2023 Recap - Threat Actor Activity Highlights - North Korea
Dec 15, 2023 1:37:07 PM / by The Hivemind posted in Threat Bulletin, North Korea, APAC, 2023 Recap, Chollima
2023 Recap - Cyber Activity in the Gaza Conflict
Dec 11, 2023 3:08:36 PM / by The Hivemind posted in Threat Bulletin, Gaza, Hacktivism, Palestine, Israel, Hamas, BiBi-Linux, Conflict, Cyberwar, BiBi-Windows, SysJoker
Executive Summary
While tension in the Gaza region has existed for years, the all-out war that ignited in October 2023 brought with it a variety of cyber activity targeting both sides of the conflict. In this report, PolySwarm provides the highlights of cyber activity associated with the Gaza conflict in 2023.
2023 Recap - Cyberwar and Hacktivism in the Russia-Ukraine Conflict
Dec 8, 2023 1:17:32 PM / by The Hivemind posted in Ukraine, Russia, Threat Bulletin, Primitive Bear, Cozy Bear, Killnet, Cadet Blizzard, LitterDrifter, Ghost Writer, Fancy Bear, VooDoo Bear, RedStinger, Nodaria, Cyber Regiment, IT Army of Ukraine, KibOrg, NLB
Executive Summary
The Russia-Ukraine conflict has continued throughout 2023, with a plethora of both state-sponsored and hacktivist cyber activity taking place alongside kinetic warfare. In this report, PolySwarm provides the highlights of cyber activity associated with the Russia-Ukraine conflict in 2023.
Kinsing Exploiting CVE-2023-46604
Dec 4, 2023 1:29:39 PM / by The Hivemind posted in Threat Bulletin, Cryptominer, Kinsing, CVE-2023-46604
Executive Summary
Kinsing threat actors were recently observed leveraging CVE-2023-46604, a vulnerability affecting Apache ActiveMQ, to infect Linux systems with cryptominers and rootkits.
LummaC2
Dec 1, 2023 12:48:51 PM / by The Hivemind posted in Threat Bulletin, Stealer, LummaC2, Lumma
Executive Summary
A new variant of LummaC2 was observed using a unique trigonometry-based anti-sandboxing technique.
C3RB3R Exploiting CVE-2023-22518
Nov 20, 2023 2:13:05 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Cerber, C3RB3R, CVE-2023-22518
Related Families: Cerber
Executive Summary
A new Cerber variant tracked as C3RB3R was recently observed leveraging CVE-2023-22518.
SecuriDropper Android Malware
Nov 17, 2023 1:27:39 PM / by The Hivemind posted in Threat Bulletin, Android, Mobile, Ermac, SpyNote, SecuriDropper, Dropper-as-a-service
Related Families: SpyNote, Ermac
Executive Summary
SecuriDropper is a widely distributed dropper-as-a-service that bypasses Android Restricted Settings.
New MOVEit Activity
Nov 13, 2023 1:31:46 PM / by The Hivemind posted in Threat Bulletin, Government, Defense, CVE-2023-34362, MOVEit, Technology
Verticals Targeted: Defense, Government, Technology