Oct 6, 2018

APT report for 2018-10-05

TRANSNATIONAL / UNKNOWN

  1. Fin7 Hackers Breached US Chain Burgerville
  2. Fin7 Hackers Breached US Chain Burgerville

CHINA

  1. DHS issued an alert on attacks aimed at Managed Service Providers

INDIA

Nothing to report

NORTH KOREA

  1. Detecting Credit Card Skimmers
  2. North Korean hacking operation behind SWIFT attacks

PAKISTAN

Nothing to report

VIETNAM

Nothing to report

IRAN

Nothing to report

LEBANON

Nothing to report

PALESTINE

Nothing to report

SAUDI ARABIA

Nothing to report

UNITED ARAB EMIRATES

Nothing to report

RUSSIA

  1. Russian State-Sponsored Operations Begin to Overlap: Kaspersky
  2. Uncle Sam Charges Seven Russians With Fancy Bear Hack Sprees
  3. The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
  4. VP Mike Pence slams Google over Chinese search engine project
  5. Russia's elite hacking unit has been silent, but busy
  6. Lojax, the new threat developed by Fancy Bear

UKRAINE

Nothing to report

Platform report for 2018-10-05

WINDOWS

  1. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  2. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  3. Missing Files, Bugs Reported After Windows 10 October 2018 Update
  4. DanaBot Banking Trojan’s Journey to North America
  5. Lojax, the new threat developed by Fancy Bear
  6. CMake 3.12.3 releases: managing the build process of software

LINUX

  1. DanaBot Banking Trojan’s Journey to North America
  2. Lojax, the new threat developed by Fancy Bear

UNIX

Nothing to report

ANDROID

  1. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  2. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  3. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  4. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System

IOS

  1. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  2. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System

MACOS

  1. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  2. DanaBot Banking Trojan’s Journey to North America
  3. Lojax, the new threat developed by Fancy Bear

Threat report for 2018-10-05

DATA BREACH

  1. Sales intel firm Apollo data breach exposed more than 200 million contact records
  2. Fortnite gamers targeted by data theft malware
  3. Apollo hackers steal info from database of 200M contact
  4. Security researchers @proofpoint recently uncovered new #DanaBot campaigns.
  5. GhostDNS hijacking campaign steps up attacks on Brazilians; 100K+ devices compromised
  6. Smart TV kit featuring Google Home Mini and third-gen Chromecast leaks
  7. UK pins 'reckless campaign of cyber attacks' on Russian military intelligence
  8. Experts warns of a new extortion campaign based on the Breach Compilation archive
  9. Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
  10. Intel, AMD both claim server speed records
  11. Samsung predicts a return to record profits in Q3
  12. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to

DENIAL-OF-SERVICE

  1. Hacked #Fortnite accounts and rent-a-botnet being pushed on Instagram

MALVERTISING

Nothing to report

PHISHING

  1. Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
  2. Remove Ursnif Trojan (Purolator Phishing) Scam
  3. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  4. Report: The bigger the company, the messier the password practices
  5. The most commonly used passwords in the world are... 1. 123456 2. password 3. 123456789 4. 12345678 5. 12345 6. qwerty
  6. Can the @Microsoft Authenticator really replace passwords in the enterprise? Microsoft says the answer is yes and proclaimed the password
  7. Weak Passwords Banned In California From 2020
  8. New IoT legislation bans shared default passwords
  9. US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
  10. Credential-Phishing Attempts Highest on Tuesdays
  11. Credential-Phishing Attempts Highest on Tuesdays
  12. If you're thinking passwords, check out #CyberSauna episode #13: A Hacker's Take on Cracking & Protecting Your Creds
  13. FYI: "password" is the 2nd most popular password in the world. Can you guess the first?
  14. Facebook Logins Available on the Dark Web for $2.60
  15. Passware Kit: Forensic software recovers passwords for Bitcoin wallets

