Check out this awesome report by Sophos on Chinese APT threat actors. There is much to learn from this technical breakdown; it's not your ordinary threat actor.
Reading this report, you will notice that they used tools like impacket for lateral movement, which provides an opportunity for detection.
➡️Interesting use of Living-Off-the-Land binaries that I personally haven't seen before - instsrv.exe and srvany.exe.
➡️Multiple defense evasion methods to hide their tracks and evade detection, including a clever way to read DNS traffic and block AV/EDR-related domains. (but still uses impacket 🤷♂️🤦♂️)
➡️Interesting choice of data being staged for exfiltration.
Overall, this prolonged intrusion had everything, and the authors did an incredible job of laying out all the details for the rest of the community. 🙏👏
Check it out here 🔗: news.sophos.com/en-us/2024/0…
Cado Security is honored to be named in the Gartner® Emerging Tech: Emergence Cycle for Cloud Security as a Sample Vendor for Cloud Forensics
Download a free copy of the report here: hubs.li/Q02yBRv50
@eric_capuano made a great beginner lab to learn Prefetch Analysis for #DFIR work.
I made a simple walkthrough video showing you how to setup the lab and get started, so no need to feel overwhelmed.
Get in there and start learning!
youtu.be/xvUbJk4wNo8?si=vkPD…
ATTN NERDS 🤓
this week we released our new @limacharlieio plaso extension! 🔥
it will take a forensic artifact from an endpoint, or a zip of artifacts (like a KAPE triage from the @velocidex extension) and make a timeline of the data that can be imported into @TimesketchProj
In 2014, @JohnHultquist named a Russian hacking group "Sandworm".
Today, Mandiant graduates it to APT44 & reveals the online persona they created, CyberArmyofRussia, disrupted U.S. and Polish water utilities, as well as a dam in France.
Full report: services.google.com/fh/files…
🎁 Today I'm giving away 3 of our DFIR Labs! 🎁
To enter:
✅Follow me
✅RT & Like this post
✅Reply with which case you'd like to take
The winners will be selected in 24 hours. #Giveaway
🎉 Announcing DFIR Labs! 🎉
Introducing our DFIR Labs based on real intrusions from our public reports and private threat briefs! Whether you're starting out or looking to deepen your skills, our labs can help.
1/2
The xz backdoor was the final part of a campaign that spanned two years of operations. These operations were predominantly HUMINT style agent operations. There was an approach that lasted months before the Jia Tan persona was well positioned to be given a trusted role.
It's here! Fully automated🔒Elastic Security server and agents for your Ludus labs. @__ar0d__ and I have made this one as easy as adding the roles to your config.
Comes with:
-ELK Fleet Detection engine
-Auto agent install registration
-Detection rules
docs.ludus.cloud/docs/Enviro…
#Horabot dirigido a empresas de México 🇲🇽
.ZIP > .HTML > .RAR > .CMD > .PS1
Los correos phishing son enviados desde dominios temporary[.]link y traen adjunto un archivo .HTML (comprimido en un .ZIP) que inicia la descarga maliciosa.
Los archivos .HTML incluyen el nombre de la empresa objetivo (víctima potencial) 👀
Siguientes etapas desde:
1.- https://facturasmex[.]cloud/b08/
2.- http://ca1[.]sytes[.]net/22/22
3.- https://www.dropbox[.]com/scl/fi/k6hxua7lwt1qcgmqou6q3/m[.]zip (URLs van rotando)
Otros dominios utilizados ↓
1ra etapa:
- facturasm[.]cloud
- adbd[.]tech
- satventasfac[.]tech
- facturasmex[.]cloud
- facturasm[.]cloud
- archivosdwn[.]cloud
- facturas[.]co[.]in
2da etapa:
ca1.sytes[.]net
ad2.gotdns[.]ch
adbd[.]tech
tths.ddns[.]net
Please wishlist my new game KingMakers on Steam. We've been working really hard on this for 5 years, and can finally unveil it to the public today. Hope you guys like it 🤞