home.social

#threatanalysis — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #threatanalysis, aggregated by home.social.

fetched live
  1. Tried to book a bar. Ended up reverse engineering a malware campaign instead.

    A fake "Cloudflare verify" page copied an obfuscated PowerShell loader to my clipboard. So I broke it down:

    XOR-obfuscated script
    Payload delivery
    RedCap infostealer analysis
    REMnux, Ghidra & Hybrid Analysis

    Also watched the infrastructure get taken down mid-write-up.

    First time doing any RE

    blog.michaelrbparker.com/post/

    (Still haven't booked that drink.)

    #CyberSecurity #MalwareAnalysis #ThreatAnalysis

  2. Threats have been made against me by gamblers on Polymarket regarding a rewrite of an Iran missile story. This situation raises serious concerns about the integrity of discourse in betting environments. #OSINT #ThreatAnalysis

  3. 🔥The "Kim" leak is an intelligence goldmine.

    For analysts: We’ve got an unprecedented look into a DPRK threat actor's playbook. This isn't just about known tactics like credential theft and phishing. Our analysis shows a strategic pivot to include Taiwanese developer and government networks, revealing a clear geographical expansion of North Korea's cyber interests.

    For defenders: We've mapped the full scope of this threat—from custom Linux rootkits to particular targets like PKI infrastructure and specific tools like NASM and ocrmypdf. Our report provides defensive recommendations and specific Indicators of Compromise (IOCs), so your team can detect and block this persistent, infrastructure-centric campaign.

    Get the full technical breakdown and all the IOCs in our new post.

    🔗dti.domaintools.com/inside-the

    #ThreatIntelligence #Cybersecurity #NationStateAPT #Kimsuky #ThreatAnalysis #DFIR #InfoSec

  4. For cybersecurity practitioners looking to stay ahead of the curve, this week's reading list is for you collated by @neurovagrant. Dive into new research from Black Hat and DEF CON to explore detailed investigations into cybercriminal groups like VexTrio (💡@InfobloxThreatIntel) and learn from the experiences of a Kaseya hacker (🔦Analyst1). Finally, get grounded perspectives on AI's role for both defenders and attackers.

    The list also highlights important findings on attacker behavior (⚠️ @greynoise), cloud threat hunting (👀Recorded Future), and vulnerabilities in AI agents. Whether you're in the trenches or looking for your next role, these resources offer valuable insights to help you navigate a challenging landscape.

    Learn More: dti.domaintools.com/cybersecur

    #cybersecurity #infosec #threatintelligence #blackhat #defcon #ransomware #cloudsecurity #AI #threatanalysis #cybercrime

  5. WAF (гав-гав): гибкая настройка пользовательских правил PT AF PRO

    Разберёмся, как грамотно (хотелось бы так) настраивать пользовательские правила в Positive Technologies Application Firewall, чтобы при виде атаки ваша защита не превратилась в уязвимую "истеричку". Расскажем про ключевые директивы, покажем примеры из реальной практики и обоснуем каждый шаг.

    habr.com/ru/articles/916434/

    #информационная_безопасность #кибербезопасность #devsecops #threatanalysis #application_security #appsec #positive_technologies

  6. Реализация атаки

    Данная научная публикация посвящена анализу кибератаки с применением широко признанных фреймворков: MITRE ATT&CK, MITRE D3FEND , Cyber Kill Chain и количественной оценки CVSS , каждый из которых представляет уникальную точку зрения на тактики, техники и поведенческие паттерны злоумышленников. В исследовании акцент сделан на синергетическом эффекте , достигаемом при комплексном применении этих моделей.

    habr.com/ru/articles/909562/

    #информационная_безопасность #кибербезопасность #threatanalysis #threatintelligence #mitre_attack #mitre_d3fend #redteam #blueteam #soc #cyberkill_chain

  7. Успешная атака по кусочкам: тестируем фреймворки кибербезопастности MITRE ATT&CK и Cyber Kill Chain

    Статья напраленна на анализ кибератаки, основанный на использовании всемиизвестными фрэймворками: MITRE ATT&CK и Cyber Kill Chain . Публикация напасана с целью, рассматреть, как эти модели дополняют друг друга, помогая выявлять уязвимости в защите, улучшить процессы обнаружения и реагирования на угрозы. Статья будет полезна специалистам по информационной безопасности, аналитикам угроз и всем, кто интересуется современными подходами к анализу кибератак.

