home.social

#sophosxops — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #sophosxops, aggregated by home.social.

fetched live
  1. A year ago, Sophos X-Ops published our research into threat actor attitudes towards AI. We went into the underground forums to see what they were saying about AI.
    At the time, we found threat actors were skeptical, grappling with the same issues, problems, and concerns everyone was.
    A year later, we've returned to see what, if anything has changed. Overall, we've seen a slight shift, but the song remains the same overall: skeptical.
    Get more details in our latest report here:

    news.sophos.com/en-us/2025/01/
    #sophosxops #threatintel #ai

  2. Get ready for the new year by taking time to better understand how to prioritize your patching.

    Read understanding #CVSS part one of our two part series on “Patch Prioritization.”.

    news.sophos.com/en-us/2024/12/

    #sophosxops #threatintelligence #patching #patchprioritization

  3. Additionally, case data reveals a 3-week delay before Akira posts victim information on their leaksite. Research indicates 127 victims have been posted to their leak site over the last 6 months. Sophos X-Ops is tracking 2 active Akira threat clusters (STAC5881, STAC5397), with the STAC5397 also deploying Fog ransomware. We commonly observe them leveraging PsExec, Advanced IP Scanner, SoftPerfect Network Scanner, 7-zip, Rclone, AnyDesk, WinRAR, WInSCP and Filezilla software during intrusions.#Akira #ransomware #threatintel #Sophosxops

  4. Sophos X-Ops has just released a brand-new Active Adversary Report, covering the first six months of 2024 – a little light holiday reading, as one does. For the first time ever, data from MDR's customer-facing Incident Response team is fully incorporated with data from our dedicated Incident Response team. The result is our largest dataset ever, with 190 entries normalized across 63 fields.

    Perhaps the most startling finding of all is that abuse of LOLbins was up, way up, in the first half of the year. The AAR analysis team thought it might be a hallucination brought on by ingesting all that MDR data but... it isn't. The report has details, including what (besides RDP) is getting a workout. (Spoiler: You name it. Some of these attackers are just odd.)

    We worked on a great number of ransomware cases in 1H24, as you'd expect. What you might not expect is which ransomware brands were most often involved, especially if you follow the headlines about high-profile law-enforcement activities. The new report looks at how the scene shaped up after the February 2024 LockBit takedown and points out a data pattern that you might not have glimpsed in the usual day-to-day news coverage.

    Finally, as AAR stands on the cusp of its sixth year of data (the first AAR was published in 2021, covering 2020 and the then-new IR team), we revisited some of our older investigations -- dwell time, time-to-Active-Directory, and many more. Updated information on these topics and many more is in the report. Enjoy!

    news.sophos.com/en-us/2024/12/

    #threatintel #Sophosxops

  5. Sophos X-Ops teams are monitoring and responding to attacks against Cleo products VLTrader, Harmony, and LexiCom prior to version 5.8.0.23 in each as outlined in this advisory: support.cleo.com/hc/en-us/arti.

    Sophos MDR and Labs teams can confirm seeing 50+ unique hosts targeted by these attacks at this time.

    All observed impacted customers have a branch or operate within the North Americas, primarily the US. We note the majority of observed affected customers are retail organizations.

    Sophos MDR threat hunting currently shows the first attack on 2024-12-06 at 17:47 UTC.

    We will continue to monitor and provide updates as we have more information.

    #Sophosxops #threatintel

  6. For 5 years, Sophos has been engaged in defensive and counter-offensive operations against China-based #NationState adversaries targeting perimeter devices like #firewalls for surveillance and sabotage.

    The attacks unfolded in two waves: the first aimed to build proxy networks, often used by Chinese groups to hide further operations. The second targeted critical infrastructure in South and Southeast Asia.

    Sophos uncovered links to groups like Volt Typhoon, APT31, APT41, and Chinese educational institutions. Now, we’re sharing insights from our detailed "Pacific Rim" report to help others defend against these persistent attackers.

    Sophos X-Ops is happy to collaborate with others and share additional detailed IOCs on a case-by-case basis.
    Contact us via [email protected].

    For the full story, please see our landing page: sophos.com/en-us/content/pacif

    #Sophosxops #threatintel

  7. Last year, #SophosXOps presented research about this #EDR killing tool at Microsoft's Blue Hat conference. The kernel drivers, custom-built by the people selling this tool to ransomware gangs, had been signed with Microsoft's own WHQL certificates, lending them the appearance of legitimacy they had not earned.

    (Our prior research is here: news.sophos.com/en-us/2022/12/)

  8. Last week we released our first Active Adversary Report for 2024, covering a selection of Incident Response cases from the last half of 2023. Our analysis found that though the last half of last year was a relatively quiet time in the ongoing struggle between attackers and defenders, the good guys may not be taking full advantage of the lull.

    news.sophos.com/en-us/2024/04/

    #threatintel #Sophosxops

  9. We have recently found yet another campaign, where AuKill was deployed to attempt disabling EDR agents on the targeted system.

