According to a recent threat report published by CyberHunter_NL, the cyber-thieves group Cloud Atlas has been identified as using a new tool called VBCloud. This backdoor is targeted at victims in Eastern Europe and Central Asia
Continue ReadingBlog
Modiloader: Sophisticated Malware Delivery Chain from Obfuscated Batch File
An investigation of a file named 'Albertsons_payment.GZ' revealed a sophisticated malware delivery chain. The file, initially disguised as an image, was actually a Windows Cabinet file containing an obfuscated batch script. This script employed string slicing
Continue ReadingBeyondTrust Remote Support SaaS Service Security Investigation: A Critical Analysis of Cybersecurity Threats and Recommendations for Improved Posture
As a result of on-going investigation, a medium-severity vulnerability (BT24-11) was identified within our Remote Support and Privileged Remote Access products (both self-hosted and cloud). This finding highlights the importance of prioritizing cybersecurity and regular updates
Continue ReadingHackers Exploit Microsoft Management Console to Drop Backdoor Payloads on Windows
Threat Report Hackers Use Microsoft Management Console to Deliver Malicious Payloads As outlined in a recent threat report, hackers have been exploiting the Microsoft Management Console (MMC) to deliver backdoor payloads on Windows systems. This sophisticated
Continue ReadingHackers Exploit Microsoft Management Console to Drop Backdoor Payloads on Windows
Threat Report Hackers Use Microsoft Management Console to Deliver Malicious Payloads. As outlined in a recent threat report, hackers have been exploiting the Microsoft Management Console (MMC) to deliver backdoor payloads on Windows systems. This sophisticated
Continue ReadingExploit attempts inspired by recent Struts2 File Upload Vulnerability (CVE-2024-53677, CVE-2023-50164) – SANS Internet Storm Center
Threat Overview Exploit attempts inspired by recent Struts2 File Upload Vulnerability (CVE-2024-53677, CVE-2023-50164) - SANS Internet Storm Center A recent threat report published by CyberHunter_NL on 2024-12-16T15:05:11.149Z highlights the exploitation of a vulnerability in Apache Struts2
Continue ReadingExploited: Critical Vulnerabilities in Cleo File Transfer Software Widespread Exploitation
Threat Overview A recent threat report published by AlienVault highlights critical vulnerabilities in Cleo file transfer products, including VLTrader, Harmony, and LexiCom. These vulnerabilities are being actively exploited by attackers, who are dropping modular Java backdoors
Continue ReadingA new infostealer called VIPKeyLogger has been observed
Threat Overview A new infostealer called VIPKeyLogger has been observed with increased activity. It shares similarities with Snake Keylogger and is distributed through phishing campaigns. The malware is delivered as an archive or Microsoft 365 file
Continue ReadingExploitation of a Vulnerability in Apache ActiveMQ by actor group Mauri Ransomware
Threat Overview Cyber Threats and Vulnerabilities: Protect Your Organization from Attack Threat Overview for Security Operation Center Cyber threats are becoming increasingly sophisticated, with attackers using new techniques to exploit vulnerabilities in systems and networks. The
Continue ReadingFreeloader: Russian Actor Secret Blizzard Exploits Other Groups’ Tools to Attack Ukraine
Threat Overview AlienVault has recently published a threat report highlighting the activities of a nation-state actor known as Secret Blizzard. This actor group, associated with Russia, has been observed using tools and infrastructure from other malicious
Continue Reading