NotLockBit Ransomware Targets MacOS
Nov 8, 2024 1:45:18 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Windows, LockBit, MacOS, NotLockBit
BitSloth
Aug 9, 2024 2:44:04 PM / by The Hivemind posted in Threat Bulletin, Windows, Backdoor, BITS, BitSloth
Verticals Targeted: Government
Executive Summary
BitSloth is a recently discovered Windows backdoor that uses a built-in feature called Background Intelligent Transfer Service (BITS) for C2.
Cosmic Leopard Activity Targets Windows, MacOS, & Android
Jun 17, 2024 3:15:17 PM / by The Hivemind posted in Threat Bulletin, Android, Windows, MacOS, Cosmic Leopard, GravityRAT, Operation Celestial Force, HeavyLift, GravityAdmin
Related Families: GravityRAT, HeavyLift, GravityAdmin
Verticals Targeted: Defense, Government, Technology
Executive Summary
Cosmic Leopard was observed targeting Windows, MacOS, and Android devices in a series of ongoing campaigns dubbed Operation Celestial Force. The threat actors used GravityRAT and HeavyLift to target entities in India.
KrustyLoader Backdoor
Mar 11, 2024 3:09:11 PM / by The Hivemind posted in Threat Bulletin, Windows, Linux, Backdoor, KrustyLoader, Avanti, UNC5221
Verticals Targeted: Government, Defense, Finance, Technology, Telecommunications, Aerospace, Pharmaceuticals
Executive Summary
Multiple industry sources recently reported on KrustyLoader, a Rust-based backdoor with both Windows and Linux variants.
Faust Ransomware
Feb 12, 2024 1:07:27 PM / by The Hivemind posted in Threat Bulletin, Ransomware, Windows, Faust, Phobos
Related Families: Phobos
Executive Summary
Faust is a newly discovered variant of Phobos ransomware delivered via an office document containing a malicious VBA script.
New Zloader Variant Discovered
Feb 9, 2024 1:16:59 PM / by The Hivemind posted in Threat Bulletin, Windows, Trojan, Zloader, ZeuS, 64-bit
Related Families: ZeuS
Executive Summary
A new variant of the modular trojan Zloader was recently identified. The new variant has been in development since September 2023.
Go-Based Proxy Targets Windows and Mac Systems
Aug 28, 2023 2:57:30 PM / by The Hivemind posted in Threat Bulletin, Windows, Mac, Proxy, Go
Executive Summary
A recent malware campaign delivered a proxy server application to both Windows and Mac systems, turning them into proxy exit nodes.
BlackSuit Ransomware
Jun 12, 2023 2:55:54 PM / by The Hivemind posted in Ransomware, Windows, Linux, Royal, BlackSuit, encryption
Related Families: Royal
Executive Summary
BlackSuit ransomware targets both Windows and Linux systems and bears a striking resemblance to Royal ransomware.