Tag: Detection Content

TA551 Hackers Spread IcedID Trojan in a New Wave of Malspam Campaign
TA551 Hackers Spread IcedID Trojan in a New Wave of Malspam Campaign

Starting from July 2020 security researchers observe notable changes implemented to the TA551 (aka Shathak) malspam routine. Threat actors behind the TA551 campaign have switched from Ursnif and Valak distribution to IcedID banking Trojan infections. TA551 Overview TA551 is a long-lasting malspam campaign that emerged in February 2019. Initially, it was focused on delivering Ursnif […]

Read More
Warzone RAT Malware Used by Confucius APT in Targeted Attacks
Warzone RAT Malware Used by Confucius APT in Targeted Attacks

Security researchers have spotted an ongoing Confucius APT campaign that leverages Warzone RAT malware to compromise its targets. The campaign is presumably aimed at the governmental sector of China and other South Asia countries. Warzone RAT Description Warzone remote access Trojan (RAT), a prolific successor of AveMaria stealer, first emerged in 2018 as a malware-as-a-service […]

Read More
Unpatched NTFS Zero-Day in Windows 10 Damages Hard Drive with a Single File View
Unpatched NTFS Zero-Day in Windows 10 Damages Hard Drive with a Single File View

The information security analyst Jonas L has discovered an alarming bug in Windows 10 that might corrupt any hard drive (HD) relying on the NTFS formatting. A zero-day flaw remains unpatched despite the researcher has pointed up to it since autumn 2020. NTFS Vulnerability Analysis The NTFS zero-day vulnerability exists in Windows 10 build 1803, […]

Read More
New QRAT Variant Distributed via Trump-themed Spam Campaign
New QRAT Variant Distributed via Trump-themed Spam Campaign

Cyber-criminals constantly take advantage of the “hottest” media topics to lure victims and infect them with malware. This time hackers decided to profit from the increased attention to the last US presidential elections and launched a Donald Trump-themed spam campaign. The final goal of this operation is to distribute the latest QRAT Trojan malware variant, […]

Read More
DoppelPaymer Ransomware Detection
DoppelPaymer Ransomware Detection

DoppelPaymer ransomware is gaining momentum as a leading threat to critical infrastructure assets. According to the FBI warning released in December 2020, DoppelPaymer has targeted multiple organizations in healthcare, educational, governmental and other sectors. The attack routine is highly sophisticated and aggressive, allowing its operators to extort six- and seven-digit ransoms from their victims. Notably, […]

Read More
Golden SAML Attack Method Used by APT Group Behind SolarWinds Hack
Golden SAML Attack Method Used by APT Group Behind SolarWinds Hack

Adversaries apply a malicious Golden SAML method to expand a scale of compromise related to the SolarWinds hack. Although security researchers initially considered that the SolarWinds Orion software was a single access vector, further investigation reveals that the Golden SAML technique allows achieving persistence on any instance within a targeted cloud environment that maintains SAML […]

Read More
New Credential Stealer Banking Malware Attacks the US and Canada
New Credential Stealer Banking Malware Attacks the US and Canada

The banking sector has always been an attractive target for cyber-criminals. After Zeus and Gozi emerged in 2007, prominent banking Trojans regularly made the headlines by emptying accounts of customers. Recently, security researchers have spotted yet another member of the financial malware family. This time the campaign is aimed at the US and Canadian banking […]

Read More
SUPERNOVA Backdoor: A Second APT Group Abused SolarWinds Flaw to Deploy Web Shell Malware
SUPERNOVA Backdoor: A Second APT Group Abused SolarWinds Flaw to Deploy Web Shell Malware

New details related to epoch-making SolarWinds supply-chain attack came into light. Research from Microsoft indicates that another stand-alone APT actor might have a hand in SolarWinds Orion compromise. Particularly, cyber-criminals utilized a newly discovered zero-day bug to infect targeted instances with SUPERNOVA backdoor. New ZeroDay Vulnerability in SolarWinds Orion Software (CVE-2020-10148) The vulnerability was disclosed […]

Read More
IceRAT Malware Detection: Catch Me If You Can
IceRAT Malware Detection: Catch Me If You Can

IceRAT is a relatively new tool in the malicious arena, being a unique strain in regard to its features and unprecedented evasion tactics. Remarkably, the threat has very low detection rates, acting as a stealth malware able to steal sensitive data and financial assets from the targeted machines. What is IceRAT malware? Despite its name, […]

Read More
Lazarus Group Attacks Manufacturing and Electrical Industries in Europe
Lazarus Group Attacks Manufacturing and Electrical Industries in Europe

The infamous Lazarus APT group (aka HiddenCobra, APT37) was yet again spotted agitating the world of cyber. This time security analysts revealed a highly targeted cyber-espionage campaign aimed at major manufacturing and electrical industry enterprises across Europe.  Lazarus Toolset and Attack Scenario The initial attack vector used by Lazarus hackers was similar to that leveraged […]

Read More