Executive Summary
Microsoft recently reported on Royal ransomware, a ransomware family used by the threat actor DEV-0569
Royal Ransomware
Dec 1, 2022 1:22:05 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, Royal, DEV-0569
Malware Leverages CAPTCHA to Bypass Browser Warning
Nov 23, 2022 1:00:33 PM / by PolySwarm Tech Team posted in Threat Bulletin, Malware, CAPTCHA, TTPs, Gozi, Ursnif
Related Families: Gozi (Ursnif)
Verticals Targeted: Financial
Executive Summary
Bleeping Computer recently reported on a malware campaign that uses CAPTCHA to bypass browser warnings and deliver Gozi. This technique appears to be a novel TTP for threat actors.
Phishing and Android Malware Campaign Targets Indian Banks
Nov 21, 2022 1:12:25 PM / by PolySwarm Tech Team posted in Threat Bulletin, Financial, India, Android, Phishing, Elibomi, FakeReward, AxBanker, IcRA, IcSpy
Related Families: Elibomi, FakeReward, AxBanker, IcRAT, IcSpy
Verticals Targeted: Financial
Executive Summary
Trend Micro recently reported on a phishing and Android malware campaign targeting clients of multiple banks in India. The campaign leverages multiple malware families, including Elibomi, FakeReward, AxBanker, IcRAT, and IcSpy.
Azov Ransomware Built to Wipe Data
Nov 17, 2022 1:36:37 PM / by PolySwarm Tech Team posted in Ukraine, Threat Bulletin, Ransomware, Azov
Executive Summary
Azov ransomware is a recently discovered malware family being distributed through pirated software, keygens, and adware bundles. It acts as a wiper and is capable of backdooring 64-bit executables. It also uses a unique pattern for overwriting files.
Recent Threats to the Healthcare Vertical
Nov 14, 2022 12:49:52 PM / by PolySwarm Tech Team posted in Threat Bulletin, Ransomware, Healthcare, Data Theft, Extortion, Data Leak
Verticals Targeted: Healthcare
Executive Summary
Multiple incidents in the last few months highlight the ongoing threats to the Healthcare vertical. These incidents have included data leaks, data theft and extortion, ransomware, and other cyber attacks.
Android Droppers on Google Play Store Distribute Banking Trojans
Nov 10, 2022 1:42:53 PM / by PolySwarm Tech Team posted in Threat Bulletin, Banking, Financial, Android, Trojan, Sharkbot, Brunhilda, Vultur
Verticals Targeted: Financial
Executive Summary
ThreatFabric recently reported on multiple Android droppers found on the Google Play Store distributing banking trojans.
Winnti Targets Hong Kong With Spyder Loader
Nov 7, 2022 1:37:10 PM / by PolySwarm Tech Team posted in Threat Bulletin, Espionage, APT41, Wicked Panda, China, Winnti, Loader, Spyder Loader
Verticals Targeted: Government
Executive Summary
Symantec recently reported on Spyder Loader, a tool used by Chinese nexus state-sponsored threat actor group Winnti to target government entities in Hong Kong.
Prestige Ransomware
Nov 3, 2022 2:37:56 PM / by PolySwarm Tech Team posted in Ukraine, Threat Bulletin, Ransomware, Poland, Prestige
Verticals Targeted: Transportation, Logistics
Executive Summary
Microsoft Threat Intelligence Center recently reported on Prestige ransomware. A novel ransomware family used to target entities in Ukraine and Poland in October 2022.