    habr.com/ru/articles/886972/

    #MITRE_ATTACK #CyberKillChain #ИнформационнаяБезопасность #кибербезопасность #ThreatAnalysis #ThreatIntelligence #SOC #redteam #blueteam #IncidentResponse

  8. I saw Raspberry PI jumped on the AI bandwagon and found myself reflexively looking for jokes:

    raspberrypi.com/news/raspberry

    But then I recalled a humbling convo with an army veteran who had fought in Iraq. Someone had made a comment suggesting that the insurgents were stupid, basing this assumption on the fact that their technology was less advanced than what the U.S. military possessed. My friend's response was pointed: those insurgents were highly effective at using what was available when it mattered most

    With little more than a map, a compass, and a basic understanding of trigonometry, they were able to calculate distances to targets using techniques like the "string method." By hanging a string of known length from a piece of debris and measuring the angle between the string and the line of sight to the target, they could determine the distance using the tangent function. These calculated distances, combined with an understanding of angles and elevations, allowed them to devise effective firing solutions, even without access to advanced targeting systems or sophisticated weaponry.

    I share this as a reminder that necessity often drives innovation, and the same principle applies to the use of AI in infosec, OSINT research and emerging threats. Just as the insurgents in Iraq were able to leverage basic tools and mathematical concepts to great effect, shouldn't we expect the same with access to tools like the Raspberry Pi AI Kit to find ways to harness its capabilities in unexpected and impactful ways?

    #ai #raspberrypi #infosec #osint #redteam #threatanalysis

  9. New Episode: hpr4081 :: The Oh No! News.

    Hosted by Some Guy On The Internet on 2024-03-25 is flagged as Clean and is released under a CC-BY-SA license.

    Tags: #OhNoNews, #ThreatAnalysis, #QNAP.

    hackerpublicradio.org/eps/hpr4

  10. New Episode: hpr3997 :: The Oh No! News.

    Hosted by Some Guy On The Internet on 2023-11-28 is flagged as Clean and is released under a CC-BY-SA license.

    Tags: #Threatanalysis, #InfoSec

    hackerpublicradio.org/eps/hpr3

  11. "🔍 Dive Deep into SpyNote: The Stealthy Android Spyware 📱🕵️‍♂️"

    SpyNote, a notorious Android spyware, has been making waves in the cybersecurity realm. This malware, primarily spread via smishing, aims to snoop on users, capturing a plethora of personal data. Some intriguing features of SpyNote include:

    🔹 Stealth Mode: Once installed, it remains hidden, making it challenging for users to detect.
    🔹 Diehard Services: It employs unique services that restart themselves, ensuring the malware remains active.
    🔹 Phone Call Recording: SpyNote can record incoming calls, sending the recordings to its Command & Control server.
    🔹 Screenshots: Using the MediaProjection API, it captures images of the user's phone screen.
    🔹 Keylogging: All keystrokes are logged, capturing sensitive data like passwords.
    🔹 Challenging Uninstallation: The spyware makes its removal extremely tricky, often leaving victims with the sole option of a factory reset.

    Stay vigilant and ensure your devices are protected against such threats. 🛡️🔒

    Source: F-Secure Blog

    Tags: #SpyNote #AndroidMalware #Spyware #CyberSecurity #MobileSecurity #InfoSec #ThreatAnalysis

    Author: Amit Tambe

  12. 𝗨𝗻𝗹𝗼𝗰𝗸𝗶𝗻𝗴 𝘁𝗵𝗲 𝗣𝗼𝘄𝗲𝗿 𝗼𝗳 𝗖𝘆𝗯𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 𝗜𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲 𝘄𝗶𝘁𝗵 𝗔𝘇𝘂𝗿𝗲 𝗢𝗽𝗲𝗻𝗔𝗜 𝗮𝗻𝗱 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗗𝗲𝗳𝗲𝗻𝗱𝗲𝗿 𝗧𝗵𝗿𝗲𝗮𝘁 𝗜𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲

    I'm excited to share my recent side project! 💻✨

    I've been exploring the incredible potential of a simple web app for engaging in conversations with threat intelligence data. In my case, I harnessed the power of Microsoft Defender Threat Intelligence.