WEB DEFACEMENT

Nothing to report

MALWARE

  1. Ransomware Recovery at the Taxpayers’ Expense
  2. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  3. Fortnite gamers targeted by data theft malware
  4. Remove Ursnif Trojan (Purolator Phishing) Scam
  5. Trojans go after MS Office vulnerabilities and China hacks US hardware
  6. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  7. Virus Bulletin 2018: Exposing the Social Media Fraud Ecosystem
  8. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  9. Danabot Banking Malware Targets U.S. Organizations
  10. The Virus Bulletin conference returns home: VB2019 to take place in London
  11. Fileless malware: part deux
  12. Cisco Discovered Multiple Vulnerabilities In Atlantis Word Processor
  13. Hackers fly under the radar for two years after infecting chiropractic clinic with malware
  14. DanaBot Banking Trojan’s Journey to North America
  15. Virus Bulletin 2018: Supply chain hacking grows up
  16. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  17. Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
  18. Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
  19. How does FacexWorm malware use Facebook Messenger to spread?
  20. Malicious remote admin tool seemingly linked to KONNI malware, North Korea
  21. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  22. .@FireEye researches discovered that the group behind #Sanny #malware attacks has made delivery method changes that put users at risk.
  23. Fake News Domains Spoof UK News Sites
  24. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System
  25. Top 5 Viruses of All Time by Security Expert Mikko Hyppönen
  26. CMake 3.12.3 releases: managing the build process of software

EXPLOIT

  1. Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
  2. Advanced Persistent Threat Activity Exploiting Managed Service Providers

VULNERABILITY

  1. Adobe October Patch Update Fixed 86 Different Security Vulnerabilities
  2. Sony Smart TV Bug Allows Remote Access, Root Privileges
  3. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  4. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  5. D-Link Patches RCE Bugs in Wireless Access Point Gear
  6. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  7. 150 Bugs Found in the Hack the Marine Corps Challenge
  8. Trojans go after MS Office vulnerabilities and China hacks US hardware
  9. 150 Bugs Found in the Hack the Marine Corps Challenge
  10. Most Home Routers Are Full of Vulnerabilities
  11. Vulnerability Scanning vs. Penetration Testing: What's the Difference?
  12. Adobe update cleans up 86 bugs in Acrobat and Reader, many critical
  13. Missing Files, Bugs Reported After Windows 10 October 2018 Update
  14. Cisco Discovered Multiple Vulnerabilities In Atlantis Word Processor
  15. Mozilla Resolves Critical Code Execution Flaw In Thunderbird
  16. Cisco patches critical flaws in DNA Center and Prime Infrastructure
  17. Marine Corps bug bounty program finds 150 vulnerabilities
  18. Mozilla resolves critical code execution flaw in Thunderbird email client
  19. Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
  20. D-Link Patches Code Execution, XSS Flaws in Management Tool
  21. Cisco updates address 36 vulnerabilities, three critical
  22. Vulnerability Scanning vs. Penetration Testing: What's the Difference?
  23. #PulseNet: How does an improper #authentication flaw affect it?
  24. Cisco Released Security Updates & Fixed 37 Vulnerabilities that Affected Cisco Products
  25. Mozilla Patches Critical Vulnerability in Thunderbird 60.2.1

Region brief for 2018-10-05

ASIA

  1. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  2. Trojans go after MS Office vulnerabilities and China hacks US hardware
  3. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  4. DHS issued an alert on attacks aimed at Managed Service Providers
  5. VP Mike Pence slams Google over Chinese search engine project
  6. North Korean hacking operation behind SWIFT attacks

OCEANIA

  1. Trojans go after MS Office vulnerabilities and China hacks US hardware
  2. Danabot Banking Malware Targets U.S. Organizations
  3. DanaBot Banking Trojan’s Journey to North America

NORTH AMERICA

  1. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  2. Trojans go after MS Office vulnerabilities and China hacks US hardware
  3. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  4. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  5. Danabot Banking Malware Targets U.S. Organizations
  6. Uncle Sam Charges Seven Russians With Fancy Bear Hack Sprees
  7. DanaBot Banking Trojan’s Journey to North America
  8. The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
  9. US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
  10. DHS issued an alert on attacks aimed at Managed Service Providers
  11. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  12. Fin7 Hackers Breached US Chain Burgerville
  13. Fin7 Hackers Breached US Chain Burgerville

SOUTH AMERICA

Nothing to report

EUROPE

  1. Russian State-Sponsored Operations Begin to Overlap: Kaspersky
  2. Danabot Banking Malware Targets U.S. Organizations
  3. The Virus Bulletin conference returns home: VB2019 to take place in London
  4. DanaBot Banking Trojan’s Journey to North America
  5. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  6. The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
  7. UK pins 'reckless campaign of cyber attacks' on Russian military intelligence
  8. Experts warns of a new extortion campaign based on the Breach Compilation archive
  9. Facebook Logins Available on the Dark Web for $2.60
  10. DHS issued an alert on attacks aimed at Managed Service Providers
  11. Fake News Domains Spoof UK News Sites
  12. Russia's elite hacking unit has been silent, but busy

