News

ECS Premium Log Source Pack is Released

Delaware, USA – September 4, 2019 – SOC Prime, Inc. announces the release of Premium Log Source Pack for Elastic Common Schema (ECS) that provides essential log telemetry across all 12 Tactics of MITRE ATT&CK. ECS is a specification that facilitates the analysis of data from diverse sources and provides a consistent and customizable way […]

Astaroth Malware Abuses Cloudflare Workers to Slip Behind Security Solutions

Delaware, USA – September 3, 2019 – Astaroth malware authors continue experiments with abusing legitimate tools and services to deploy the trojan and hide their traces after infection. Following the recent disclosure of the infection chain, attackers have significantly altered the delivery mechanism and launched a new campaign. Security researcher Marcel Afrahim discovered the misuse […]

Cryptocurrency Mining Botnet Targets Intel Systems

Delaware, USA – September 2, 2019 – New cryptocurrency mining malware has switched from IoT devices to Intel systems running Linux. The security researcher at Akamai discovered that one of the botnets attacking MIPS and ARM-powered devices began to attack X86/I686 systems installing XMRig v2.14.1 cryptocurrency miner. The earliest malware samples were developed at the […]

More than 400 Dental Offices Suffers Sodinokibi Ransomware Attack

Delaware, USA – August 30, 2019 – Last weekend, another large-scale ransomware attack targeting US companies took place, and it seems that average ransom payment will once again shoot upwards this quarter. Adversaries compromised PercSoft, a cloud management provider for Digital Dental Record, who provides online data backup service archiving medical records and other information […]

New TrickBot Modules Collect Data to Perform SIM Swapping Attacks

Delaware, USA – August 29, 2019 – Not only MegaCortex ransomware gained new features over this summer preparing to autumn campaigns. During August, Trickbot sequentially received three modules to attack users of US-based mobile carriers: Verizon Wireless, T-Mobile, and Sprint. SecureWorks researchers discovered that new trojan versions harvest PIN code of these operators when a […]

New Details on Hexane Group Campaigns

Delaware, USA – August 28, 2019 – New details of Hexane group operations show how proven techniques and tools, as well as some custom malware pieces, allow the threat actor to effectively attack oil and gas companies in the Middle East. The cybersecurity company Dragos Inc was the first to report the group after they […]

Emotet Botnet Comes Back From Summer Vacation

Delaware, USA – August 27, 2019 – Emotet botnet like a relic monster of cyberspace has woken up and is preparing to strike a new blow. Earlier this year, the known command-and-control infrastructure of the botnet disappeared from researchers’ radars, presumably for maintenance and modification. As expected, this did not last too long, and on […]

Asruex Backdoor Spreads via Infected Documents

Delaware, USA – August 23, 2019 – DarkHotel group (aka APT-C-06) modified Asruex backdoor, adding the capability of infecting PDFs, Word documents, and executables to spread infection within a targeted organization. The group is known for its stealth attacks, sophisticated techniques, and access to zero-day vulnerabilities, even more interesting is a fresh sample of their […]

NanoCore RAT is Offered for Free on a DarkNet Forum

Delaware, USA – August 22, 2019 – The fresh version of NanoCore RAT emerged on an underground forum despite the fact that its author is sentenced to 33 months imprisonment. LMNTRIX Labs discovered a relatively new version of the trojan with modifications, which is available to any user of the forum. Nanocore has been used […]

Silence Group Includes Fileless Tools In Their Arsenal

Delaware, USA – August 21, 2019 – In the three years since its inception, the financially motivated Silence group has stolen more than $4 million from banks located in Europe, Asia, Africa, and Latin America. In 2016, the group consisted of supposedly two people and effectively operated exclusively within the CIS. This spring, Silence group […]