06/22

Defending Ukraine: Early Lessons from the Cyber War - Microsoft On the Issues

https://blogs.microsoft.com/on-the-issues/2022/06/22/defending-ukraine-early-lessons-from-the-cyber-war/
Defending Ukraine: Early Lessons from the Cyber War - Microsoft On the Issues

NSA, Partners Recommend Properly Configuring, Monitoring PowerShell in New Report > National Security Agency/Central Security Service > Article

https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/3069620/nsa-partners-recommend-properly-configuring-monitoring-powershell-in-new-report/
NSA, Partners Recommend Properly Configuring, Monitoring PowerShell in New Report > National Security Agency/Central Security Service > Article

Russia's APT28 uses fear of nuclear war to spread Follina docs in Ukraine | Malwarebytes Labs

https://blog.malwarebytes.com/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine/
Russia's APT28 uses fear of nuclear war to spread Follina docs in Ukraine | Malwarebytes Labs

Detecting Linux Anti-Forensics Log Tampering

https://www.inversecos.com/2022/06/detecting-linux-anti-forensics-log.html
Detecting Linux Anti-Forensics Log Tampering

How Vladimir Putin Is Plotting to Weasel His Way Into American Hearts

https://www.thedailybeast.com/how-vladimir-putin-is-plotting-to-weasel-his-way-into-american-hearts
How Vladimir Putin Is Plotting to Weasel His Way Into American Hearts

Attacking With WebView2 Applications | mr.d0x

https://mrd0x.com/attacking-with-webview2-applications/
Attacking With WebView2 Applications | mr.d0x

Researchers Uncover Ways to Break the Encryption of 'MEGA' Cloud Storage Service

https://thehackernews.com/2022/06/researchers-uncover-ways-to-break.html
Researchers Uncover Ways to Break the Encryption of 'MEGA' Cloud Storage Service

Introducing Tailscale SSH · Tailscale

https://tailscale.com/blog/tailscale-ssh/
Introducing Tailscale SSH · Tailscale

VirusTotal - File - 45776d2ab0d35a13eb4eb51988b38ab5190563c6eb9a1897c67778ee6e9d2691

https://www.virustotal.com/gui/file/45776d2ab0d35a13eb4eb51988b38ab5190563c6eb9a1897c67778ee6e9d2691
VirusTotal - File - 45776d2ab0d35a13eb4eb51988b38ab5190563c6eb9a1897c67778ee6e9d2691

VirusTotal - File - 57e09a3e68c324c41eb7714282115ac6fd9e6ef9af00d5e089752f5c3d65c681

https://www.virustotal.com/gui/file/57e09a3e68c324c41eb7714282115ac6fd9e6ef9af00d5e089752f5c3d65c681
VirusTotal - File - 57e09a3e68c324c41eb7714282115ac6fd9e6ef9af00d5e089752f5c3d65c681

MalwareBazaar | SHA256 5b52efa55271c8749766de24a3b89105e809a4438a35fdc492e9c364ec274a7a (Quakbot)

https://bazaar.abuse.ch/sample/5b52efa55271c8749766de24a3b89105e809a4438a35fdc492e9c364ec274a7a/
MalwareBazaar | SHA256 5b52efa55271c8749766de24a3b89105e809a4438a35fdc492e9c364ec274a7a (Quakbot)

Arsenal Kit Update: Thread Stack Spoofing | Cobalt Strike

https://www.cobaltstrike.com/blog/arsenal-kit-update-thread-stack-spoofing/
Arsenal Kit Update: Thread Stack Spoofing | Cobalt Strike

Chinese actor takes aim, armed with Nim Language and Bizarro AES - Check Point Research

https://research.checkpoint.com/2022/chinese-actor-takes-aim-armed-with-nim-language-and-bizarro-aes/
Chinese actor takes aim, armed with Nim Language and Bizarro AES - Check Point Research

MalwareBazaar | SHA256 380fafae824b48724591be9bd4460fd3c1e77f4cb28c80b2c2c1ee76dc94bf7b (Quakbot)

https://bazaar.abuse.ch/sample/380fafae824b48724591be9bd4460fd3c1e77f4cb28c80b2c2c1ee76dc94bf7b/
MalwareBazaar | SHA256 380fafae824b48724591be9bd4460fd3c1e77f4cb28c80b2c2c1ee76dc94bf7b (Quakbot)

Russian govt hackers hit Ukraine with Cobalt Strike, CredoMap malware

https://www.bleepingcomputer.com/news/security/russian-govt-hackers-hit-ukraine-with-cobalt-strike-credomap-malware/
Russian govt hackers hit Ukraine with Cobalt Strike, CredoMap malware

Orion/APT_APT28_CredoMap_Jun_2022_1.yara at main · StrangerealIntel/Orion · GitHub

https://github.com/StrangerealIntel/Orion/blob/main/APT/APT_APT28_CredoMap_Jun_2022_1.yara
Orion/APT_APT28_CredoMap_Jun_2022_1.yara at main · StrangerealIntel/Orion · GitHub

Cyber-Reports-2022-06-IT-Army-of-Ukraine.pdf

https://css.ethz.ch/content/dam/ethz/special-interest/gess/cis/center-for-securities-studies/pdfs/Cyber-Reports-2022-06-IT-Army-of-Ukraine.pdf
Cyber-Reports-2022-06-IT-Army-of-Ukraine.pdf

Qakbot/Qakbot_obama191_22.06.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_obama191_22.06.2022.txt
Qakbot/Qakbot_obama191_22.06.2022.txt at main · pr0xylife/Qakbot · GitHub

Qakbot/Qakbot_AA_22.06.2022.txt at main · pr0xylife/Qakbot · GitHub

https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_AA_22.06.2022.txt
Qakbot/Qakbot_AA_22.06.2022.txt at main · pr0xylife/Qakbot · GitHub

The forgotten SUAVEEYEFUL FreeBSD software implant of the EQUATION GROUP | xorl %eax, %eax

https://xorl.wordpress.com/2022/06/22/the-forgotten-suaveeyeful-freebsd-software-implant-of-the-equation-group/
The forgotten SUAVEEYEFUL FreeBSD software implant of the EQUATION GROUP | xorl %eax, %eax

Deadwood 2022 Conference - Wild West Hackin' Fest

https://wildwesthackinfest.com/deadwood/
Deadwood 2022 Conference - Wild West Hackin' Fest

Semgrep rules for PHP security assessment - hn security

https://security.humanativaspa.it/semgrep-rules-for-php-security-assessment/
Semgrep rules for PHP security assessment - hn security

Google Online Security Blog: Game on! The 2022 Google CTF is here.

https://security.googleblog.com/2022/06/game-on-2022-google-ctf-is-here.html
Google Online Security Blog: Game on! The 2022 Google CTF is here.

Newly Discovered Magecart Infrastructure Reveals the Scale of Ongoing Campaign

https://thehackernews.com/2022/06/newly-discovered-magecart.html
Newly Discovered Magecart Infrastructure Reveals the Scale of Ongoing Campaign

MalwareBazaar | CredoMap

https://bazaar.abuse.ch/browse/tag/CredoMap/
MalwareBazaar | CredoMap