примере новой атаки PhantomCore - одной из главных киберугроз для российских и белорусских компаний - показываем, как группировка развивает свои инструменты и тактики, внедряет новое ВПО и расширяет спектр используемых технологий, включая AI-решения. Одна из главных особенностей PhantomCore – её постоянная изменчивость: эта АРТ-группа быстро приспосабливается к новым условиям, оперативно меняет инструменты и изобретает нестандартные способы доставки ВПО до атакуемых организаций.
https://habr.com/ru/companies/F6/articles/1024486/
#phantomcore #apt #kermit_rat #фишинговые_письма #киберразведка #threat_intelligence #mattermost #cyberstrike_ai #mashagent #sliver
-
«Ждите гостей»: новые инструменты и тактики PhantomCore в атаках на российские компании
На примере новой атаки PhantomCore - одной из главных киберугроз для российских и белорусских компаний - показываем, как группировка развивает свои инструменты и тактики, внедряет новое ВПО и расширяет спектр используемых технологий, включая AI-решения. Одна из главных особенностей PhantomCore – её постоянная изменчивость: эта АРТ-группа быстро приспосабливается к новым условиям, оперативно меняет инструменты и изобретает нестандартные способы доставки ВПО до атакуемых организаций.
https://habr.com/ru/companies/F6/articles/1024486/
#phantomcore #apt #kermit_rat #фишинговые_письма #киберразведка #threat_intelligence #mattermost #cyberstrike_ai #mashagent #sliver
-
«Ждите гостей»: новые инструменты и тактики PhantomCore в атаках на российские компании
На примере новой атаки PhantomCore - одной из главных киберугроз для российских и белорусских компаний - показываем, как группировка развивает свои инструменты и тактики, внедряет новое ВПО и расширяет спектр используемых технологий, включая AI-решения. Одна из главных особенностей PhantomCore – её постоянная изменчивость: эта АРТ-группа быстро приспосабливается к новым условиям, оперативно меняет инструменты и изобретает нестандартные способы доставки ВПО до атакуемых организаций.
https://habr.com/ru/companies/F6/articles/1024486/
#phantomcore #apt #kermit_rat #фишинговые_письма #киберразведка #threat_intelligence #mattermost #cyberstrike_ai #mashagent #sliver
-
Movie TV Tech Geeks #MovieNews #BasicInstinct #Sliver #TheHousemaid Sydney Sweeney’s New Erotic Thriller Just Beat Sharon Stone’s ‘Basic Instinct’ Follow-Up at the Box Office http://dlvr.it/TQ3k3X
-
Hack Smarter: Sliver C2 Pentesting and Evasion Course now available
https://secburg.com/posts/hack-smarter-sliver-c2-course-now-available/
-
Hack Smarter: Sliver C2 Pentesting and Evasion Course now available
https://secburg.com/posts/hack-smarter-sliver-c2-course-now-available/
-
**‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC)**
"_The Southern Levant saw significant use of silver during the final stages of the Middle Bronze Age, with the first silver-currency hoards appearing at Shiloh and Gezer (~ 1650/1600–1600/1550 BC), predating other regions. Although silver was temporarily replaced by gold in the Late Bronze Age, it re-emerged as the dominant form of money by the Late Bronze Age IIB, ~ 1300 BC, a status it retained until the end of the Iron Age (~ 600 BC), despite occasional shortages._"
Eshel, T. ‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC). J World Prehist 38, 5 (2025). https://doi.org/10.1007/s10963-025-09191-7.
#OpenAccess #OA #Article #Archaeology #Archaeodons #History #BronzeAge #IronAge #Sliver #Money #Levant #NearEast #Academia @archaeodons
-
**‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC)**
"_The Southern Levant saw significant use of silver during the final stages of the Middle Bronze Age, with the first silver-currency hoards appearing at Shiloh and Gezer (~ 1650/1600–1600/1550 BC), predating other regions. Although silver was temporarily replaced by gold in the Late Bronze Age, it re-emerged as the dominant form of money by the Late Bronze Age IIB, ~ 1300 BC, a status it retained until the end of the Iron Age (~ 600 BC), despite occasional shortages._"
Eshel, T. ‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC). J World Prehist 38, 5 (2025). https://doi.org/10.1007/s10963-025-09191-7.
#OpenAccess #OA #Article #Archaeology #Archaeodons #History #BronzeAge #IronAge #Sliver #Money #Levant #NearEast #Academia @archaeodons
-
**‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC)**
"_The Southern Levant saw significant use of silver during the final stages of the Middle Bronze Age, with the first silver-currency hoards appearing at Shiloh and Gezer (~ 1650/1600–1600/1550 BC), predating other regions. Although silver was temporarily replaced by gold in the Late Bronze Age, it re-emerged as the dominant form of money by the Late Bronze Age IIB, ~ 1300 BC, a status it retained until the end of the Iron Age (~ 600 BC), despite occasional shortages._"
Eshel, T. ‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC). J World Prehist 38, 5 (2025). https://doi.org/10.1007/s10963-025-09191-7.
