#threatresponseunit — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatresponseunit, aggregated by home.social.
-
LummaC2 Malware and Malicious Chrome Extension Delivered
In August 2024, eSentire's Threat Response Unit observed a sophisticated attack involving LummaC2 stealer malware and a malicious Google Chrome browser extension. The attack leveraged DLL side-loading to execute a loader delivering the malware and a PowerShell script that installed the extension. The extension manipulated browser activities, stole data like credentials and crypto wallets, and enabled remote control of infected systems. The infection chain showcased evasive tactics and the ability to dynamically alter web content, highlighting the importance of robust endpoint security, security awareness training, and secure software configurations.
Pulse ID: 66dec11ad9c488b7b2a839cb
Pulse Link: https://otx.alienvault.com/pulse/66dec11ad9c488b7b2a839cb
Pulse Author: AlienVault
Created: 2024-09-09 09:34:18Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Browser #Chrome #ChromeExtension #CyberSecurity #Endpoint #Google #ICS #InfoSec #LummaC2 #Mac #Malware #OTX #OpenThreatExchange #PowerShell #RAT #ThreatResponseUnit #bot #eSentire #AlienVault
-
Blind Eagle's North American Journey
The eSentire Threat Response Unit (TRU) recently observed the Blind Eagle threat actor targeting the manufacturing industry in North America. The actor used phishing emails containing malicious VBS files that delivered the Ande Loader, which then deployed Remcos RAT and NjRAT payloads. Technical analysis shows Blind Eagle leveraging crypters developed by threat actors known as Roda and Pjoao1578. The campaign targeted Spanish-speaking users at manufacturing companies. eSentire recommends implementing EDR solutions and security awareness training to help defend against Blind Eagle.
Pulse ID: 65f420f93280cbf7e41d2847
Pulse Link: https://otx.alienvault.com/pulse/65f420f93280cbf7e41d2847
Pulse Author: AlienVault
Created: 2024-03-15 10:20:41Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #NorthAmerica #RAT #Phishing #BlindEagle #ThreatResponseUnit #VBS #Manufacturing #eSentire #Email #EDR #RemcosRat #Remcos #AlienVault
-
WorkersDevBackdoor Delivered via Malvertising
In November 2023, eSentire’s Threat Response Unit (TRU) detected WorkersDevBackdoor malware impacting a customer in business services industry. This malware spreads through malicious online ads, tricking users into downloading it by mimicking legitimate software. Once installed, it secretly collects sensitive information and provides backdoor access to the infected system.
Pulse ID: 65a50837dcd86509d659545d
Pulse Link: https://otx.alienvault.com/pulse/65a50837dcd86509d659545d
Pulse Author: AlienVault
Created: 2024-01-15 10:25:59Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #BackDoor #Malvertising #ThreatResponseUnit #eSentire #Mimic #AlienVault
-
WorkersDevBackdoor Delivered via Malvertising
In November 2023, eSentire’s Threat Response Unit (TRU) detected WorkersDevBackdoor malware impacting a customer in business services industry. This malware spreads through malicious online ads, tricking users into downloading it by mimicking legitimate software. Once installed, it secretly collects sensitive information and provides backdoor access to the infected system.
Pulse ID: 65a50838a416d4a7f488d1a8
Pulse Link: https://otx.alienvault.com/pulse/65a50838a416d4a7f488d1a8
Pulse Author: AlienVault
Created: 2024-01-15 10:26:00Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #BackDoor #Malvertising #ThreatResponseUnit #eSentire #Mimic #AlienVault