๐จ Threat Campaign Alert: "GambleForce" Threat group is targeting APAC organizations ๐จ
Summary: Relatively new threat group "GambleForce" has been attributed to a series of SQL injection attacks against companies primarily in the Asia-Pacific (APAC) region
Malware/Tools used: Cobalt Strike, dirsearch, sqlmap, tinyproxy, redis-rogue-getshell
Attack methods: SQL injections, CVE Exploitations
Exploited CVE: CVE-2023-23752
Target Country: China, India, Indonesia, Philippines, South Korea, Thailand, Australia, Brazil.
Target Industry: Gambling, Government, Retail, Travel sectors
Impact: Blackmail, System Compromise, Sensitive Data Exfiltration, steal funds
IOC_IPs:
212.60.5[.]129
38.54.40[.]156
IOC_Domains:
Dns-supports[.]online
Windows.updates[.]wiki
MITRE TTPs: T1217, T1008, T1003.001, T1039, T1005, T1132, T1003.003, T1003.004, T1003.005, T1436.001, T1556.002, T1556.003, T1566, T1573, T1599, T1045, T1003.008, T1024, T1032, T1046, T1033, T1064, T1219, T1135, T1074, T1105, T1204, T1486
Action: Threat Management/SOC professionals shall use the listed IOCs, TTPs to detect the subjected campaign activities and also to perform proactive Threat Hunting.
Reference: This writing is based on the security research advisory released by GROUP-IB.
---------------------------------------------------------------------------------------
๐Join us on our mission to secure the digital world and make cyber defense affordable to everyone! ๐ Follow "CyberXTron Technologies" for the timely, relevant and actionable cyber threat insights.
#GambleForce #SQLinjections #APACCyberAttacks #CyberSecurity ๐ก๏ธ๐