#OpenAccess #OA #Article #Archaeology #Archaeodons #History #BronzeAge #IronAge #Sliver #Money #Levant #NearEast #Academia @archaeodons
-
**‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC)**
"_The Southern Levant saw significant use of silver during the final stages of the Middle Bronze Age, with the first silver-currency hoards appearing at Shiloh and Gezer (~ 1650/1600–1600/1550 BC), predating other regions. Although silver was temporarily replaced by gold in the Late Bronze Age, it re-emerged as the dominant form of money by the Late Bronze Age IIB, ~ 1300 BC, a status it retained until the end of the Iron Age (~ 600 BC), despite occasional shortages._"
Eshel, T. ‘Keseph’: The Use of Silver Money in the Southern Levant from the Middle Bronze Age to the End of the Iron Age (~ 2000–600 BC). J World Prehist 38, 5 (2025). https://doi.org/10.1007/s10963-025-09191-7.
#OpenAccess #OA #Article #Archaeology #Archaeodons #History #BronzeAge #IronAge #Sliver #Money #Levant #NearEast #Academia @archaeodons
-
Nirvana’s “Sliver” is an eerie reversal of Marx’s adage that history repeats itself “first as tragedy, then as farce.” The song was always a deceptively rich tapestry, but time and fate have since added a layer of meaning even Kurt Cobain couldn’t have anticipated. What began as a tongue-in-cheek parody of childhood loneliness now reads like a ghostly premonition.
#Sliver #Nirvana #Rock #Song #Lyrics #Analysis
https://songreading.wordpress.com/2025/06/27/sliver/ -
Nirvana’s “Sliver” is an eerie reversal of Marx’s adage that history repeats itself “first as tragedy, then as farce.” The song was always a deceptively rich tapestry, but time and fate have since added a layer of meaning even Kurt Cobain couldn’t have anticipated. What began as a tongue-in-cheek parody of childhood loneliness now reads like a ghostly premonition.
#Sliver #Nirvana #Rock #Song #Lyrics #Analysis
https://songreading.wordpress.com/2025/06/27/sliver/ -
Nirvana’s “Sliver” is an eerie reversal of Marx’s adage that history repeats itself “first as tragedy, then as farce.” The song was always a deceptively rich tapestry, but time and fate have since added a layer of meaning even Kurt Cobain couldn’t have anticipated. What began as a tongue-in-cheek parody of childhood loneliness now reads like a ghostly premonition.
#Sliver #Nirvana #Rock #Song #Lyrics #Analysis
https://songreading.wordpress.com/2025/06/27/sliver/ -
Nirvana’s “Sliver” is an eerie reversal of Marx’s adage that history repeats itself “first as tragedy, then as farce.” The song was always a deceptively rich tapestry, but time and fate have since added a layer of meaning even Kurt Cobain couldn’t have anticipated. What began as a tongue-in-cheek parody of childhood loneliness now reads like a ghostly premonition.
#Sliver #Nirvana #Rock #Song #Lyrics #Analysis
https://songreading.wordpress.com/2025/06/27/sliver/ -
Инструменты атакующих в 2023–2024 годах
На конференции OFFZONE 2024, которая прошла в Москве в культурном центре ЗИЛ 22–23 августа, выступил наш сотрудник Семён Рогачёв, руководитель отдела реагирования на инциденты. Он рассказал, какие инструменты сегодня чаще всего используются в кибератаках на российскую Linux- и Windows-инфраструктуру, и объяснил, как эффективно отлавливать и отражать подобные атаки. Мы написали текст по мотивам этого доклада, обогатив его данными за конец 2024 года. Статья будет полезна для тех, кто занимается пентестами и реагированием на инциденты.
https://habr.com/ru/companies/bastion/articles/862168/
#GSocket #инструменты_хакеров #инструменты_для_атак_на_Linux #инструменты_для_атак_на_Windows #реагирование_на_инциденты #soc #расследование_инцидентов #Sliver #разведка_угроз #кибератаки_в_2024
-
Инструменты атакующих в 2023–2024 годах
На конференции OFFZONE 2024, которая прошла в Москве в культурном центре ЗИЛ 22–23 августа, выступил наш сотрудник Семён Рогачёв, руководитель отдела реагирования на инциденты. Он рассказал, какие инструменты сегодня чаще всего используются в кибератаках на российскую Linux- и Windows-инфраструктуру, и объяснил, как эффективно отлавливать и отражать подобные атаки. Мы написали текст по мотивам этого доклада, обогатив его данными за конец 2024 года. Статья будет полезна для тех, кто занимается пентестами и реагированием на инциденты.