AFRICA

Nothing to report

Sector brief for 2018-10-05

HEALTHCARE

  1. Hackers fly under the radar for two years after infecting chiropractic clinic with malware
  2. DHS issued an alert on attacks aimed at Managed Service Providers

TRANSPORT

Nothing to report

BANKING & FINANCE

  1. Sales intel firm Apollo data breach exposed more than 200 million contact records
  2. Remove Ursnif Trojan (Purolator Phishing) Scam
  3. Trojans go after MS Office vulnerabilities and China hacks US hardware
  4. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  5. Danabot Banking Malware Targets U.S. Organizations
  6. Report: The bigger the company, the messier the password practices
  7. Hackers fly under the radar for two years after infecting chiropractic clinic with malware
  8. DanaBot Banking Trojan’s Journey to North America
  9. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  10. Detecting Credit Card Skimmers
  11. Experts warns of a new extortion campaign based on the Breach Compilation archive
  12. Facebook Logins Available on the Dark Web for $2.60
  13. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  14. Passware Kit: Forensic software recovers passwords for Bitcoin wallets
  15. North Korean hacking operation behind SWIFT attacks

INFORMATION & TELECOMMUNICATION

  1. Sales intel firm Apollo data breach exposed more than 200 million contact records
  2. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  3. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  4. Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
  5. 150 Bugs Found in the Hack the Marine Corps Challenge
  6. 150 Bugs Found in the Hack the Marine Corps Challenge
  7. Virus Bulletin 2018: Exposing the Social Media Fraud Ecosystem
  8. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  9. Fileless malware: part deux
  10. Can the @Microsoft Authenticator really replace passwords in the enterprise? Microsoft says the answer is yes and proclaimed the password
  11. Smart TV kit featuring Google Home Mini and third-gen Chromecast leaks
  12. Hacked #Fortnite accounts and rent-a-botnet being pushed on Instagram
  13. US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
  14. Credential-Phishing Attempts Highest on Tuesdays
  15. Credential-Phishing Attempts Highest on Tuesdays
  16. If you're thinking passwords, check out #CyberSauna episode #13: A Hacker's Take on Cracking & Protecting Your Creds
  17. How does FacexWorm malware use Facebook Messenger to spread?
  18. FYI: "password" is the 2nd most popular password in the world. Can you guess the first?
  19. Facebook Logins Available on the Dark Web for $2.60
  20. VP Mike Pence slams Google over Chinese search engine project
  21. Fake News Domains Spoof UK News Sites
  22. Fin7 Hackers Breached US Chain Burgerville
  23. Fin7 Hackers Breached US Chain Burgerville
  24. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System
  25. CMake 3.12.3 releases: managing the build process of software

FOOD

Nothing to report

WATER

Nothing to report

ENERGY

  1. DHS issued an alert on attacks aimed at Managed Service Providers

GOVERNMENT & PUBLIC SERVICE

Nothing to report

Daily brief for 2018-10-05

ASIA

  1. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  2. Trojans go after MS Office vulnerabilities and China hacks US hardware
  3. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  4. DHS issued an alert on attacks aimed at Managed Service Providers
  5. VP Mike Pence slams Google over Chinese search engine project
  6. North Korean hacking operation behind SWIFT attacks

WORLD

  1. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  2. Trojans go after MS Office vulnerabilities and China hacks US hardware
  3. Russian State-Sponsored Operations Begin to Overlap: Kaspersky
  4. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  5. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  6. Danabot Banking Malware Targets U.S. Organizations
  7. The Virus Bulletin conference returns home: VB2019 to take place in London
  8. Uncle Sam Charges Seven Russians With Fancy Bear Hack Sprees
  9. DanaBot Banking Trojan’s Journey to North America
  10. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  11. The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
  12. UK pins 'reckless campaign of cyber attacks' on Russian military intelligence
  13. Experts warns of a new extortion campaign based on the Breach Compilation archive
  14. US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
  15. Facebook Logins Available on the Dark Web for $2.60
  16. DHS issued an alert on attacks aimed at Managed Service Providers
  17. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  18. Fake News Domains Spoof UK News Sites
  19. Russia's elite hacking unit has been silent, but busy
  20. Fin7 Hackers Breached US Chain Burgerville
  21. Fin7 Hackers Breached US Chain Burgerville

