Posts

Image
Microsoft recently released their findings after a lengthy investigation into activity conducted by the Russian state-sponsored APT28 group using a unique tool for privilege escalation and credential harvesting on victim networks. Microsoft refers to the custom tool as GooseEgg and claim that the group has been observed leveraging this tool since at least June 2020. GooseEgg The custom toolset leverages CVE-2023-38208 in the Windows Print Spooler service which changes a JavaScript constraints file and executes it with SYSTEM permissions. Based on their findings, Microsoft believes GooseEgg is deployed after initial access to elevate access to targeted systems with the end goal of harvesting credentials and data. Unsurprisingly, targeting includes Ukrainian, Western European and North American entities across several sectors including government, non-government, education and transportation. After initial access of victim device, researchers observed APT28 deploying GooseEgg to escalate...
Image
 Mandiant Identifies Novel OT Malware: COSMICENERGY Researchers at Mandiant recently provided the public with an analysis of a recently discovered OT malware they've dubbed COSMICENERGY. The malware was uploaded to a public malware scanner in December of 2021 by someone in Russia. They believe that the malware may have been developed by a contractor for red teaming purposes for simulation of power disruption exercises hosted by Rostelecom-Solar, a Russian cybersecurity consultant company. In their blog post, Mandiant draws comparisons between this new malware and previous OT malwares like INDUSTROYER, like both malwares being deployed to impact electricity transmission and distribution through IEC-104. COSMICENERGY contains two derivative components: PIEHOP and LIGHTWORK. PIEHOP is a disruption tool written in Python that is able to connect to remote MSSQL servers for file upload and sending remote commands to a remote terminal unit (RTU). PIEHOPE uses LIGHTWORK to issue "ON...

APTs Exploiting the new PaperCut Vulnerability

Image
The Vulnerabilities Print management software company PaperCut warned users of their product about an actively exploited vulnerability in their printing management software. The company claimed that 3rd party security vendors informed them of the two critical vulnerabilities as far back as January 10th, 2023. Tracked as CVE-2023-27350 and CVE-2023-27351 , the low-complexity vulnerabilities allow for threat actors to bypass authentication and execute arbitrary code on compromised PaperCut servers with SYSTEM permissions and without user interaction. Both flaws have since been fixed in PaperCut MF and PaperCut NG versions 20.1.7, 21.2.11, and 22.0.9 and later. Technical details on the exploits and proof of concept(s) can be found here:  https://news.sophos.com/en-us/2023/04/27/increased-exploitation-of-papercut-drawing-blood-around-the-internet/  https://packetstormsecurity.com/files/172022/PaperCut-NG-MG-22.0.4-Authentication-Bypass.html https://github.com/horizon3ai/CVE-2023-...

Russian Organizations in Chinese APT Crosshairs

Image
Overview SentinelLabs recently reported on a new cluster of activity targeting Russian organizations that they attributed with high-confidence to a Chinese state-sponsored espionage group. This was corroborated by a recent Ukraine CERT advisory (June 22, 2022).  The report highlights recent Chinese intelligence objectives regarding the observation of Russian organizations in the midst of the chaotic conflict in Ukraine. Scarab, Mustang Panda, and Space Pirates campaigns have all been observed and previously reported on but the researchers at SentinelLabs believe their ongoing analysis points to a new, separate campaign being conducted by an unattributed Chinese APT.  Campaign Details Back in June, CERT-UA asserted that the malicious RTF documents seen in phishing attempts against Russian organizations were " likely built in the Royal Road builder and dropped via the Bisonal backdoor ". SentinelLabs researchers took the OSINT provided by nao_sec and Malwarebytes, regarding C2 ...

Racoon Stealer Leverages Telegram for C2

Image
Introduction Raccoon Stealer is a fairly new tool that is able to extract passwords, browser cookies, email credentials, plugin/extension data, and crypto wallet files. The malware can download and execute arbitrary files through command-and-control and has become a very popular tool of choice as of late. According to Avast , Raccoon Stealer has been observed being distributed through downloaders like GCleaner and Buer Loader since 2019, and has seen multiple updates since original release. In the recent research paper provided by the Avast team, analysts point out that their samples of the malware appeared to be distributed in the form of game cheats, patches, game mods, or other popular software. Raccoon Stealer can be used by anyone who buys it so the scope of delivery themes is endless. Technical Analysis (Shortened) Raccoon Stealer is written in C/C++ via Visual Studio. The malware does several checks on an infected machine before executing the main payload. Once of these checks i...

Qakbot Inserting itself in your Conversations

Image
A recent threat report by Sophos Labs details techniques and tactics utilized by the infamous Qakbot/Qbot malware. By inserting itself into existing email conversations and using the account of compromised victims, it is able to spread quickly across a target's network. Qakbot leverages reply-all messages equipped with a link to a download URL containing the zip file of a MS Office maldoc.  See below: There are hundreds of variants of the distributed emails, in different languages and with slightly different one-liners. The primary malicious document analyzed by the Sophos team was an uncommon .xlsb , or Excel Binary Workbook extension. On par with expectations, the embedded payload executed upon enabling content. Here are some key takeaways from their analysis: the payload was dropped into a random 5-character folder in the root of the C: drive. via MS Edge, it contacts a compromised website and injects itself into an Edge instance the malware profiled the machine it was on (ie: ...

Google TAG: APT31 Targeting US govt Affiliates in Phishing Campaign

Image
Google's Threat Analysis Group (TAG) warned Gmail users about Chinese APT31 (Judgement Panda/Zirconium) observed phishing activity targeting high-profile accounts affiliated with the US government. Shane Huntley of Google TAG shared on Twitter information about this campaign including assurance that Google blocked 100% of these emails and classified them as spam. The campaign was first detected in February 2022 and, so far, shows no indication that it is related to the current Ukraine/Russia conflict. Google continues to monitor and react specifically to government-backed threat alerts. Back in October, some 50,000 alerts regarding state-sponsored activity and/or phishing were sent to customers throughout the 2021 year. Over 15,000 of these alerts were confidently linked to Russian GRU's APT28 (Fancy Bear) . APT31 has been linked in the past with the theft of the EpMe NSA exploit some years before the Shadow Brokers leaked it in 2017. Microsoft analysts have also observed APT...