Related Families: Effluence
Cerber Ransomware Linux Variant Exploiting CVE-2023-22518
Apr 22, 2024 2:02:42 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Linux, Cerber, CVE-2023-22518, Confluence
Operation MidnightEclipse Leverages CVE-2024-3400
Apr 19, 2024 12:54:33 PM / by The Hivemind posted in Threat Bulletin, UPSTYLE, Operation MidnightEclipse, CVE-2024-3400
Related Families: UPSTYLE
Executive Summary
Since late March 2024, a threat actor dubbed UTA0218 has been leveraging a zero-day exploit of CVE-2024-3400.
DarkGate
Apr 15, 2024 3:29:16 PM / by The Hivemind posted in Threat Bulletin, Loader, DarkGate, CVE-2023-36025, CVE-2024-21412
Verticals Targeted: Financial
Executive Summary
DarkGate was observed in early 2024 in a campaign leveraging CVE-2024-21412 to target entities in the financial vertical.
Latrodectus
Apr 12, 2024 2:32:43 PM / by The Hivemind posted in Threat Bulletin, IcedID, DanaBot, Downloader, Latrodectus, TA577, TA578, IAB, initial access broker
Related Families: IcedID, DanaBot
Executive Summary
Latrodectus is a downloader first seen in the wild in late 2023. It has been used by threat actors who operate as initial access brokers (IAB).
INC Ransomware
Apr 8, 2024 2:23:53 PM / by The Hivemind posted in Threat Bulletin, Government, Ransomware, Healthcare, INC
Verticals Targeted: Government, Healthcare
Executive Summary
INC is a relatively new ransomware group that has been active since summer 2023. The group recently claimed responsibility for attacks on Leicester City Council and NHS services in Scotland.
Vultur Android Malware
Apr 5, 2024 1:49:09 PM / by The Hivemind posted in Threat Bulletin, Android, Brunhilda, Vultur, Mobile, Banker
Related Families: Brunhilda
Verticals Targeted: Financial
StrelaStealer Campaign Targeted US and EU
Apr 1, 2024 2:28:11 PM / by The Hivemind posted in Threat Bulletin, Government, Stealer, Energy, Manufacturing, Legal Services, Insurance, Construction, StrelaStealer, Email, Finance
Verticals Targeted: Technology, Finance, Legal Services, Manufacturing, Government, Energy, Insurance, Construction
Executive Summary
StrelaStealer was recently used in a widespread campaign targeting over 100 entities in the US and EU. The newest version of StrelaStealer is more advanced than previous versions and includes features to help thwart analysis.
AcidPour Wiper Targets Linux x86 Devices
Mar 29, 2024 12:44:53 PM / by The Hivemind posted in Ukraine, Russia, Threat Bulletin, Linux, AcidRain, AcidPour, x86
Related Families: AcidRain
Verticals Targeted: Telecommunications