ATTACKS

  1. Sales intel firm Apollo data breach exposed more than 200 million contact records
  2. Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
  3. Fortnite gamers targeted by data theft malware
  4. Remove Ursnif Trojan (Purolator Phishing) Scam
  5. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  6. Report: The bigger the company, the messier the password practices
  7. The most commonly used passwords in the world are... 1. 123456 2. password 3. 123456789 4. 12345678 5. 12345 6. qwerty
  8. Apollo hackers steal info from database of 200M contact
  9. Can the @Microsoft Authenticator really replace passwords in the enterprise? Microsoft says the answer is yes and proclaimed the password
  10. Security researchers @proofpoint recently uncovered new #DanaBot campaigns.
  11. Weak Passwords Banned In California From 2020
  12. New IoT legislation bans shared default passwords
  13. GhostDNS hijacking campaign steps up attacks on Brazilians; 100K+ devices compromised
  14. Smart TV kit featuring Google Home Mini and third-gen Chromecast leaks
  15. Hacked #Fortnite accounts and rent-a-botnet being pushed on Instagram
  16. UK pins 'reckless campaign of cyber attacks' on Russian military intelligence
  17. Experts warns of a new extortion campaign based on the Breach Compilation archive
  18. US users open 30% of phishing emails with 12% of those clicking on infected links or attachments. Prepare for 2019's
  19. Credential-Phishing Attempts Highest on Tuesdays
  20. Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
  21. Credential-Phishing Attempts Highest on Tuesdays
  22. If you're thinking passwords, check out #CyberSauna episode #13: A Hacker's Take on Cracking & Protecting Your Creds
  23. Intel, AMD both claim server speed records
  24. FYI: "password" is the 2nd most popular password in the world. Can you guess the first?
  25. Facebook Logins Available on the Dark Web for $2.60
  26. Samsung predicts a return to record profits in Q3
  27. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  28. Passware Kit: Forensic software recovers passwords for Bitcoin wallets

THREATS

  1. Adobe October Patch Update Fixed 86 Different Security Vulnerabilities
  2. Ransomware Recovery at the Taxpayers’ Expense
  3. Sony Smart TV Bug Allows Remote Access, Root Privileges
  4. Virus Bulletin 2018: Saudi Dissident Spyware Attack Belies Bigger Threat
  5. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  6. Unit 42 Vulnerability Research October 2018 Disclosures – Adobe
  7. Facebook Found “No Evidence” Of Facebook Login Exploited To Access Linked Apps
  8. Fortnite gamers targeted by data theft malware
  9. D-Link Patches RCE Bugs in Wireless Access Point Gear
  10. VMware Releases Patches for Critical A/W Console Auth Bypass Vulnerability
  11. Remove Ursnif Trojan (Purolator Phishing) Scam
  12. 150 Bugs Found in the Hack the Marine Corps Challenge
  13. Trojans go after MS Office vulnerabilities and China hacks US hardware
  14. .@alienvault researchers recently discovered #MassMiner, a #cryptocurrency mining #malware that has the ability to infect systems across the web. Discover
  15. 150 Bugs Found in the Hack the Marine Corps Challenge
  16. Most Home Routers Are Full of Vulnerabilities
  17. Virus Bulletin 2018: Exposing the Social Media Fraud Ecosystem
  18. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  19. Danabot Banking Malware Targets U.S. Organizations
  20. The Virus Bulletin conference returns home: VB2019 to take place in London
  21. Vulnerability Scanning vs. Penetration Testing: What's the Difference?
  22. Fileless malware: part deux
  23. Adobe update cleans up 86 bugs in Acrobat and Reader, many critical
  24. Missing Files, Bugs Reported After Windows 10 October 2018 Update
  25. Cisco Discovered Multiple Vulnerabilities In Atlantis Word Processor
  26. Advanced Persistent Threat Activity Exploiting Managed Service Providers
  27. Mozilla Resolves Critical Code Execution Flaw In Thunderbird
  28. Hackers fly under the radar for two years after infecting chiropractic clinic with malware
  29. DanaBot Banking Trojan’s Journey to North America
  30. Cisco patches critical flaws in DNA Center and Prime Infrastructure
  31. Virus Bulletin 2018: Supply chain hacking grows up
  32. Marine Corps bug bounty program finds 150 vulnerabilities
  33. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  34. Mozilla resolves critical code execution flaw in Thunderbird email client
  35. Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
  36. D-Link Patches Code Execution, XSS Flaws in Management Tool
  37. Cisco updates address 36 vulnerabilities, three critical
  38. Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
  39. Vulnerability Scanning vs. Penetration Testing: What's the Difference?
  40. How does FacexWorm malware use Facebook Messenger to spread?
  41. Malicious remote admin tool seemingly linked to KONNI malware, North Korea
  42. #PulseNet: How does an improper #authentication flaw affect it?
  43. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  44. .@FireEye researches discovered that the group behind #Sanny #malware attacks has made delivery method changes that put users at risk.
  45. Cisco Released Security Updates & Fixed 37 Vulnerabilities that Affected Cisco Products
  46. Fake News Domains Spoof UK News Sites
  47. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System
  48. Top 5 Viruses of All Time by Security Expert Mikko Hyppönen
  49. CMake 3.12.3 releases: managing the build process of software
  50. Mozilla Patches Critical Vulnerability in Thunderbird 60.2.1

