Month: January 2022

Changes in REvil ransomware version 2.2

By the Intel 471 Malware Intelligence team. Summary The REvil ransomware-as-a-service (RaaS) operation continues to impact businesses worldwide. The threat actors responsible for developing and maintaining the malware have released an updated ransomware, namely version 2.2. In this short blog post, we will cover the significant changes from the previous version, which we covered in …

Changes in REvil ransomware version 2.2 Read More »

A brief history of TA505

Ten articles before and after You need to adjust your patch priorities! Coronavirus having minimal impact on prices, demand,… Iran’s domestic espionage: Lessons from recent data… Flowspec – TA505’s bulletproof hoster of choice Prioritizing “critical” vulnerabilities: A threat… Changes in REvil ransomware version 2.2 COVID-19 pandemic: Through the eyes of a cybercriminal Understanding the relationship …

A brief history of TA505 Read More »

Coronavirus having minimal impact on prices, demand,…

Coronavirus Disease 2019 (COVID-19) continues to surround our everyday lives and its presence remains a topic of interest and discussion within underground forums. In the earlier days of the pandemic, we took a look at how attackers were leveraging the fear surrounding the disease to launch campaigns such as business email compromise (BEC), phishing and …

Coronavirus having minimal impact on prices, demand,… Read More »

Iran’s domestic espionage: Lessons from recent data…

By the Intel 471 Global Research Team. In the last decade, Iran has undergone a quiet revolution. Since the“Green Movement” uprising in 2009, more Iranians have dared to openly oppose their regime. The reasons include accusations of elections tampering, global sanctions, increased inflation, heavy investment of state funds in the nuclear and arming programs, and …

Iran’s domestic espionage: Lessons from recent data… Read More »

Prioritizing “critical” vulnerabilities: A threat…

By the Intel 471 Intelligence Analysis team. Recently, there have been many vendor security advisories containing multiple critical vulnerabilities potentially impacting organizations that may be conflicted with patch prioritization when looking at the variables seen for each reported vulnerability. Threat intelligence can supplement publicly disclosed information and provide a contextual view of exploitation efforts and …

Prioritizing “critical” vulnerabilities: A threat… Read More »

Recent Trickbot disruption operation likely to have…

Key points Recent disruption actions against Trickbot likely will have only a short-term impact on Trickbot operations. Trickbot operators have multiple methods to avoid centralization of their command and control infrastructure which would make the botnet resilient to take down. If bogus data has been inserted into Trickbot as claimed and Trickbot operators are unable …

Recent Trickbot disruption operation likely to have… Read More »

Criminals posing as Lazarus Group threatened Travelex:…

A group posing as notorious nation-state-linked hacking group “Lazarus Group” threatened to hit British foreign exchange company Travelex with a distributed-denial-of-service (DDoS) attack unless it paid 20 bitcoins. According to an email discovered by Intel 471 researchers, attackers threatened to hit Travelex with an “extremely powerful” attack that would “peak over 2 Tbps” until the …

Criminals posing as Lazarus Group threatened Travelex:… Read More »

Leveraging Intel 471’s Malware Intelligence Data using…

Intel 471’s Malware Intelligence provides our clients with constant coverage of top-tier malware families. It delivers near real-time alerts of targeting changes, spamming and malware campaigns, updates in infrastructure and much more. In the first in a series of blogs and white papers, we take a look at how this high-volume and high-fidelity data has …

Leveraging Intel 471’s Malware Intelligence Data using… Read More »

Trickbot down, but is it out?