    The malware introduced minor changes, specifically by using a custom packer and implementing anti analysis techniques. However, in terms of core functionalities and purpose of the EDRKiller, there are no major differences between the version of AuKill we're seeing in March 2024 and the version we reported on in April 2023.

    Therefore, defenders can and should continue to be on the lookout for AuKill and follow our published guidance:

    news.sophos.com/en-us/2023/04/

    #threatintel #Sophosxops

  10. Each year, Sophos releases an annual threat report. This year, we took a different approach: rather than looking at the whole threat landscape, we focused on the biggest cybercrime threats to small and medium businesses.

    news.sophos.com/en-us/2024/03/. #sophosxops #threatintel /1

  11. We have just posted our latest research with our observations and analysis into ConnectWise ScreenConnect attacks.

    We’ve observed multiple attacks in the past 48 hours. This has included a malware that was built using the LockBit 3 ransomware builder tool leaked in 2022: this may not have originated with the actual LockBit developers.

    But we’re also seeing RATS, infostealers, password stealers and other ransomware. All of this shows that many different attackers are targeting ScreenConnect.

    Anyone using ScreenConnect should take steps to immediately isolate vulnerable servers and clients, patch them and check for any signs of compromise.

    We have extensive guidance and threat hunting material from our teams to help.

    We’ll provide updates to our blog with more information as appropriate.

    #Sophosxops #threatintel

    news.sophos.com/en-us/2024/02/

  12. While the world digests what, precisely, the LockBit takedown this week entails and how much it’s likely to kneecap the ransomware gang, we’d just like to point out how prevalent the family is – literally, what Conti was to 2021, LockBit was to 2023. Here’s a graphic from our upcoming Active Adversary Report , showing precisely how, as seen by the Sophos X-Ops Incident Response team, Conti in 2021 and LockBit in 2023 represented literally double the volume of infections of the nearest “competitors .”

    #sophosxops #threatintel #lockbit #lockbit_takedown

  13. Hey everyone. @threatresearch here on the X-Ops thread with a quick update about #Qakbot

    After last August's international takedown of infrastructure that controlled the Qakbot botnet, a lot of people – including some here at Sophos – thought we hadn't seen the last of the #spam-delivered #malware

    Unfortunately, we and others were right. Someone with access to the source code has been experimenting with new builds, making incremental changes. 1/
    #threatintel #SophosXOps

  14. Despite working for #Sophos I find articles like this fascinating. I am not a threat hunter. These articles are a real education into how attacks work and unfold. I would not want to be an admin anymore. You have your day job to do while fighting against attacks like this.

    The attacker won’t have users asking for a new mouse, fix the printer, or the server is slow. They can just concentrate on the attack. Imaging being an admin with only one job to do.

    news.sophos.com/en-us/2023/12/

    #SophosXOps

  15. From SysAid’s write up about active attacks attributed to Cl0p.

    "- Checks all running processes for any process beginning with the name “Sophos” [and only Sophos] and if found, exits.
    - If no matching processes are found, starts the user.exe malware."

    SysAid On-Prem Software customers should read and apply the update discussed to address CVE-2023-47246 Vulnerability.

    sysaid.com/blog/service-desk/o
    #Sophosxops

  16. 1. For almost a quarter of a century, Sophos has had memory scanning capabilities (searching within a process’s memory space) to combat malicious techniques. In a new article published today, the first in a series of technical thought leadership papers, we take an in-depth look at memory scanning and how it works (link follows at the end of the thread) #threatintel #sophosxops

  17. A few weeks ago, we saw a challenge posted online where a technical user was looking for the most elaborate, complex Regular Expression (eg., regex) that someone uses on a regular basis for a practical reason.

    twitter.com/timhwang/status/16

    We asked around our team of researchers, and we found what might be the largest, most complex regex anyone has ever seen: 272,816 UTF-8 characters in length, created for our Data Loss Prevention product.

    The regex is designed to detect postal addresses in files or messages transmitted over the internet, and the reason it is so long is that it can detect a large variety of international post address formats, using local languages and character sets. It can tell if someone is transmitting lists of addresses in Gaelic or Malay, Norwegian or Chinese, Russian or Finnish or Tamil.

    According to the researcher who created the regex, John Bryan, this regex is scanning a file or email every second of every day, somewhere in the world.

    It is far too large to show the entire thing on one screenshot (plus, there's some proprietary data in there), so we've generated a screenshot that highlights a few key locations within this massive regex, and that shows the entire thing in a human-viewable scale.

    So, challenge accepted, and challenge met.

