#malwareanalysis

6 posts · Last used 1h

Back to Timeline
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 1h ago
Discover how the TAG-195 cybercriminal group utilizes the new ChonkyChicken modular malware to evade detection and expand its Malware-as-a-Service operations. #TAG195 #ChonkyChicken #MalwareAnalysis #Cybersecurity #GoldenChickens https://meterpreter.org/tag-195-chonkychicken-modular-malware/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 5h ago
Discover how the SANDWORM_MODE worm targets AI toolchains, developer environments, and supply chains to exfiltrate secrets and wipe files. #SANDWORM_MODE #Cybersecurity #SupplyChainAttack #AIToolchain #MalwareAnalysis https://meterpreter.org/sandworm-mode-worm-attack/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · 2d ago
Discover VMRay Labs' execution-level analysis of Operation STANDOFF, a Russian-speaking multi-operator campaign deploying stealer malware and AI bots. #OperationSTANDOFF #VMRayLabs #MalwareAnalysis #Infostealers #Cybersecurity https://meterpreter.org/operation-standoff-intrusion-campaign/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0
hasamba @hasamba@infosec.exchange · 4d ago

🎯 Threat Intelligence

Group-IB Threat Intelligence has identified HOLLOWGRAPH, a .NET NativeAOT-compiled DLL malware attributed with high confidence to the Cavern backdoor framework. The malware transforms Microsoft 365 calendars into covert command-and-control channels using the Microsoft Graph API, communicating through a compromised Israeli mailbox.

🔹 Technical Overview

HOLLOWGRAPH operates with only two commands: get and send. Both execute exclusively through trusted Microsoft cloud infrastructure. The malware never reaches out directly to attacker-owned servers. Instead, it uses the Microsoft Graph API to treat a compromised mailbox's calendar as a two-way dead-drop.

🔹 C2 Mechanism

The calendar-based C2 works as follows:

  1. Tasking: Operators plant calendar events containing encrypted commands as attachments.
  2. Exfiltration: The implant creates its own calendar events with encrypted stolen data attached as files.
  3. Concealment: Every event is dated to 13 May 2050, ensuring the mailbox owner is unlikely to notice them.

All Graph payloads use hybrid RSA + AES encryption. Two separate key pairs keep tasking and exfiltration channels cryptographically independent.

🔹 Credential Renewal Channel

HOLLOWGRAPH maintains a secondary communication channel through DNS tunneling. It performs IPv6 AAAA record queries against the attacker-controlled domain cloudlanecdn[.]com to refresh its Microsoft Entra ID (Azure AD) credentials. Updated values are written to an on-disk configuration file named logAzure.txt.

This dual-channel architecture provides resilience. Even if the primary Graph API channel is disrupted, the malware can continue receiving refreshed authentication tokens through DNS.

🔹 Victimology

Group-IB identified 12 systems carrying the implant. Only approximately three were actively communicating with attacker infrastructure. The recovered indicators, an Israeli mailbox used for exfiltration and malware samples uploaded from Israel, suggest focused interest in Israeli entities rather than broad opportunistic compromise.

🔹 Detection Considerations

Defenders monitoring Microsoft 365 environments should look for: • Calendar events with future dates far beyond typical scheduling horizons (e.g., 2050) • Unusual file attachments on calendar entries • DNS queries to cloudlanecdn[.]com with AAAA record types • The on-disk artifact logAzure.txt • Authentication patterns from .NET NativeAOT binaries interacting with Microsoft Graph API

🔹 Attribution

Group-IB links HOLLOWGRAPH to the Cavern backdoor framework with high confidence, based on code and behavioral similarities with known Cavern components.

🔹 HOLLOWGRAPH #ThreatIntelligence #C2 #Microsoft365 #MalwareAnalysis

🔗 Source: https://www.group-ib.com/blog/hollowgraph-microsoft-365/

0
0
0
thecybersecguru @thecybersecguru@infosec.exchange · Jul 15, 2026
🚨 High-Severity FortiSandbox Flaw Disclosed CVE-2026-59835 (CVSS 7.7) allows unauthenticated attackers to access VNC servers used by FortiSandbox malware analysis VMs, potentially exposing malware samples, analysis sessions, screenshots, and security research activities. ✅ No authentication required ✅ Network exploitable ✅ Patch available If you're running FortiSandbox 5.0.x or 4.4.x, prioritize updates immediately. 🔗 Full technical breakdown: https://thecybersecguru.com/news/fortisandbox-cve-2026-59835-vnc-vulnerability/ #CVE2026-59835 #Fortinet #FortiSandbox #CyberSecurity #InfoSec #Vulnerability #ThreatIntel #BlueTeam #SOC #MalwareAnalysis #SecurityResearch #PatchNow #CVE #CyberThreats
0
0
0
Lenny Zeltser @lennyzeltser@infosec.exchange · Jul 02, 2026
Threat attribution works at 3 levels: Tactical examines the incident, operational characterizes the campaign, and strategic asks who's responsible and why. Disciplined analysts weigh the same 6 signals at every level. https://zeltser.com/six-signals-for-threat-attribution #malwareanalysis #incidentresponse
0
0
0

You've seen all posts