CRIME

  1. Fortnite gamers targeted by data theft malware
  2. Remove Ursnif Trojan (Purolator Phishing) Scam
  3. California Is Making It Illegal for Devices to Have Shitty Default Passwords
  4. AirNaine Uses New ARS RAT Strain Named ZeroEvil Against Canadian Businesses
  5. Danabot Banking Malware Targets U.S. Organizations
  6. Report: The bigger the company, the messier the password practices
  7. Hackers fly under the radar for two years after infecting chiropractic clinic with malware
  8. DanaBot Banking Trojan’s Journey to North America
  9. The Kronos banking trojan is back from the malware dustbin. After years of lying dormant, hackers have reworked the underlying
  10. Detecting Credit Card Skimmers
  11. The fur is not gonna fly: Uncle Sam charges seven Russians with Fancy Bear hack sprees
  12. Experts warns of a new extortion campaign based on the Breach Compilation archive
  13. Cryptomining malware steals Fortnite gamers' Bitcoins and personal data
  14. Facebook Logins Available on the Dark Web for $2.60
  15. DHS issued an alert on attacks aimed at Managed Service Providers
  16. New research reveals the DanaBot banking Trojan is now targeting banks in the United States as well. The campaign attempts to
  17. Roaming Mantis Hacking Group Inject Web Crypto Mining for iOS Devices via Malicious Content Delivery System
  18. Passware Kit: Forensic software recovers passwords for Bitcoin wallets
  19. North Korean hacking operation behind SWIFT attacks
  20. Lojax, the new threat developed by Fancy Bear

POLITICS

  1. Russian State-Sponsored Operations Begin to Overlap: Kaspersky
  2. Advanced Persistent Threat Activity Exploiting Managed Service Providers
  3. DHS issued an alert on attacks aimed at Managed Service Providers

Oct 5, 2018

APT report for 2018-10-04

TRANSNATIONAL / UNKNOWN

  1. Formjacking attacks spike as Magecart sets sites on ecommerce
  2. Pacific Northwest burger chain hit by FIN7
  3. Burgerville customer credit card info stolen in data breach laid at Fin7's feet

CHINA

Nothing to report

INDIA

Nothing to report

NORTH KOREA

  1. HIDDEN COBRA – FASTCash Campaign
  2. APT38 is behind financially motivated attacks carried out by North Korea

PAKISTAN

Nothing to report

VIETNAM

Nothing to report

IRAN

Nothing to report

LEBANON

Nothing to report

PALESTINE

Nothing to report

SAUDI ARABIA

Nothing to report

UNITED ARAB EMIRATES

Nothing to report

RUSSIA

  1. Virus Bulletin 2018: Turla APT Changes Shape with New Code and Targets
  2. Should You Worry About Software Supply Chain Attacks?
  3. Shedding Skin – Turla’s Fresh Faces
  4. LoJack for computers used to attack European government bodies
  5. Justice Department charges 7 Russian intelligence officers
  6. APT28 turns away from election hacking and back to cyberespionage
  7. Russian Fancy Bear APT Linked To Earworm Hacking Group
  8. Russian Fancy Bear APT linked to Earworm hacking group
  9. LoJax: First UEFI Malware seen in the Wild

UKRAINE

Nothing to report

Platform report for 2018-10-04

WINDOWS

  1. Shedding Skin – Turla’s Fresh Faces
  2. LoJack for computers used to attack European government bodies
  3. CVE-2018-8373 Exploit Spotted
  4. LoJax: First UEFI Malware seen in the Wild
  5. Foxit PDF Reader fixes serious remote code execution vulnerability

