#truebot — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #truebot, aggregated by home.social.
-
#Cybersecurity agencies have warned about the emergence of new variants of the #TrueBot #malware. This enhanced #threat is now targeting companies in the U.S. and Canada. https://tchlp.com/46AwBmt
-
#Cybersecurity agencies have warned about the emergence of new variants of the #TrueBot #malware. This enhanced #threat is now targeting companies in the U.S. and Canada. https://tchlp.com/46AwBmt
-
Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: https://news.sophos.com/en-us/2021/12/02/two-flavors-of-tor2mine-miner-dig-deep-into-networks-with-powershell-vbscript/), and #Mirai (a #botnet #worm).
One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.
5/6
-
Some of the final payloads overlap with previously-reported threats, such as #Truebot (#downloader, often linked to Cl0p #ransomware), #Buhti (ransomware), #MoneroOcean (a #coinminer, discussed here: https://news.sophos.com/en-us/2021/12/02/two-flavors-of-tor2mine-miner-dig-deep-into-networks-with-powershell-vbscript/), and #Mirai (a #botnet #worm).
One such example of a #miner, shown in the screenshot below, details the commands to terminate the processes and services used by other, competing malicious miners before launching their own #Monero (#XMR) mining software. This cynical form of 'capture the flag' is commonplace behavior among the threat actor groups who deploy and maintain hostile miners.
5/6
-
Critical RCE in PaperCut (printing software) - already exploited in the wild 🚨
🔗 https://www.papercut.com/kb/Main/PO-1216-and-PO-1219Yesterday Sophos detected and responded to this activity, here's some threat hunting guidance:
- Review process execution from PaperCut (pc-app.exe)
- Check for PowerShell network connection to windowservicecemter[.]com
- Review for malicious Dual-Use Agent Installations (Atera RMM)
The C2 Server hosting the post-compromise tools was also hosting #TrueBot malware a few days. TrueBot has previously been observed prior to #CLOP ransomware 🤔
-
Critical RCE in PaperCut (printing software) - already exploited in the wild 🚨
🔗 https://www.papercut.com/kb/Main/PO-1216-and-PO-1219Yesterday Sophos detected and responded to this activity, here's some threat hunting guidance:
- Review process execution from PaperCut (pc-app.exe)
- Check for PowerShell network connection to windowservicecemter[.]com
- Review for malicious Dual-Use Agent Installations (Atera RMM)
The C2 Server hosting the post-compromise tools was also hosting #TrueBot malware a few days. TrueBot has previously been observed prior to #CLOP ransomware 🤔
-
Some analysis from my team and the Huntress Threat ops folks on recent exploitation of #GoanywhereMFT software, with a link to #Truebot malware and potential #ransomware deployment:
https://www.huntress.com/blog/investigating-intrusions-from-intriguing-exploits -
Some analysis from my team and the Huntress Threat ops folks on recent exploitation of #GoanywhereMFT software, with a link to #Truebot malware and potential #ransomware deployment:
https://www.huntress.com/blog/investigating-intrusions-from-intriguing-exploits