    All the details are in the following blog post:

    medium.com/@antonio.formato/ch

    I'd love to hear your thoughts and feedback.

    This project has been an eye-opener for me, demonstrating how Generative AI can be a game-changer in the realm of cybersecurity. I hope it serves as a valuable starting point for other innovative applications in the cybersecurity space.

    Let's connect and discuss how technology can empower us in the ever-evolving world of cybersecurity. 🌐🛡️

    #azure #azureopenai #llm #chatbot #threatintelligence #ti #microsoft #microsoftdefenderthreatintelligence #mdti #cyber #cybersecurity #soc #threatactors #threatanalysis #ttp #ioc #securityanalyst #microsoftsecurity #largelanguagemodel #gpt4 #azurelogicapps #logicapps #cognitiveservices #dev #chat

  13. "🐰 BunnyLoader Unleashed: The Newest Kid on the Malware Block 🐰"

    In a recent discovery, Zscaler ThreatLabz stumbled upon a new Malware-as-a-Service (MaaS) threat named "BunnyLoader" being peddled on various forums. This nefarious service offers a plethora of malicious functionalities including downloading and executing a second-stage payload, pilfering browser credentials and system information, keylogging, and even cryptocurrency theft through clipboard manipulation. 🕵️‍♀️💻

    The malware, written in C/C++, is sold for a lifetime price of $250 and is under rapid development with multiple feature updates and bug fixes. It employs various anti-sandbox techniques during its attack sequence to evade detection and has a fileless loader feature which executes further malware stages in memory. BunnyLoader's C2 panel allows the threat actor to control infected machines remotely, showcasing a list of various tasks including keylogging, credential theft, and remote command execution among others. 🛑🔐

    The detailed technical analysis reveals how BunnyLoader maintains persistence, performs anti-VM techniques, registers with the C2 server, and executes its core malicious tasks. The malware also harbors a clipper module to replace cryptocurrency addresses in a victim's clipboard with addresses controlled by the threat actor, targeting multiple cryptocurrencies like Bitcoin, Ethereum, and Monero. 🪙💸

    The article is a comprehensive dive into the technical intricacies of BunnyLoader, shedding light on its modus operandi and the potential threat it poses to individuals and organizations alike. 🧐🔍

    Source: Zscaler ThreatLabz

    Tags: #BunnyLoader #MalwareAsAService #CyberSecurity #ThreatAnalysis #Malware #CryptocurrencyTheft #Zscaler #ThreatLabz #InfoSec

    Authors: NIRAJ SHIVTARKAR, SATYAM SINGH

  14. 🔍 Technical Analysis: Smoke Loader Malware Leveraging Wi-Fi Access Points for Geolocation

    📅 Date: August 28, 2023
    🖋️ Author: Eswar

    📌 Tags: #Malware #SmokeLoader #Geolocation #Wi-FiScanning #Cybersecurity

    🛠️ The Smoke Loader malware, recently discovered, employs a novel technique to locate infected systems through Wi-Fi access points and Google's Geolocation API. This technical analysis sheds light on the key mechanisms used by this malware.

    🔗 System Location Identification:
    The malware, also known as "Whiffy Recon," utilizes a custom Wi-Fi scanning tool to identify an infected system's precise coordinates using nearby Wi-Fi access points. This is achieved by leveraging the Windows WLANSVC service and Google's Geolocation API.

    🔒 Infection Process:
    The malware checks the existence of the WLANSVC service, regardless of its operational status. If the service exists, the malware creates a wlan.lnk shortcut in the Startup folder pointing to the malware's original location. On the other hand, if the service is absent, the malware terminates execution.

    🔄 Malware Loops:
    There are two loops in the malware's execution flow:

    1. The first loop checks for the presence of the file %APPDATA%\wlan\str-12.bin. If valid parameters are found, the malware proceeds to the next loop for Wi-Fi scanning.
    2. In the absence of the file, the malware registers the bot with the Command and Control (C2) server, sending a JSON payload in an HTTPS POST request with a hard-coded UUID for bot identification.

