Elektrine lite

← Feed

Just Another Blue Teamer

LeeArchinal@ioc.exchange

<p>A threat hunter that has a passion for logs, especially endpoint logs, and for teaching the next generation of Threat Hunters to come!</p><p>I have recently been awarded the honor to be a trainer at <a href="https://ioc.exchange/tags/BlackHat" class="mention hashtag" rel="tag">#<span>BlackHat</span></a> 2023, which is an amazing opportunity and a goal I had set for myself. I am truly flattered!</p>

Posts

  • Post #1845024

    Happy Wednesday all! Sometimes its good to take it back to the basics! Cisco Talos shares their insights and trends on adversaries using legitimate tools with nefarious intent! They discuss Living-off-the-land binaries (LOLBINs) and Remote Monitoring and Management (RMM) tools and the impact they can have! Enjoy and Happy hunting! When legitimate tools go rogue https://blog.talosintelligence.com/when-legitimate-tools-go-rogue/ Intel 471 Cyborg Security, Now Part of Intel 471 #ThreatIntel #Thr...

  • Post #1845023

    Good day everyone! A little while ago I stumbled across an article from Trend Micro that discussed the #Anubis ransomware and its abilities to act both as a ransomware and a wiper. Now it appears that the group has gained sensitive documents related to Disneyland Paris&amp;#39;s plans for new rides and renovations (Anubis X post is in the article). Not trying to fear-monger or anything but it goes to show how these groups will adapt their TTPs and behaviors to get to any organization. Anubis...

  • Post #1845022

    Happy Wednesday everyone! I came across this article from Check Point Software&amp;#39;s research team where they discuss a malware &amp;quot;prototype&amp;quot; they found that contained prompt injection to trick any LLM that it may be interacting with while it is being analyzed, aptly named Skynet. It attempted to sue the &amp;quot;Ignore all previous instructions&amp;quot; command adding another layer of sandbox evasion but was unsuccessful in this instance. The malware also contained an emb...

  • Post #1845021

    Happy Monday everyone and what a way to start it! I encourage you to read the latest report from The DFIR Report where they document an attack that started with a &amp;quot;password spray attack against an exposed RDP server&amp;quot; and ended in the #RansomHub ransomware strain being deployed in the victim&amp;#39;s environment and spread over SMB. I am going to forgo the brief summary because I truly believe these reports need to be read by you! But a bunch of LOLBINs were leveraged, inclu...

  • Post #1845020

    Happy Wednesday everyone! Elastic Security Labs researchers found a bunch of infostealers being spread by adversaries. In the past we have seen other tools like Brute Ratel and CobaltStrike but this time they decided to use a cracked version of #SHELLTER, another offensive security tool (OST). There are TONS of technical details about the tools they used during the investigation into the tool and what artifacts they found. Interestingly they are also releasing a &amp;quot;dynamic unpacker for b...

  • Post #1845019

    Good day everyone! Morphisec released an insightful report covering Iranian Cyber Warfare that is targeting the West and other enemies of Iran. The APT involved is #Pay2Key, &amp;quot;an Iranian-backed ransomware-as-as-service (RaaS) operation&amp;quot; that is linked to the Fox Kitten APT group and &amp;quot;closely tied to the well-known #Mimic ransomware.&amp;quot; Normally I call out behaviors and TTPs related but for this report I want to call out the completeness of the report. Not only...

  • Post #1845018

    Happy Wednesday everyone! News broke that #SaltTyphoon gained access to the U.S. National Guard&amp;#39;s network &amp;quot;and, among other things, collected its network configuration and its data traffic with its counterparts’ networks in every other US state and at least four US territories, according to a DOD report. This data also included these networks’ administrator credentials and network diagrams—which could be used to facilitate follow-on Salt Typhoon hacks of these units.&amp;quot;...

  • Post #1845017

    Good day everyone! Cisco Talos researchers report on a malware-as-a-service (MaaS) operation that was targeting Ukrainian entities and involved the #Amadey trojan, known for &amp;quot;collecting system information and downloading secondary payloads&amp;quot; and the #Emmenhtal downloader. Behaviors that are observed in this attack include a BUNCH of powershell activity with obfuscation and dropping a legitimate copy of PuTTY.exe. Looking at the technical details, they also us some URLs that m...

  • Post #1845015

    Happy Friday everyone! Researchers from the FortiCNAPP team, part of FortiGuard Labs identified a new variant of the #Lcryx ransomware called #Lcrypt0rx. The report states that it &amp;quot;is a relatively new VBScript-based ransomware strain first observed in November 2024&amp;quot; and &amp;quot;exhibits several unusual characteristics that suggest it may have been generated using AI.&amp;quot; According to the researchers, it currently only targets Windows machines. Indicators that led th...

  • Post #1845012

    Good day everyone! Somehow I missed this article when it first dropped but at least I found it! The DFIR Report published another great article that involved the #Bumblebee malware as the initial access vector that was installed after a user fell victim to an SEO poisoning campaign. The report states that &amp;quot;the threat actor moved laterally to a domain controller, dumped credentials, installed persistent remote access tools, and exfiltrated data using an SFTP client.&amp;quot; The adver...

  • Post #1845011

    Happy Friday everyone! Really thankful for the opportunity to join Arun Warikoo at the SANS Digital Forensics and Incident Response Summit to talk about my passion, Threat Hunting. We focused on how to prioritize a structured-hunt (hypothesis driven) and when to conduct an unstructured, or a data-structured hunt. A big thank you to Heather Barnhart and Phil Hagen for hosting and providing us the opportunity to speak at the event, it truly was an honor and an unforgettable experience! If you m...

  • Post #1845010

    Happy Monday everyone! Cisco Talos researchers report on a &amp;quot;malvertising campaign&amp;quot; that involved the #PS1Bot, which is modular and has &amp;quot;several modules delivered to perform a variety of malicious activities on infected systems.&amp;quot; It has the capability to capture keystrokes from their victim, conduct reconnaissance and establish persistence. This campaign involved Search Engine Optimization (SEO) poisoning and/or malvertising where the file name matched the k...

  • Post #1845009

    Happy Wednesday everyone! #GodRAT is a new remote trojan that is targeting financial institutions as reported by Kaspersky. According to their analysis, GodRAT is based on the #Gh0stRAT codebase and uses steganography to evade detection. It supports additional plugins that are used to explore the victim&amp;#39;s systems, deploy browser password stealers, and during the attack they even deployed the #AsyncRAT as a backup to maintain access. Looking at two password stealer payloads, it can giv...

  • Post #1845008

    Happy Monday everyone! CrowdStrike is reminding us that just because some of us use Macs, doesn&amp;#39;t mean we are malware proof! In this case the cybercriminal group dubbed #COOKIESPIDER was deploying their stealer known as #SHAMOS. Using a combination of malvertising and the #ClickFix technique, the group would trick their victim&amp;#39;s into installing the Shamos stealer which leads to it running &amp;quot;host reconnaissance and data collection tasks, including searching for known cr...

  • Post #1845007

    Happy Monday Everyone! I usually use this space to share workshops, articles, or insights from the community but today is a little different. I was humbled to see my name listed alongside so many amazing professionals as a nominee for the SANS Institute Difference Makers Award. This recognition isn’t about me, though. It’s about celebrating the people who push our field forward, make an impact, and inspire others. If someone has made a difference in your journey, I encourage you to take a mome...