LINUX

  1. LoJack for computers used to attack European government bodies

UNIX

Nothing to report

ANDROID

  1. .@ThreatFabric researchers uncovered an #Android malware, #MysteryBot, which uses overlay attacks to avoid detection. Learn how this #malware affects @Google's
  2. How is Android Accessibility Service affected by a banking Trojan?
  3. .@Trustlook Labs discovered an #Android #Trojan stealing data from messaging apps. Learn what #mobilesecurity programs should look for to detect
  4. Researchers found that cheap Android devices were shipped pre-installed backdoors

IOS

  1. A Remote iOS Bug

MACOS

  1. Google Project Zero drops macOS exploit, calls out Apple for silent patching
  2. CVE-2018-4251 – Apple did not disable Intel Manufacturing Mode in its laptops
  3. macOS Flaw Allows Attackers To Hijack Installed Apps
  4. Tearing Apart the Undetected (OSX)Coldroot RAT
  5. An Unpatched Kernel Bug
  6. OSX/MacRansom; analyzing the latest ransomware to target macs
  7. Two Bugs, One Func(), part three
  8. Two Bugs, One Func(), part two
  9. Two Bugs, One Func(), part one
  10. Analysis of an Intrusive Cross-Platform Adware; OSX/Pirrit
  11. More on, "Adware for OS X Distributes Trojans"
  12. A Google bug breaks the search results in Safari

Threat report for 2018-10-04

DATA BREACH

  1. UK pins ‘reckless campaign of cyber attacks’ on Russian military intelligence
  2. .@FireEye researchers tracked an aggressive #cybertheft campaign -- attributed to North Korean #APT38 -- in which threat actors attempted to
  3. Campaign 2018: Cyberattacks on infrastructure could suppress voter turnout
  4. Sony accidentally leaked November's PS Plus free games
  5. US charges Russian military officers over international hacking and disinformation campaigns
  6. Burgerville Customer Credit Card Info Stolen In Data Breach
  7. HIDDEN COBRA – FASTCash Campaign
  8. Database of 200 Million Records Stolen from Apollo in Data Breach
  9. Irish Data Regulator Likely to Fine Facebook for Data Breach
  10. 5,000 UK firms' financial details exposed in data breaches, finds @digitalshadows
  11. The @UN accidentally exposed credentials on public @trello boards. Plus, #Uber is set to pay $148 million settlement following its
  12. Burgerville customer credit card info stolen in data breach laid at Fin7's feet
  13. How #livechatsoftware leak personal #employeedata?
  14. Democratic congressional intern arrested for doxing GOP senators during Kavanaugh hearing
  15. Business Email Compromise: When You Don’t Need to Phish.
  16. Business email compromise made easy for cyber criminals
  17. In manufacturing, almost half – 47 percent – of breaches involve the theft of intellectual property to gain competitive advantage.
  18. Security Investigator who Compromised Hotel Wi-Fi, Shared Pass-Codes Online, is Fined
  19. UK and allies accuse Russia of cyber attack campaign
  20. Business email compromise made easy for #cybercriminals as 12.5 million company email boxes and 33,000 finance department credentials found openly
  21. U.S. Capitol Police Arrest Suspect for Doxing U.S. Senators
  22. DanaBot Observed in Large Campaign Targeting U.S. Organizations

DENIAL-OF-SERVICE

  1. California bill bans bots during elections
  2. Why It’s Time to Nuke the Password
  3. Why It’s Time to Nuke the Password

MALVERTISING

Nothing to report

PHISHING

  1. Exclusive: Moving away from passwords to two-factor authentication
  2. Block Blocking Login Items
  3. Business Email Compromise: When You Don’t Need to Phish.
  4. Hackers Selling Facebook Account Logins Details On Dark Web For $3
  5. Experts recommend avoiding single step logins
  6. Phishing Attacks Distributed Through CloudFlare's IPFS Gateway
  7. Why It’s Time to Nuke the Password
  8. Why It’s Time to Nuke the Password
  9. DanaBot Observed in Large Campaign Targeting U.S. Organizations

WEB DEFACEMENT

  1. Hacker Pleads Guilty of Defacing 11,000 Websites, Could Get up to 20 Years
  2. Hacktivist pleads guilty to defacing websites for NYC comptroller, Combating Terrorism Center

