#PhotoOfTheDay: #Coathanger Cluster Redux
The Coathanger is actually an #Asterism in the dim, little constellation of Vupecula. It's a happenstance alignment of stars and not a true open star cluster.
The nearest stars in this tight grouping are over 4,000 light years distant.
Photographer: Greg Parker
1/3
https://epod.usra.edu/blog/2025/02/coathanger-cluster-redux.html
Release 301 Cybercrimeinfo
This edition of our newsletter highlights the fight against cyber threats such as #COATHANGER malware, #space weapons from #Russia, and tackling #drug shipments via the #darkweb. We discuss recent #cyber attacks, offer tips for digital resilience and highlight a case of #bankhelpdesk fraud, emphasising the importance of vigilance and cooperation.
Download the newsletter, subscribe or watch the video via this link: https://www-ccinfo-nl.translate.goog/nieuwsbrief-archief/nieuwsbrief-berichten/1681483_nieuwsbrief-301-cybercrimeinfo-ccinfo-nl?_x_tr_sl=nl&_x_tr_tl=en&_x_tr_hl=nl&_x_tr_pto=wapp
#COATHANGER is only part of the story.
If you’re curious about Chinese cyber espionage, be sure to check out Hunt & Hackett's threat profile, where we break down China’s geopolitical relations, strategic motives, and how these relate to their #cyber campaigns.
Dutch intelligence agency publishes detailed technical analysis of the COATHANGER malware they found in their network, originating from Chinese state-sponsored actors.
"""
It hides itself by hooking system calls that could reveal its presence. It survives reboots and
firmware upgrades. [..]
First libpe.so will check if the contents of /proc/[pid]/cmdline starts with [..]
"""
via https://www.ncsc.nl/documenten/publicaties/2024/februari/6/mivd-aivd-advisory-coathanger-tlp-clear
**Ministry of Defence of The Netherlands uncovers #coathanger, a stealthy Chinese #fortigate RAT**
“The COATHANGER #malware is stealthy and persistent. It hides itself by hooking system calls that could reveal its presence. It survives reboots and firmware upgrades.”
“MIVD & AIVD assess with high confidence that the **intrusion at the MOD**, as well as the development of the malware described in this report, was conducted by a state-sponsored actor from […] China.“
https://www.ncsc.nl/documenten/publicaties/2024/februari/6/mivd-aivd-advisory-coathanger-tlp-clear