https://habr.com/ru/companies/bastion/articles/862168/
#GSocket #инструменты_хакеров #инструменты_для_атак_на_Linux #инструменты_для_атак_на_Windows #реагирование_на_инциденты #soc #расследование_инцидентов #Sliver #разведка_угроз #кибератаки_в_2024
-
Инструменты атакующих в 2023–2024 годах
На конференции OFFZONE 2024, которая прошла в Москве в культурном центре ЗИЛ 22–23 августа, выступил наш сотрудник Семён Рогачёв, руководитель отдела реагирования на инциденты. Он рассказал, какие инструменты сегодня чаще всего используются в кибератаках на российскую Linux- и Windows-инфраструктуру, и объяснил, как эффективно отлавливать и отражать подобные атаки. Мы написали текст по мотивам этого доклада, обогатив его данными за конец 2024 года. Статья будет полезна для тех, кто занимается пентестами и реагированием на инциденты.
https://habr.com/ru/companies/bastion/articles/862168/
#GSocket #инструменты_хакеров #инструменты_для_атак_на_Linux #инструменты_для_атак_на_Windows #реагирование_на_инциденты #soc #расследование_инцидентов #Sliver #разведка_угроз #кибератаки_в_2024
-
Play Ransomware Engagement
Unit 42 has identified Jumpy Pisces, a North Korean state-sponsored threat group, as a key player in a recent ransomware incident. The group appears to be collaborating with the Play ransomware group, marking a shift in their tactics. This is the first observed instance of Jumpy Pisces using existing ransomware infrastructure, potentially acting as an initial access broker or an affiliate. The attack timeline spans from May to September 2024, involving initial access through a compromised user account, lateral movement, and persistence using tools like Sliver and DTrack. The incident culminated in the deployment of Play ransomware in early September. This collaboration signals deeper involvement of North Korean threat actors in the broader ransomware landscape, potentially leading to more widespread and damaging attacks globally.
Pulse ID: 67225f8455c324e956f9ebc1
Pulse Link: https://otx.alienvault.com/pulse/67225f8455c324e956f9ebc1
Pulse Author: AlienVault
Created: 2024-10-30 16:32:04Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #ICS #InfoSec #Korea #NorthKorea #OTX #OpenThreatExchange #PlayRansomware #RAT #RansomWare #Sliver #Unit42 #bot #AlienVault
-
MimiStick — imitators of Sticky Werewolf
F.A.C.C.T. Threat Intelligence discovered a malicious file targeting Russian defense industry enterprises. Initially thought to be the work of Sticky Werewolf, further analysis revealed a new threat actor named MimiStick. The attack used a PDF lure mimicking a letter from the Russian Ministry of Labor. The malware employed a multi-stage infection chain, ultimately deploying a Sliver implant. Later findings confirmed the campaign was indeed Sticky Werewolf, who had expanded their toolkit to include Sliver implant alongside their existing Quasar RAT. The group registered multiple domains, including one impersonating the Ministry of Labor, likely for future phishing campaigns.
Pulse ID: 66f6e5caacbbdd830c3f1c8c
Pulse Link: https://otx.alienvault.com/pulse/66f6e5caacbbdd830c3f1c8c
Pulse Author: AlienVault
Created: 2024-09-27 17:05:14Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Malware #Mimic #OTX #OpenThreatExchange #PDF #Phishing #RAT #Russia #Sliver #StickyWerewolf #bot #AlienVault
-
Threat Actors’ Toolkit: Leveraging Sliver, PoshC2 & Batch Scripts
#PoshC2 #Sliver
https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/ -
Threat Actors’ Toolkit: Leveraging Sliver, PoshC2 & Batch Scripts
#PoshC2 #Sliver
https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/ -
Threat Actors’ Toolkit: Leveraging Sliver, PoshC2 & Batch Scripts
#PoshC2 #Sliver
https://thedfirreport.com/2024/08/12/threat-actors-toolkit-leveraging-sliver-poshc2-batch-scripts/ -
Scopri il testo della canzone “Sliver” di Nirvana
#Nirvana #Sliver
https://daletra.online/nirvana/testi/sliver.html -
Scopri il testo della canzone “Sliver” di Nirvana
#Nirvana #Sliver
https://daletra.online/nirvana/testi/sliver.html -
Scopri il testo della canzone “Sliver” di Nirvana
#Nirvana #Sliver
https://daletra.online/nirvana/testi/sliver.html -
Auch von uns noch ein #Kommentar zu Donald #Trump: … nein.