Summary Since the separate and independent actions taken against Trickbot, we have observed successful disruption of its command and control infrastructure. However, the actors linked to Trickbot have not ceased their criminal activities. These actors have continued engaging in ransomware activity, using BazarLoader instead of Trickbot. We are unable to assess the long-term impact of …

Trickbot down, but is it out? Read More »

Ransomware-as-a-service: The pandemic within a pandemic

Ransomware is a massive problem. But you already knew that. Technical novices, along with seasoned cybersecurity professionals, have witnessed over the past year a slew of ransomware events that have devastated enterprises around the world. Even those outside of cybersecurity are now familiar with the concept: criminals behind a keyboard have found a way into …

Ransomware-as-a-service: The pandemic within a pandemic Read More »

Steal, then strike: Access merchants are first clues…

Cybercrime does not happen in a vacuum. While ransomware variants like REvil, Ryuk and DoppelPaymer have become household names for cybersecurity professionals, those deploying ransomware only represent part of the process by which criminals are forcing organizations to either pay them millions or watch their business go under. The broader picture shows an underground marketplace …

Steal, then strike: Access merchants are first clues… Read More »

No pandas, just people: The current state of China’s…

China’s internet is a lot different than the rest of the world. Yet, that hasn’t stopped its population from engaging in cybercrime. Despite the various measures the Chinese government has taken to censor and surveil its residents on the internet, a significant cybercrime underground full of financially motivated actors exists. Efforts like “The Great Firewall” …

No pandas, just people: The current state of China’s… Read More »

More annoying than crippling: Joker’s Stash takedown…

Law enforcement has allegedly seized proxy servers used in connection with the blockchain-based domains belonging to Joker’s Stash, a prolific vendor of compromised financial card data in the cybercrime underground. On December 17, an image adorned the shop’s website that claimed the U.S. Federal Bureau of Investigation and Interpol had taken it into law enforcement’s …

More annoying than crippling: Joker’s Stash takedown… Read More »

TA505’s modified loader means new attack campaign…

After months of inactivity, hacking group TA505’s Get2 Loader has sprung back into operation, possibly signaling that the group is ready for a new round of malicious activity. On December 14, 2020, the Get2 loader had resurfaced with new download and execute configuration parameters named “LD” and “ED.” Intel 471 last observed the loader in …

TA505’s modified loader means new attack campaign… Read More »

Cybercriminals are interested in your SCADA systems

The public learned this week of an alarming cybersecurity incident that could have physically harmed people: Someone managed to access a system that controlled a Florida city’s water treatment plant, temporarily adjusting sodium hydroxide levels to amounts that could have made the population sick had the chemicals been introduced into the water supply. While city …

Cybercriminals are interested in your SCADA systems Read More »

Hiding in plain sight: Bulletproof Hosting’s dueling…

A June 2020 feature in The New Yorker was really more cyberpunk than cybersecurity. The story focuses on the people who ran CyberBunker, a server farm built in an underground European military bunker that served as a host for spammers, botnet command-and-control servers, malware and online scams. The story follows the familiar arc of dystopian …

Hiding in plain sight: Bulletproof Hosting’s dueling… Read More »

Egregor operation takes huge hit after police raids

Law enforcement action carried out last week in Ukraine has targeted the people behind some of the most notorious ransomware gangs of the past year. On Feb. 9, 2021, Ukrainian law enforcement conducted a joint operation with U.S. and French authorities against several Ukrainian nationals believed to be deeply involved with Egregor ransomware operations. Intel …

Egregor operation takes huge hit after police raids Read More »

Bulletproof hosting: How cybercrime stays resilient

If we were to list all of the malicious acts carried out by cybercriminals who leverage bulletproof hosting (BPH), we’d have a report that would rival “Infinite Jest” or “War & Peace” for length. Bulletproof hosting has been hand-in-glove with cybercrime for decades, supplying criminals with the infrastructure they need to carry out their crimes. …

Bulletproof hosting: How cybercrime stays resilient Read More »

Friendly fire: Four well-known cybercriminal forums…

Since the beginning of the year, Intel 471 has observed four well-known cybercriminal forums dealing with a breach, including two since the beginning of March. The forums, all predominantly Russian-language forums, saw the breaches publicly disclosed elsewhere, with some instances of user data being leaked or put up for sale. Intel 471 does not know …

Friendly fire: Four well-known cybercriminal forums… Read More »