Background
CERT-UA, the Ukraine government’s incident response team, recently released a report on MicroBackdoor. CERT-UA did not provide further information on the scope of the incident leading to the discovery of this malware.
MicroBackdoor
Mar 11, 2022 1:28:25 PM / by PolySwarm Tech Team posted in Ukraine, Threat Bulletin, MicroBackdoor, UNC1151, Belarus, First Seen
Jester Stealer
Mar 10, 2022 1:10:05 PM / by PolySwarm Tech Team posted in Threat Bulletin, Jester Stealer, Stealer
Background
Cyble recently published research on Jester Stealer, an info stealer known to harvest login credentials, cookies, payment card details, and other information.
HermeticWiper & IsaacWiper Target Ukraine
Mar 9, 2022 1:34:55 PM / by PolySwarm Tech Team posted in Ukraine, Threat Bulletin, IsaacWiper, HermeticWiper, WhisperGate, HermeticWizard, HermeticRansom, FoxBlade
Background
Ukraine was recently targeted by several wiper malware families. In January, WhisperGate, which was attributed to a Belarusian threat actor group known as Ghostwriter/UNC1151, targeted Ukraine’s government, non-profit, and technology verticals. On February 23, another wiper malware dubbed HermeticWiper or FoxBlade was used to target Ukraine. On February 24, a third wiper malware was observed targeting Ukrainian entities. This new malware was dubbed IsaacWiper. ESET recently published research on HermeticWiper and IsaacWiper.
Daxin Backdoor
Mar 4, 2022 2:06:59 PM / by PolySwarm Tech Team posted in Threat Bulletin, Espionage, China, Owlproxy, Daxin
Background
Symantec recently published research on Daxin backdoor, which they called the “most advanced” malware they have seen from Chinese threat actors.
Sugar Ransomware Targets Individuals Instead of Enterprises
Mar 3, 2022 2:59:22 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, RaaS, Sugar
Background
Walmart recently reported on a new ransomware as a service (RaaS) called Sugar ransomware. The threat actors behind Sugar ransomware appear to be targeting individuals rather than enterprises and demand a low ransom amount, based on the number of files encrypted.
BlackByte Ransomware Targets Critical Infrastructure
Mar 1, 2022 2:42:23 PM / by PolySwarm Tech Team posted in Threat Bulletin, Critical Infrastructure, BlackByte, Ransomware
Background
The FBI and US Secret Service released an advisory regarding BlackByte ransomware, which compromised multiple US and foreign businesses, including three entities that are part of US critical infrastructure. These three unnamed entities belonged to the government, financial, and food and agriculture verticals. The threat actors behind BlackByte also claimed they hacked networks belonging to the San Francisco 49ers in mid-February 2022.
Wicked Panda’s ShadowPad RAT
Feb 28, 2022 2:31:59 PM / by PolySwarm Tech Team posted in Threat Bulletin, APT41, Shadow Pad, China, Winnti, Axiom
Background
Secureworks recently posted research analyzing Wicked Panda’s ShadowPad RAT. Secureworks stated multiple clusters of ShadowPad activity appeared to be linked to PLA theater commands.
Russian Websites Down As Russia Fears Critical Infrastructure Attacks
Feb 25, 2022 4:06:31 PM / by PolySwarm Tech Team posted in Ukraine, Russia, Threat Bulletin, Critical Infrastructure
PolySwarm Threat Bulletin
THIS THREAT BULLETIN IS PROVIDED FOR SITUATIONAL AWARENESS
Background
This report is part of our ongoing coverage of the Russia-Ukraine conflict and cyber implications.
PolySwarm recently released the following publications and blog posts discussing Russia-Ukraine tensions and the potential for both kinetic and cyber conflict: