#threatintelligence

197 posts · Last used 8d

(truesec.com) Denmark Raises Threat Level for Destructive Cyberattacks Amid Escalating Russian Hybrid Warfare In brief - This article discusses the increased risk of destructive cyberattacks in Denmark and Europe, driven by Russian hybrid warfare aimed at pressuring nations to reduce support for Ukraine. Technically - This article categorizes the threat landscape into cybercrime, espionage, and cyber warfare, noting that while crime remains the most common threat, Russian state-sponsored activity is escalating. Technical vectors identified include Distributed Denial of Service (DDoS) attacks, the compromise of CCTV systems, and the manipulation of unprotected critical infrastructure components. Furthermore, the report highlights the use of proxy or disposable agents to target defense sector supply chains, factories, and warehouses through destructive cyber operations. Source: https://www.truesec.com/hub/blog/danish-intelligence-services-raises-threat-for-destructive-cyberattacks #ThreatIntelligence #ThreatIntel #Cybersecurity #Infosec
1
0
2
0
Quiz time: which of these domains is impersonating Apple? quizearny[.]shop, rewardquiz[.]org look like generic quiz sites. applerewards[.]net is more obvious. All of them belong to a cluster serving identical Apple impersonation content, prompting victims to claim an Apple gift card reward by handing over their personal details. testar[.]ink, "to test", was the first to be created, nearly a month before the others went live, which may say something about how this campaign got started. What makes this cluster more interesting is what happens after you click the "Claim Your Apple Reward" button on the initial page. Different locations, different device types, different destinations. Classic TDS. This cluster is a good reminder that brand impersonation lives in the page content, not just the domain name. A quiz site with no Apple in its name can be just as dangerous as an obvious lookalike. #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #axur #lookalike #scam #tds
0
0
9
0
validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling. Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains. The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar. The tunnel itself is answering with TXT records like: ⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz" As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this. We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block :ablobcatpopcorn: We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly. Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you. ⛔ validx[.]shop ⛔ cordkit[.]online ⛔ zenithly[.]best ☠️ 95[.]179[.]159[.]229 #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2
16
0
18
0
🚨New ransom group blog posts!🚨 Group name: AuditTeam Post title: vit.ac.in Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: TEK SPB Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: kit-e.jp Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: krimax.org Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: gownet.net Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: dg.ac.kr Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: buben Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: Wise IT Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: palletshop Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: PIT.local Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: mansurovogroup Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: Demidov Steel Group Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: I-SYS Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: Mopas Online Supermarket Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: Trésor Public Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: joycity Info: https://cti.fyi/groups/AuditTeam.html Group name: AuditTeam Post title: Kawasaki Motors Philippines Corporation Info: https://cti.fyi/groups/AuditTeam.html #ransomware #cti #threatintelligence #cybersecurity #infosec
0
0
0
0
Netskope observed malicious Google Ads redirecting to cross-platform tech-support scams affecting Windows and macOS users across 619 organizations. The abuse of trusted ad delivery on high-traffic sites bypasses traditional web filtering and increases social engineering success. #Malvertising #TechSupportScam #ThreatIntelligence https://cyberworldops.eu/en/malicious-google-ads-turn-browser-tricks-into-cross-platform-tech
0
0
0
0
---------------- 🦠 Malware Analysis =================== Settra is a ransomware operation first identified in June 2026 that has already claimed 50-70+ enterprise victims across technology, manufacturing, financial services, healthcare, and retail sectors. The group operates double-extortion: data exfiltration followed by encryption and ransom negotiation via Tox and darknet portals. 🔹 Intrusion Methodology Human-operated intrusions begin through compromised VPNs or valid accounts. Credential dumping uses Mimikatz and ProcDump. Lateral movement relies on dual-use tools including PAExec and NetExec. Durable remote access is established via Mesh Agent. Before encryption, operators abuse signed STProcessMonitor drivers via BYOVD to blind endpoint defenses. 🔹 Encryptor Architecture The encryptor is a two-stage design recovered through offline static reverse engineering by Cynet Research Labs. Outer loader (win64.exe): • Password-gated entry • PEB export hashing for API resolution • Anti-debugging gates • ~200,000-round SHA-256 KDF for key derivation • AES-256-CTR decryption of inner payload • Custom LP77 decompression • Process hollowing into a suspended self-copy Inner PE payload executes systematic anti-forensics: • Wipes 12 targeted event logs via wevtutil • Purges Windows Prefetch • Deletes PowerShell command history • Wipes USN change journals • Disables Windows Recovery (reagentc, bcdedit, wbadmin, Disable-ComputerRestore) • Resizes VSS shadow storage stealthily • Powers down Hyper-V VMs via WMI (ROOT\virtualization\v2) to release .vhdx file locks 🔹 Cryptography Files encrypted using Windows CNG (BCryptGenRandom, BCryptEncrypt) with unique symmetric keys wrapped by an embedded 4096-bit RSA-1 public key. Files renamed to .locked (preceded by temporary .locked_wip). The RSA private key is never present on the victim host. The encryptor contains zero C2 network communication stacks, making it fully offline. 🔹 Detection Claims Cynet claims proactive interception within 1 second of detonation via kernel-level driver decoy traps. This is a vendor claim from the same organization that performed the analysis, so treat with appropriate skepticism. 🔹 Key Takeaways The encryptor design is notable for its complete lack of network communication, heavy anti-forensics targeting recovery infrastructure, and deliberate Hyper-V shutdown to access locked virtual disks. The BYOVD approach using signed STProcessMonitor drivers is increasingly common in ransomware operations. 🔹 ransomware #malware #threatintelligence #BYOVD #reverseengineering 🔗 Source: https://www.cynet.com/settra-ransomware-inside-a-new-enterprise-grade-extortion-threat/
