#threatresearch — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatresearch, aggregated by home.social.
-
New.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."
Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/ @Rapid7Official #infosec #cybercrime #threatresearch #Linux
-
New.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."
Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/ @Rapid7Official #infosec #cybercrime #threatresearch #Linux
-
New.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."
Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/ @Rapid7Official #infosec #cybercrime #threatresearch #Linux
-
New.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."
Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/ @Rapid7Official #infosec #cybercrime #threatresearch #Linux
-
New.
"The standout feature of this toolkit is its depth of integration with the target environment. The ted backdoor is compiled as part of the victim’s existing HAProxy version 2.8.12. It uses its native filter API, internal memory pools, event scheduler, and process management infrastructure to intercept traffic and hide from monitoring, while genuine load balancing traffic operates as expected."
Rapid7: DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors/ @Rapid7Official #infosec #cybercrime #threatresearch #Linux
-
Note: the actor in question targets Russian organizations.
Kaspersky: Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ @Kaspersky #infosec #threatresearch #cybercrime
-
Note: the actor in question targets Russian organizations.
Kaspersky: Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ @Kaspersky #infosec #threatresearch #cybercrime
-
Note: the actor in question targets Russian organizations.
Kaspersky: Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ @Kaspersky #infosec #threatresearch #cybercrime
-
Note: the actor in question targets Russian organizations.
Kaspersky: Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ @Kaspersky #infosec #threatresearch #cybercrime
-
Note: the actor in question targets Russian organizations.
Kaspersky: Angry Birds: Toy Ghouls’ new toys https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ @Kaspersky #infosec #threatresearch #cybercrime
-
Threat actors continue to operationalize current-events lures as part of malware delivery chains.
Recent research shows a backdoor deployed via attachments themed around breaking geopolitical news, using legitimate binaries and DLL sideloading techniques for persistence.
No attribution assumptions - just a reminder that contextual relevance remains one of the most effective social engineering tools.
What controls have you found most effective against news-driven phishing?
Engage with us in the comments and follow @technadu for practical threat intelligence coverage.
Source: https://www.darktrace.com/blog/maduro-arrest-used-as-a-lure-to-deliver-backdoor
#InfoSec #ThreatResearch #MalwareTTPs #PhishingDefense #CyberOperations #ThreatDetection #TechNadu
-
Home from #LABScon23 and I know I’ll be thinking about many of these talks and the great conversations for days to come. Getting to talk a bit about the Internet presence and security of #MFT tools like #MOVEit and #GoAnywhere was an added bonus 📂☺️🗄️
-
A few months ago I posted about a DNS malware C2 we had discovered— Decoy Dog — that was based on Pupy, had been undetected for over a year, and had some inexplicable behavior. We hoped the community would easily find the infected devices based on the info we provided. No suck luck. Since then we have used DNS to learn and an astonishing amount about the operations. Once we realized Decoy Dog was more advanced than Pupy, and we saw how the actors responded to our original relesases, we went back to the binaries. Today we released an indepth technical analysis of Decoy Dog, a Pupy research data set, and a new Yara rule. This is the exec summary. Link to the full technical paper and other tidbits in the comments. #dns #theatintel #malware #decoydog #rat #c2 #infoblox #datascience #threatresearch https://blogs.infoblox.com/cyber-threat-intelligence/decoy-dog-is-no-ordinary-pupy-distinguishing-malware-via-dns/