Month: June 2019

GlobeImposter 2.0 Encrypted Almost All Systems in Auburn Food Bank

Delaware, USA ā€“ June 11, 2019 ā€“ The attack occurred on June 5 in the middle of the night, when there were no employees in the office of the non-profit organization. Only one computer remained unencrypted which now is used as a server to partially maintain operations of the organization. Auburn Food Bank provides relief […]

Read More
Multiple APT Groups Use Updated ICEFOG Malware

Delaware, USA ā€“ June 10, 2019 ā€“ ICEFOG APT disappeared from the radar of researchers in 2013 after Kaspersky Lab experts revealed the activities of the group, but their custom malware is still used by multiple Chinese APT groups in highly targeted cyber espionage campaigns. At the CONFidence cybersecurity conference, Chi-en Shen, FireEyeā€™s senior researcher, […]

Read More
MuddyWater Uses New Vectors to Attack Telecoms and Governmental Entities

Delaware, USA ā€“ June 7, 2019 ā€“ Iranian APT group conducts cyber espionage campaign targeting organizations in the telecommunication sector and governmental entities in the Middle Eastern and Middle Asian countries. ClearSky researchers observed the latest activity of the MuddyWater group and discovered new tricks used to infect victims. In the arsenal of the group […]

Read More
Metasploit Team Develops Module to Exploit BlueKeep Vulnerability

Delaware, USA ā€“ June 5, 2019 ā€“ Every day we are approaching WannaCry-like outbreak, as more and more information becomes available about the CVE-2019-0708 vulnerability aka BlueKeep. Reverse engineer Sean Dillon (ZĒÉ¹osum0x0) developed a module for the Metasploit pentesting framework which exploits BlueKeep flaw to achieve remote code execution. The module allows the researcher to […]

Read More
BlackSquid Malware Targets Web Servers to Mine Monero

Delaware, USA ā€“ June 4, 2019 ā€“ Malware attacks not only the Web servers but also network drives and removable drives. Experts of Trend Micro analyzed new malware family and discovered that BlackSquid uses seven exploits to spread Monero miner. In the arsenal of malware, there are exploits for bugs in Rejetto HFS (CVE-2014-6287), Apache […]

Read More
GandCrab Authors Go Out of Business

Delaware, USA ā€“ June 3, 2019 ā€“ Appeared at the beginning of last year, the Ransomware-as-a-Service platform GandCrab quickly gained popularity and became a leader in the number of ā€œcustomersā€. According to the adversaries’ post on the popular underground forum Exploit.in, for the sixteen months the victims paid about $2 billion for decrypting their data, […]

Read More