MALWARE

  1. Virus Bulletin 2018: Turla APT Changes Shape with New Code and Targets
  2. .@ThreatFabric researchers uncovered an #Android malware, #MysteryBot, which uses overlay attacks to avoid detection. Learn how this #malware affects @Google's
  3. China allegedly infiltrated US companies through implanted hardware backdoors
  4. Researchers at the 2018 @RSAConference discussed #stegware: @malware that uses #steganography. Discover how this works with expert @lewisnic.
  5. Report: In Huge Hack, Chinese Manufacturer Sneaks Backdoors Onto Motherboards
  6. Avast AV reclassifies cryptominers | Avast
  7. Researchers at Cisco Talos (@TalosSecurity) recently discovered #GravityRAT, a remote access #Trojan. Discover how this RAT can check for
  8. This is also a good time to remind that bugdoors are far more scary than backdoors.
  9. Fallout Exploit Kit Now Installing the Kraken Cryptor Ransomware
  10. Apple, Amazon deny claims Chinese spies implanted backdoor chips in company hardware: report
  11. Researchers from @proofpoint have announced the discovery of a remote access trojan, and an upgraded version of an old banking
  12. Canadian restaurant chain Recipe suffered a network outage, is it a ransomware attack?
  13. Tearing Apart the Undetected (OSX)Coldroot RAT
  14. Mac Malware of 2017
  15. WTF is Mughthesec!? poking on a piece of undetected adware
  16. OSX/MacRansom; analyzing the latest ransomware to target macs
  17. Mac Malware of 2016
  18. Towards Generic Ransomware Detection
  19. Analysis of an Intrusive Cross-Platform Adware; OSX/Pirrit
  20. Analyzing the Anti-Analysis Logic of an Adware Installer
  21. Monitoring Process Creation via the Kernel (Part III)
  22. Monitoring Process Creation via the Kernel (Part II)
  23. Monitoring Process Creation via the Kernel (Part I)
  24. More on, "Adware for OS X Distributes Trojans"
  25. LoJax: First UEFI Malware seen in the Wild
  26. Virus Bulletin 2018: Attack velocity ramps up
  27. More than 4,000 ransomware attacks occur every day. Secure your company & build your network at #RiskSec with promo code
  28. Malicious remote admin tool seemingly linked to KONNI malware, North Korea
  29. Betabot trojan packed with anti-malware evasion tools
  30. How is Android Accessibility Service affected by a banking Trojan?
  31. How does stegware malware exploit steganography techniques?
  32. .@Trustlook Labs discovered an #Android #Trojan stealing data from messaging apps. Learn what #mobilesecurity programs should look for to detect
  33. Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
  34. A new group of #malware -- dubbed #GoScanSSH -- was recently discovered by researchers. Learn how this malware works and
  35. Seriously if I could make evil semiconductors I would just replace one which is already present rather than adding it. Show
  36. WATCH: Top 5 Viruses of All Time by Security Expert @mikko Hyppönen
  37. New DanaBot Banking Malware Attack in Various Countries with Stealer and Remote Access Futures
  38. Researchers found that cheap Android devices were shipped pre-installed backdoors
  39. Google opened the .page domain
  40. Most Advanced Backdoor Obfuscation and Evasion Technique That used by Hackers
  41. Zoho Heavily Used by Keyloggers to Transmit Stolen Data
  42. Network Outage at Some Recipe Unlimited Locations Caused by Malware
  43. DanaBot Observed in Large Campaign Targeting U.S. Organizations

EXPLOIT

  1. Google Project Zero drops macOS exploit, calls out Apple for silent patching
  2. CVE-2018-8373 Exploit Spotted
  3. Fallout Exploit Kit Now Installing the Kraken Cryptor Ransomware
  4. Remote Mac Exploitation Via Custom URL Schemes
  5. How does stegware malware exploit steganography techniques?
  6. Secure encrypted #virtualization: How is this technology exploited?

VULNERABILITY

  1. Bug bounty scheme uncovers 150 vulnerabilities in US Marine Corps websites
  2. CVE-2018-4251 – Apple did not disable Intel Manufacturing Mode in its laptops
  3. macOS Flaw Allows Attackers To Hijack Installed Apps
  4. ICYMI - CISO @rickhholland joins @drshellface and @mazzazone in this week's ShadowTalk episode: Security Flaws Affect 50 Million Facebook Accounts
  5. CVE-2018-8373 Exploit Spotted
  6. Vulnerability Scanning vs. Penetration Testing by @TripwireInc
  7. This is also a good time to remind that bugdoors are far more scary than backdoors.
  8. A Remote iOS Bug
  9. An Unpatched Kernel Bug
  10. From the Top to the Bottom; Tracking down CVE-2017-7149
  11. Two Bugs, One Func(), part three
  12. Two Bugs, One Func(), part two
  13. Two Bugs, One Func(), part one
  14. CVE-2015-3673: Goodbye Rootpipe...(for now?)
  15. Cisco: Two critical bugs in DNA network software need these urgent patches
  16. Paper over the Kracks: New techniques can bypass WPA2 flaw mitigations
  17. Hackers Earn $150,000 in Marine Corps Bug Bounty Program
  18. Cisco plugs critical flaws in DNA Center and Prime Infrastructure
  19. Marine Corps bug bounty program finds 150 vulnerabilities
  20. Cisco Talos spotted 18 vulnerabilities in Foxit PDF Reader, 8 in Atlantis World Processor
  21. Foxit PDF Reader fixes serious remote code execution vulnerability
  22. A Google bug breaks the search results in Safari
  23. Hacking for good uncovers over 150 Marine Corps web vulnerabilities