Aber natürlich zu Joe #Biden:
Noch am Tag vor dem "Vorfall" (#Medien …) hat der alte Mann vor seinen jubelnden Anhängern gegen "#Donald" gehetzt, aber nachdem letzterem dann fast "erfolgreich" nach dem #Leben getrachtet wurde, dauerte es nur Minuten bis sich #Grandpa #Joe plötzlich doch medienwirksam "Sorgen" um die #Gesundheit seines #Duzrivalen machte. 🤔
-
Auch von uns noch ein #Kommentar zu Donald #Trump: … nein.
Aber natürlich zu Joe #Biden:
Noch am Tag vor dem "Vorfall" (#Medien …) hat der alte Mann vor seinen jubelnden Anhängern gegen "#Donald" gehetzt, aber nachdem letzterem dann fast "erfolgreich" nach dem #Leben getrachtet wurde, dauerte es nur Minuten bis sich #Grandpa #Joe plötzlich doch medienwirksam "Sorgen" um die #Gesundheit seines #Duzrivalen machte. 🤔
-
Auch von uns noch ein #Kommentar zu Donald #Trump: … nein.
Aber natürlich zu Joe #Biden:
Noch am Tag vor dem "Vorfall" (#Medien …) hat der alte Mann vor seinen jubelnden Anhängern gegen "#Donald" gehetzt, aber nachdem letzterem dann fast "erfolgreich" nach dem #Leben getrachtet wurde, dauerte es nur Minuten bis sich #Grandpa #Joe plötzlich doch medienwirksam "Sorgen" um die #Gesundheit seines #Duzrivalen machte. 🤔
-
Voir les paroles de la chanson “Sliver” de Nirvana
#Nirvana #Sliver
https://daletra.art/nirvana/paroles/sliver.html -
Voir les paroles de la chanson “Sliver” de Nirvana
#Nirvana #Sliver
https://daletra.art/nirvana/paroles/sliver.html -
Voir les paroles de la chanson “Sliver” de Nirvana
#Nirvana #Sliver
https://daletra.art/nirvana/paroles/sliver.html -
Nirvana - Sliver (Official Music Video) - YouTube
https://www.youtube.com/watch?v=QECJ9pCyhns “#Nirvana #Remastered #Sliver” おれがはじめて買ったNirvanaのシングル。当時はレコードプレーヤーも持ってた。その頃サラレーベルとか大量のダンスミュージックとかレコードしかリリースが無いうえに買わないと聴けない時代だったのでレコードプレーヤーはけっこう必要だった。その後引っ越しとかレコードに対する物欲がなくなりディスク・ユニオンにレコードほとんど売った。プレーヤーもオーディオユニオンに売った #YouTube
-
‘Sliver’ Is Mandatory Midnight Movie Viewing for Any ‘Basic Instinct’ Fan
#IndieWire #BestOf #Features #IndieWireAfterDark #MidnightMovies #SharonStone #Sliverhttps://www.indiewire.com/features/best-of/sliver-midnight-movie-sharon-stone-1235011287/
-
‘Sliver’ Is Mandatory Midnight Movie Viewing for Any ‘Basic Instinct’ Fan
#IndieWire #BestOf #Features #IndieWireAfterDark #MidnightMovies #SharonStone #Sliverhttps://www.indiewire.com/features/best-of/sliver-midnight-movie-sharon-stone-1235011287/
-
‘Sliver’ Is Mandatory Midnight Movie Viewing for Any ‘Basic Instinct’ Fan
#IndieWire #BestOf #Features #IndieWireAfterDark #MidnightMovies #SharonStone #Sliverhttps://www.indiewire.com/features/best-of/sliver-midnight-movie-sharon-stone-1235011287/
-
Entdecken Sie den Text des Liedes “Sliver” von Nirvana
#Nirvana #Sliver
https://daletra.top/nirvana/liedtexte/sliver.html -
Hunting for a Sliver in a haystack - https://www.huntandhackett.com/blog/hunting-for-a-sliver #redteam #sliver
-
Hunting for a Sliver in a haystack - https://www.huntandhackett.com/blog/hunting-for-a-sliver #redteam #sliver
-
Hunting for a Sliver in a haystack - https://www.huntandhackett.com/blog/hunting-for-a-sliver #redteam #sliver
-
@jeromesegura Here's another #Sliver C2 server on 94.156.65.98:8443. It's also on @abuse_ch ThreatFox
https://threatfox.abuse.ch/ioc/1252442/This second Sliver C2 has the same JA3/JA3S as the previous one.
-
@jeromesegura Here's another #Sliver C2 server on 94.156.65.98:8443. It's also on @abuse_ch ThreatFox
https://threatfox.abuse.ch/ioc/1252442/This second Sliver C2 has the same JA3/JA3S as the previous one.
-
@jeromesegura Here's another #Sliver C2 server on 94.156.65.98:8443. It's also on @abuse_ch ThreatFox
https://threatfox.abuse.ch/ioc/1252442/This second Sliver C2 has the same JA3/JA3S as the previous one.