0
0
0
0
Replying to
Reward: You've received the Summer 2026 Memorial Plaque. It hangs where your incident response plan used to be. https://www.darkreading.com/cyberattacks-data-breaches/3-cyber-threats-defined-summer-2026 #CyberSecurity #Ransomware #ThreatIntelligence #CriticalInfrastructure #AISecurityThreats #SummerOfCyberChaos (3/3)
0
0
0
0
Replying to
Reward: You've received a laminated Storm-2570 Awareness Certificate. It does not stop ransomware. https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments #Ransomware #ThreatIntelligence #Storm2570 #CyberSecurity #APT #FollowTheTrail (3/3)
0
0
0
0
🚨New ransom group blog posts!🚨 Group name: Spirals Post title: Armada Credit Bureau Info: https://cti.fyi/groups/Spirals.html Group name: Spirals Post title: ASYAD GROUP Info: https://cti.fyi/groups/Spirals.html Group name: N0n Post title: FinSoft (Kolibri retail back-office software) Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: AFRICA-TECH (IT services / document processing) Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: Fanatics (global sports commerce platform) Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: United Federation of Teachers Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: AstraZeneca Türkiye Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: BeLi Teacher / FSC education centers (AWS) Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: Argentem Creek Partners (investment firm) Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: Ministry of Education — Argentina Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: PayPal support operations (Transcom WorldWide) Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: STOKR (digital securities platform) Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: Vietnamese betting operator (GC789 network / Boundless TE) Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: Konnatus (usucapião legal services) Info: https://cti.fyi/groups/N0n.html Group name: N0n Post title: Inter (Venezuela's largest internet provider) Info: https://cti.fyi/groups/N0n.html #ransomware #cti #threatintelligence #cybersecurity #infosec
0
0
0
0
(intel471.com) SANS 2026 Threat Hunting Survey: Adversaries Prioritize Stealth Over Speed as Defenders Reevaluate AI's Role In brief - This article discusses the 2026 SANS Threat Hunting Survey, highlighting a shift where adversaries prioritize stealth and living-off-the-land techniques over speed, while defenders face challenges with data quality and a cooling interest in AI-driven hunting. Technically - This article analyzes the prevalence of 'living-off-the-land' (LotL) tactics, noting that 72.7% of nation-state actors use legitimate admin tools to blend into system activity. It emphasizes the use of anti-forensic tradecraft, such as clearing Windows Event Logs (via wevtutil) and deleting shadow copies to inhibit recovery. The text identifies MITRE ATT&CK technique T1041 (Exfiltration Over C2 Channel) as a dominant observation and stresses the necessity of behavioral baselining to identify anomalies in process lineages and account interactions. Furthermore, it addresses the technical debt of poor data engineering, specifically the lack of normalization across disparate telemetry sources and the risk of visibility gaps created by misconfigured API gateways and SSO proxies. Source: https://www.intel471.com/blog/2026-sans-threat-hunting-survey-adversaries-prizing-stealth-over-speed-defenders-cooling-on-ai #ThreatIntelligence #ThreatIntel #Cybersecurity #Infosec
0
0
0
0
🚨New ransom group blog posts!🚨 Group name: pear Post title: Indroj Medical Group Inc. Info: https://cti.fyi/groups/pear.html Group name: pear Post title: Martin Lawrence Galleries Info: https://cti.fyi/groups/pear.html Group name: pear Post title: Westside GI Info: https://cti.fyi/groups/pear.html #ransomware #cti #threatintelligence #cybersecurity #infosec
0
0
0
0
🚨New ransom group blog posts!🚨 Group name: Booba Project Post title: Smart Eye Care Info: https://cti.fyi/groups/Booba Project.html Group name: Booba Project Post title: The Merrimack County Info: https://cti.fyi/groups/Booba Project.html Group name: Booba Project Post title: COSEF - Consorzio di Sviluppo Economico del Friuli Info: https://cti.fyi/groups/Booba Project.html #ransomware #cti #threatintelligence #cybersecurity #infosec
0
0
0
0
🚨New ransom group blog posts!🚨 Group name: BrainCipher Post title: ACCSync29042019.BAK Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: BeforeDocSync.BAK Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: BeforeRemovingNewthings_19052025.bak Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: COMPANY.zip Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: Com_ON_20052025BF4Restore.BAK Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: DATA.zip Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: Desktop.david.zip Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: FANTASY_SRV.zip Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: HRD_Lab_Results.BAK Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: IGI_Lab_Results.BAK Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: Report Project1.rptproj.bak Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: WEX.zip Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: WINDIAM_ACC_ON_backup_2026_07_18_220022_2852655.bak Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: WINDIAM_COM_ON_backup_2026_07_18_220022_3321457.bak Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: Windiam_ACC_OFF.BAK Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: Windiam_ACC_OFF_backup_2019_05_02_220006_8273415.bak Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: Windiam_B4V_2018_07_08.bak Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: Windiam_to_clean.BAK Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: rst.zip Info: https://cti.fyi/groups/BrainCipher.html Group name: BrainCipher Post title: windiam_net_ON_OpenStock.BAK Info: https://cti.fyi/groups/BrainCipher.html #ransomware #cti #threatintelligence #cybersecurity #infosec
0
0
0
0