Злоумышленники перенимают опыт коллег: что общего между SilverFox и APT41. Разбор атаки

Привет, Хабр! На связи Евгения Устинова, старший аналитик сетевой безопасности группы компаний «Гарда» . В статье хочу рассказать, как нам удалось связать инструментарий двух группировок через особенности реализации сетевых протоколов. Отследить эволюцию инструментов группировки SilverFox – например, ПО Winos – по отпечатку процедуры сетевой коммуникации оказалось довольно сложной задачей, поэтому я решила поделиться кейсом. Подключайтесь к расследованию

https://habr.com/ru/companies/garda/articles/962222/

#разбор_атаки #Winos #Silverfox #вредоносы #фишинг #ValleyRAT #apt41 #winnti

Злоумышленники перенимают опыт коллег: что общего между SilverFox и APT41. Разбор атаки

Привет, Хабр! На связи Евгения Устинова, старший аналитик сетевой безопасности группы компаний «Гарда» . В статье хочу рассказать, как нам удалось связать инструментарий двух группировок через...

Хабр
Winnti APT41 Targets Japanese Firms in RevivalStone Cyber Espionage Campaign

Winnti’s RevivalStone campaign exploited an ERP SQL flaw to deploy upgraded malware, breaching an MSP and infecting multiple firms.

The Hacker News
China-linked APT group Winnti targets Japanese organizations

China-linked threat actor Winnti targeted Japanese companies in the manufacturing, materials, and energy sectors in March 2024.

Security Affairs

Trend Micro reported on the attack chain of a cyberespionage group Earth Freybug, which they claim is a subset of the Chinese state-sponsored APT41 (Winnti Group). No information about the targets or timeline, but they describe a new UNAPIMON malware used for defense evasion ( prevent child processes from being monitored). One SHA256 provided, which isn't recognized in VirusTotal. 🔗 https://www.trendmicro.com/en_us/research/24/d/earth-freybug.html

#China #cyberespionage #EarthFreybug #APT41 #Winnti #UNAPIMON #threatintel #IOC

Earth Freybug Uses UNAPIMON for Unhooking Critical APIs

This article provides an in-depth look into two techniques used by Earth Freybug actors: dynamic-link library (DLL) hijacking and application programming interface (API) unhooking to prevent child processes from being monitored via a new malware we’ve discovered and dubbed UNAPIMON.

Trend Micro

Recorded Future publishes a 24 page report on i-SOON and their connections to offensive cyberespionage operations attributed to RedHotel, RedAlpha and POISON CARP. The links indicate that they are likely sub-teams focused on specific missions within the same company. i-SOON's victims span 22 countries, with government, telco and education being the most targeted sectors. i-SOON also supports domestic including the targeting of ethnic and religious minorities and the online gambling industry. i-SOON very likely uses and sells access to custom malware families like Winnti and ShadowPad. IOC provided. 🔗 https://www.recordedfuture.com/attributing-i-soon-private-contractor-linked-chinese-state-sponsored-groups

#ISOON #cyberespionage #China #APT #threatintel #IOC #redhotel #redalpha #poisoncarp #winnti #shadowpad

Attributing I-SOON: Private Contractor Linked to Multiple Chinese State-sponsored Groups

Insikt Group uncovers ties between I-SOON and multiple Chinese state-sponsored cyber groups like RedAlpha and RedHotel.

LABSCon23 Replay | Chasing Shadows | The rise of a prolific espionage actor

YouTube

i-SOON: another company in the APT 41 network. Is Sichuan i-SOON an APT? Could Sichuan i-SOON stand behind Redhotel/Earth Lusca operations?

https://nattothoughts.substack.com/p/i-soon-another-company-in-the-apt41
#APT #apt41 #RedHotel #China #Earth Lusca #Winnti #chengdu404 #i-SOON

i-SOON: Another Company in the APT41 Network

A lawsuit casts light on the ecosystem of IT companies related to Chengdu 404, the company allegedly behind Chinese state-sponsored hacking group APT41.

Natto Thoughts
Major Gaming Companies Hit with Ransomware Linked to APT27 - Researchers say a recent attack targeting videogaming developers has 'strong links' to the infamou... https://threatpost.com/ransomware-major-gaming-companies-apt27/162735/ #ransomwareattack #gamingcompanies #cyberattacks #bronzeunion #supplychain #drbcontrol #ransomware #videogames #shellcode #covid-19 #malware #dropbox #winnti #hacks #apt27 #apt
Major Gaming Companies Hit with Ransomware Linked to APT27

Researchers say a recent attack targeting videogaming developers has 'strong links' to the infamous APT27 threat group.

Threatpost - English - Global - threatpost.com
Chinese Antivirus Firm Was Part of APT41 ‘Supply Chain’ Attack — Krebs on Security

Chinese Antivirus Firm Was Part of APT41 ‘Supply Chain’ Attack - The U.S. Justice Department this week indicted seven Chinese nationals for a decade-long hacking spr... https://krebsonsecurity.com/2020/09/chinese-antivirus-firm-was-part-of-apt41-supply-chain-attack/ #neer-do-wellnews #zackwhittaker #wickedspider #witheredrose #wickedpanda #chengdu404 #techcrunch #wickedrose #tandailin #anvisoft #barium #citrix #d-link #sonarx #winnti #apt41 #cisco #pulse
Chinese Antivirus Firm Was Part of APT41 ‘Supply Chain’ Attack — Krebs on Security