    #Sophosxops

  18. In September, Sophos X-Ops found evidence in customer telemetry of a would-be ransomware actor targeting organizations running ColdFusion 11 servers. Adobe ended support for ColdFusion 11 in April 2019, and “extended” (paid) support ended in 2021—so these servers no longer get security updates. /1

    #sophosxops #threatintel

  19. The Conference on Applied Machine Learning in Information Security (CAMLIS) is being held in Arlington, Virginia this week, and the Sophos AI team will be there.

    Sophos X-Ops advocates for open research and information exchange in the cybersecurity and AI fields, and CAMLIS is a crucial componenty of our Sophos AI team’s efforts to stay on the cutting-edge of machine learning—as well as offer us a chance to showcase our own research. camlis.org /1

    #Sophosxops

  20. During a recent investigation, Sophos X-Ops discovered a trojanized Windows installer for CloudChat, an instant messaging application. Looking into this supply chain attack further, we found that the official distribution server for the application had been compromised, and delivered a Window installer modified to load an additional, malicious DLL. This DLL contained an encrypted payload that connected back to a C2 server to download and execute the next stage malware. We contacted the vendor when we found this issue, but at the time of posting haven’t received a response.

    #Sophosxops #threatintel

  21. Microsoft Tuesday released patches for 104 vulnerabilities, including 80 for Windows. Ten other product groups are also affected. Of the 104 CVEs addressed, 11 are considered Critical in severity; ten of those are in Windows, while one falls in the Microsoft Common Data Model SDK. (The Common Data Model is a metadata system for business-related data.) One CVE, an Important-severity denial-of-service issue (CVE-2023-38171), affects not only Windows but both .NET and Visual Studio.

    #threatintel #patchtuesday #Sophosxops

  22. In mid-August, the Sophos X-Ops Incident Response team was brought in to address a cyber incident impacting a telecommunications company. Shortly after, when the customer was onboarded to Sophos MDR services, a detection was generated for a service creation for the Cloudflared tunneling service from a suspicious path. The resulting investigation led Sophos MDR Ops analysts and SophosLabs researchers to uncover a backdoor leveraging a loading function similar to that previously seen within the TinyTurla backdoor.

    #ThreatIntel #TinyTurla #NotSoTinyTurla #SophosXops

  23. Sophos X-Ops is currently tracking a campaign by threat actors targeting unpatched #Citrix #NetScaler systems exposed to the internet. Our data indicates strong similarity between #attacks using CVE-2023-3519 delivering #malware and #webshells and previous attacks using a number of the same #TTPs.

    #Sophosxops #threatintel #cve20233519

  24. Under investigation: During a recent threat hunt for DLL sideloading abuse leveraging vmnat.exe, Sophos X-Ops uncovered a likely nation-state campaign targeting an organization in Southeast Asia. Aligning closely with techniques previously attributed to the Mustang Panda threat group, we unraveled a complex and sustained intrusion. 1/7

    #threatintel #Sophosxops

  25. We have just updated our Patch Tuesday posting with information on Sophos protections against reported attacks against CVE-2023-36884.

    #threatintel #Sophosxops

    news.sophos.com/en-us/2023/07/

  26. We have updated our #MoveIT blog with new information on Sophos protections and to update the community that we have seen activity against CVE-2023-36934, one of the three new vulns disclosed on July 5, 2023.

    MoveIT customers should apply the service pack released on July 5, 2023. It’s important to note if you deployed previously released patches you need to also deploy the latest July 5, 2023 service pack to be fully protected against all known and exploited vulnerabilities.

    #threatintel #Sophosxops #moveit

    news.sophos.com/en-us/2023/06/

  27. We have updated our #MOVEit posting with the latest information from Progress regarding a service-pack-style update system for all MOVEit products that fixes three new vulnerabilities discovered in older versions of MOVEit Transfer.

    news.sophos.com/en-us/2023/06/

    #threatintel #Sophosxops

  28. In our latest posting, Sophos X-Ops MDR team uses Microsoft Graph to analyze two different email compromise attacks to detail each step in the attack flow, and show that the two attacks may be related to the same (unknown) threat actor.

    Learn more about the attacks and the hunting techniques here: news.sophos.com/en-us/2023/06/

    #threatintel #Sophosxops

  29. In mid-June, Sophos identified a previously unnoted initial-access campaign targeting IT users via malicious advertising (malvertising) – one that uses interesting export forwarding and DLL pre-loading techniques to mask malicious activity, hinder analysis, and generally support its foothold once on the target network. Our colleagues at Trend are watching this adversary too, and have some thoughts on what we’re tracking as “Nitrogen,” after we observed a string in the PDB path commonly used among the samples. As we continue our own research, we are sharing early findings with the community. (1/4)

    #threatintel #sophosxops

Share on Mastodon

Enter the server where you have an account.