Region brief for 2018-10-04

ASIA

  1. Should You Worry About Software Supply Chain Attacks?
  2. .@FireEye researchers tracked an aggressive #cybertheft campaign -- attributed to North Korean #APT38 -- in which threat actors attempted to
  3. Shedding Skin – Turla’s Fresh Faces
  4. China allegedly infiltrated US companies through implanted hardware backdoors
  5. Report: In Huge Hack, Chinese Manufacturer Sneaks Backdoors Onto Motherboards
  6. Apple, Amazon deny claims Chinese spies implanted backdoor chips in company hardware: report
  7. Canadian restaurant chain Recipe suffered a network outage, is it a ransomware attack?
  8. A Remote iOS Bug
  9. APT38 is behind financially motivated attacks carried out by North Korea
  10. Security Investigator who Compromised Hotel Wi-Fi, Shared Pass-Codes Online, is Fined

OCEANIA

  1. New DanaBot Banking Malware Attack in Various Countries with Stealer and Remote Access Futures

NORTH AMERICA

  1. UK pins ‘reckless campaign of cyber attacks’ on Russian military intelligence
  2. Bug bounty scheme uncovers 150 vulnerabilities in US Marine Corps websites
  3. China allegedly infiltrated US companies through implanted hardware backdoors
  4. US charges Russian military officers over international hacking and disinformation campaigns
  5. Hacker Pleads Guilty of Defacing 11,000 Websites, Could Get up to 20 Years
  6. Justice Department charges 7 Russian intelligence officers
  7. CVE-2018-4251 – Apple did not disable Intel Manufacturing Mode in its laptops
  8. ICYMI - CISO @rickhholland joins @drshellface and @mazzazone in this week's ShadowTalk episode: Security Flaws Affect 50 Million Facebook Accounts
  9. HIDDEN COBRA – FASTCash Campaign
  10. Pacific Northwest burger chain hit by FIN7
  11. Apple, Amazon deny claims Chinese spies implanted backdoor chips in company hardware: report
  12. Canadian restaurant chain Recipe suffered a network outage, is it a ransomware attack?
  13. Burgerville customer credit card info stolen in data breach laid at Fin7's feet
  14. LoJax: First UEFI Malware seen in the Wild
  15. Hackers Earn $150,000 in Marine Corps Bug Bounty Program
  16. APT38 is behind financially motivated attacks carried out by North Korea
  17. U.S. Capitol Police Arrest Suspect for Doxing U.S. Senators
  18. DanaBot Observed in Large Campaign Targeting U.S. Organizations

SOUTH AMERICA

  1. APT38 is behind financially motivated attacks carried out by North Korea

EUROPE

  1. UK pins ‘reckless campaign of cyber attacks’ on Russian military intelligence
  2. Virus Bulletin 2018: Turla APT Changes Shape with New Code and Targets
  3. Should You Worry About Software Supply Chain Attacks?
  4. US charges Russian military officers over international hacking and disinformation campaigns
  5. LoJack for computers used to attack European government bodies
  6. Justice Department charges 7 Russian intelligence officers
  7. Russian Fancy Bear APT Linked To Earworm Hacking Group
  8. Pacific Northwest burger chain hit by FIN7
  9. Irish Data Regulator Likely to Fine Facebook for Data Breach
  10. Russian Fancy Bear APT linked to Earworm hacking group
  11. 5,000 UK firms' financial details exposed in data breaches, finds @digitalshadows
  12. Canadian restaurant chain Recipe suffered a network outage, is it a ransomware attack?
  13. LoJax: First UEFI Malware seen in the Wild
  14. UK and allies accuse Russia of cyber attack campaign
  15. New DanaBot Banking Malware Attack in Various Countries with Stealer and Remote Access Futures
  16. Experts recommend avoiding single step logins

AFRICA

Nothing to report