    📥 Registration and Communication:
    Upon successful registration, the server responds with a secret UUID, replacing the initial bot ID for future requests. Both UUIDs are stored in the str-12.bin file. The malware then scans for Wi-Fi access points using the Windows WLAN API, sending results to Google's Geolocation API via HTTPS POST requests.

    🌐 Google Geolocation API:
    The Geolocation API provides system coordinates based on Wi-Fi access points and mobile network data. The obtained coordinates are integrated into a JSON structure along with encryption methods of access points. This data is sent to the C2 server through HTTP POST requests with Authorization UUID and specific URLs.

    🔎 Indicators of Compromise:

    Whiffy Recon sample dropped by Smoke Loader

    • MD5 hash: 009230972491f5f5079e8e86e19d5458
    • SHA256 hash: 935b44784c055a897038b2cb6f492747c0a1487f0ee3d3a39319962317cd4087

    Whiffy Recon sample dropped by Smoke Loader

    • SHA1 hash: 8532e67e1fd8441dc8ef41f5e75ee35b0d12a087

    Whiffy Recon C2 server

    • 194.87.32[.]20

    Whiffy Recon payload URL

    🛡️ Recommendations:
    Cybersecurity professionals are advised to be vigilant against Smoke Loader malware and Whiffy Recon malware. Monitoring for these indicators of compromise can aid in identifying and mitigating potential threats.

    Source: cybersecuritynews.com/smoke-lo

    #Cybersecurity #ThreatAnalysis #MalwareDetection #GeolocationTracking #WindowsMalware

  15. Too much #CTI #ThreatIntel #ThreatAnalysis hinges on how the producers of said analysis think their output will be received and interpreted by an industry/media/popularity ecosystem, instead of focusing on what matters: defending end-users and organizations from threats.

    This is why #infosec is in an unsustainable bubble, while we're rife with online "celebrities" who contribute nothing tangible to the field, and why we're losing the battle against #ThreatActors.

  16. This article by me at Forbes has now been updated with analysis from Mandiant (now part of Google Cloud), which reports Fancy Bear (APT28) has been exploiting CVE-2023-23397 since April 2022.

    "This will be a propagation event. This is an excellent tool for nation-state actors and criminals alike who will be on a bonanza in the short term" - John Hultquist, head of Mandiant Intelligence Analysis.

    #infosec #microsoft #outlook #zeroday #cve202323397 #mandiant #threatanalysis #news #russiaukrainewar

    forbes.com/sites/daveywinder/2

  17. REALLY excited to finally announce that our "Fundamentals of Cyber Investigations and Human Intelligence" class will be part of this year's trainings at #BlackHat Asia! 🎩

    @OSINTgeek and I will deliver a 2-day training on conducting in-depth online investigations by combining the disciplines of open-source intelligence ( #OSINT ), social media intelligence ( #SOCMINT ), and human intelligence ( #HUMINT ).

    We created this class with the vision to help investigators and intelligence analysts adapt to the ever-evolving complexities of online investigations. We wanted them to develop a good skill set and utilize the competitive advantage those three intelligence disciplines bring to an investigation, when combined. We have been able to do that, through our previous open, and in-house classes.

    In the meantime, we started observing an increased interest from threat hunters, threat intelligence teams, security researchers, and other related professionals that came to attend with a different motive. They wanted to understand how threat actors utilize open-source intelligence along with human intelligence in their attack kill chains. They wanted to be able to conduct a more informed analysis, increase the accuracy of their reports, and inform their security strategy.

    This year, we are once again offering this class as an open class, in Black Hat Asia 2023!! 🥹🥹

    #intelligence #training #cybersecurity #opensourceintelligence #humanintelligence #intelligenceanalysis #threatintelligence #threatintel #socialengineering #cyber #cybercrime @[email protected] @[email protected] #blackhat2023 #blackhatasia #bhasia #fraudinvestigation #lawenforcementtraining #lawenforcement #threatanalysis #investigations

  18. Nextcloud offers different layers of #encryption to #secure your enterprise data. Read this blog to support your #ThreatAnalysis and decision on how to protect your digital assets.

    nextcloud.com/blog/encryption- …pic.twitter.com/I3VNc3aKkD #nextcloud