03/23

DEV-0537 criminal actor targeting organizations for data exfiltration and destruction - Microsoft Security Blog

https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/
DEV-0537 criminal actor targeting organizations for data exfiltration and destruction - Microsoft Security Blog

Updated Okta Statement on LAPSUS$ | Okta

https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/
Updated Okta Statement on LAPSUS$ | Okta

Microsoft and Okta Confirm Breach by LAPSUS$ Extortion Group

https://thehackernews.com/2022/03/microsoft-and-okta-confirm-breach-by.html
Microsoft and Okta Confirm Breach by LAPSUS$ Extortion Group

Mustang Panda’s Hodur: Old tricks, new Korplug variant | WeLiveSecurity

https://www.welivesecurity.com/2022/03/23/mustang-panda-hodur-old-tricks-new-korplug-variant/
Mustang Panda’s Hodur: Old tricks, new Korplug variant | WeLiveSecurity

Not So Lazarus: Mapping DPRK Cyber Threat Groups to Government Organizations | Mandiant

https://www.mandiant.com/resources/mapping-dprk-groups-to-government
Not So Lazarus: Mapping DPRK Cyber Threat Groups to Government Organizations | Mandiant

Microsoft confirms they were hacked by Lapsus$ extortion group

https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-they-were-hacked-by-lapsus-extortion-group/
Microsoft confirms they were hacked by Lapsus$ extortion group

A Closer Look at the LAPSUS$ Data Extortion Group – Krebs on Security

https://krebsonsecurity.com/2022/03/a-closer-look-at-the-lapsus-data-extortion-group/
A Closer Look at the LAPSUS$ Data Extortion Group – Krebs on Security

Cloudflare’s investigation of the January 2022 Okta compromise

https://blog.cloudflare.com/cloudflare-investigation-of-the-january-2022-okta-compromise/
Cloudflare’s investigation of the January 2022 Okta compromise

Resources for Retired Events Links | 6Connex Event Tech

https://securityweek.6connex.com/event/SecuritySummit/en-us#!/Auditorium/n1418636
Resources for Retired Events Links | 6Connex Event Tech

Okta’s Investigation of the January 2022 Compromise | Okta

https://www.okta.com/blog/2022/03/oktas-investigation-of-the-january-2022-compromise/
Okta’s Investigation of the January 2022 Compromise | Okta

GOLD ULRICK leaks reveal organizational structure and relationships | Secureworks

https://www.secureworks.com/blog/gold-ulrick-leaks-reveal-organizational-structure-and-relationships
GOLD ULRICK leaks reveal organizational structure and relationships | Secureworks

CVE-2021-22555: Turning \x00\x00 into 10000$ | security-research

https://google.github.io/security-research/pocs/linux/cve-2021-22555/writeup.html
CVE-2021-22555: Turning \x00\x00 into 10000$ | security-research

Operation Dragon Castling: APT group targeting betting companies - Avast Threat Labs

https://decoded.avast.io/luigicamastra/operation-dragon-castling-apt-group-targeting-betting-companies/
Operation Dragon Castling: APT group targeting betting companies - Avast Threat Labs

2244 - containerd: Insecure handling of image volumes - project-zero

https://bugs.chromium.org/p/project-zero/issues/detail?id=2244
2244 - containerd: Insecure handling of image volumes - project-zero

Tweet / Twitter

https://twitter.com/williamturton/status/1506739931456155648
Tweet / Twitter

CERT-UA

https://cert.gov.ua/article/38088
CERT-UA

New Variant of Chinese Gimmick Malware Targeting macOS Users

https://thehackernews.com/2022/03/new-variant-of-chinese-gimmick-malware.html
New Variant of Chinese Gimmick Malware Targeting macOS Users

Bloomberg - Are you a robot?

https://www.bloomberg.com/news/articles/2022-03-23/teen-suspected-by-cyber-researchers-of-being-lapsus-mastermind?sref=ylv224K8
Bloomberg - Are you a robot?

Azure Dominance Paths - Cloudbrothers

https://cloudbrothers.info/en/azure-dominance-paths/
Azure Dominance Paths - Cloudbrothers

Botnet of Thousands of MikroTik Routers Abused in Glupteba, TrickBot Campaigns

https://thehackernews.com/2022/03/over-200000-microtik-routers-worldwide.html
Botnet of Thousands of MikroTik Routers Abused in Glupteba, TrickBot Campaigns

Malware-IOCs/2022-03-23_CobaltStrike_C2 at main · CronUp/Malware-IOCs · GitHub

https://github.com/CronUp/Malware-IOCs/blob/main/2022-03-23_CobaltStrike_C2
Malware-IOCs/2022-03-23_CobaltStrike_C2 at main · CronUp/Malware-IOCs · GitHub

MalwareBazaar | SHA256 e93cc14c93709b38dc8d95fb58d70d1a8930576c7d16c64c3efbc4cc08d951ff (AZORult)

https://bazaar.abuse.ch/sample/e93cc14c93709b38dc8d95fb58d70d1a8930576c7d16c64c3efbc4cc08d951ff/
MalwareBazaar | SHA256 e93cc14c93709b38dc8d95fb58d70d1a8930576c7d16c64c3efbc4cc08d951ff (AZORult)

https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt

https://feodotracker.abuse.ch/downloads/ipblocklist_recommended.txt

Raccoon Stealer – An Insight into Victim “Gates”

https://team-cymru.com/blog/2022/03/23/raccoon-stealer-an-insight-into-victim-gates/
Raccoon Stealer – An Insight into Victim “Gates”

IOCs/2022-03-23-AA-Qakbot-data-dump.zip at main · brad-duncan/IOCs · GitHub

https://github.com/brad-duncan/IOCs/blob/main/2022-03-23-AA-Qakbot-data-dump.zip
IOCs/2022-03-23-AA-Qakbot-data-dump.zip at main · brad-duncan/IOCs · GitHub

https://gist.githubusercontent.com/plutooo/2aadbd4a718e269df474079dd2e584fb/raw/7b3af77b5202366c8934c88ef251f1e905967040/gistfile1.txt

https://gist.githubusercontent.com/plutooo/2aadbd4a718e269df474079dd2e584fb/raw/7b3af77b5202366c8934c88ef251f1e905967040/gistfile1.txt

What the Pack(er)? – cyber.wtf

https://cyber.wtf/2022/03/23/what-the-packer/
What the Pack(er)? – cyber.wtf