Tag: Sigma

Turla Activity Detection: russian Cyberespionage Group Targeting Ukraine Uses Decade-Old USB-Delivered Andromeda Malware to Spread Novel Backdoors 4 min read Latest Threats Turla Activity Detection: russian Cyberespionage Group Targeting Ukraine Uses Decade-Old USB-Delivered Andromeda Malware to Spread Novel Backdoors by Veronika Telychko SOC Prime Introduces The Prime Hunt 5 min read SIEM & EDR SOC Prime Introduces The Prime Hunt by Veronika Telychko BlueNoroff Group Activity Detection: Threat Actors Apply Novel Methods to Bypass Windows Mark-of-the-Web (MoTW) Protection 4 min read Latest Threats BlueNoroff Group Activity Detection: Threat Actors Apply Novel Methods to Bypass Windows Mark-of-the-Web (MoTW) Protection by Veronika Telychko IcedID Botnet Detection: Malvertising Attacks Abusing Google Pay-Per-Click (PPC) Ads 4 min read Latest Threats IcedID Botnet Detection: Malvertising Attacks Abusing Google Pay-Per-Click (PPC) Ads by Veronika Telychko OWASSRF Exploit Detection: New Exploit Method Abuses Exchange Servers to Bypass ProxyNotShell (CVE-2022-41040 and CVE-2022-41082) Mitigations and Gain RCE 4 min read Latest Threats OWASSRF Exploit Detection: New Exploit Method Abuses Exchange Servers to Bypass ProxyNotShell (CVE-2022-41040 and CVE-2022-41082) Mitigations and Gain RCE by Daryna Olyniychuk FateGrab/StealDeal Detection: Phishing Attacks by the UAC-0142 Group Against Ukrainian Government Entities Targeting DELTA Users  3 min read Latest Threats FateGrab/StealDeal Detection: Phishing Attacks by the UAC-0142 Group Against Ukrainian Government Entities Targeting DELTA Users  by Veronika Telychko Detecting Fantasy Data Wiper Leveraged by Agrius APT in a Supply-Chain Attack 3 min read Latest Threats Detecting Fantasy Data Wiper Leveraged by Agrius APT in a Supply-Chain Attack by Daryna Olyniychuk SOC Prime Threat Bounty —  November 2022 Results 3 min read SOC Prime Threat Bounty —  November 2022 Results by Alla Yurchenko DolphinCape Malware Detection: Phishing Campaign Against Ukrainian Railway Transport Organization of Ukraine “Ukrzaliznytsia” Related to the Use of Iranian Shahed-136 Drones 3 min read Latest Threats DolphinCape Malware Detection: Phishing Campaign Against Ukrainian Railway Transport Organization of Ukraine “Ukrzaliznytsia” Related to the Use of Iranian Shahed-136 Drones by Veronika Telychko AppleJeus Malware Detection: North Korea-Linked Lazarus APT Spreads Malicious Strains Masquerading as Cryptocurrency Apps 4 min read Latest Threats AppleJeus Malware Detection: North Korea-Linked Lazarus APT Spreads Malicious Strains Masquerading as Cryptocurrency Apps by Veronika Telychko