Big spamming op sees 8,000+ domains of trusted brands spoofed

Feb 27 2024

Domain thing to remember is… ????????????


???????? SubdoMailing Saga Unveiled! ????????

In a shocking revelation, Guardio Labs has uncovered a massive spam operation dubbed SubdoMailing, orchestrated by a threat actor ominously known as ResurrecAds! ????????

This sophisticated scheme involves hijacking over 8,000 domains and 13,000 subdomains belonging to reputable brands like eBay, McAfee, and UNICEF. ????️????

But wait, there’s more! ResurrecAds isn’t playing by the rules. They’ve crafted a devious distribution architecture, slipping past security measures with ease and dodging text-based spam filters like a pro! ????️‍♂️????

And it gets even trickier – these malicious emails are cleverly disguised as images, bypassing standard security blocks and luring unsuspecting victims into a maze of redirects, leading to malicious content tailored for maximum profit! ????????

But fear not! Guardio isn’t backing down. With their SubdoMailing Checker, domain administrators and site owners can now detect signs of compromise and safeguard against this nefarious campaign. ????️????

The battle against cyber threats rages on, but with vigilance and determination, we’ll keep our digital world safe from harm! ????????


Who dat? IDAT ????

????️ Ukrainian Entities in Finland Targeted by Malicious Campaign! ????

Threat actors identified as UAC-0184, tracked by CERT-UA, unleash a devious assault using the IDAT Loader to spread the Remcos RAT. ????????

Morphisec researcher Michael Dereviashkin sheds light on the attack’s sophisticated use of steganography, a well-known but formidable technique for defence evasion. ????????️‍♂️

The IDAT Loader, often associated with the Hijack Loader family, serves as a conduit for various payloads, including DanaBot and RedLine Stealer. ????????

This onslaught aligns with a phishing campaign unveiled by CERT-UA, employing war-themed lures to initiate an infection chain leading to Remcos RAT deployment via embedded steganographic PNG files. ????????

???? FYI: Steganography is the technique of hiding data within an ordinary, nonsecret file or message to avoid detection; the hidden data is then extracted at its destination. ????

Meanwhile, defence forces face another threat as UAC-0149 leverages the Signal app to distribute booby-trapped Excel documents, facilitating the execution of COOKBOX, a PowerShell-based malware. ????????

Adding to the turmoil, PikaBot malware reemerges with a revamped variant boasting new unpacking methods and heightened obfuscation, signalling active development efforts. ????????

As cyber adversaries evolve their tactics, vigilance and robust defences remain paramount in safeguarding against malicious incursions. ????????️

Time to rethink a Korea in dev? ????

???? North Korean Actors Tied to Malicious npm Packages! ????

Phylum’s latest findings unveil a sinister link between fake npm packages and North Korean state-sponsored threat actors. ????️‍♂️????

Dubbed execution-time-async, data-time-utils, login-time-utils, mongodb-connection-utils, and mongodb-execution-utils, these packages pose as legitimate Node.js utilities, infiltrating developers’ systems with malicious intent. ⚠️????

In a clever ploy, the adversaries concealed nefarious code within a test file, triggering the installation of cryptocurrency and credential stealers upon execution. ????????

Further investigation revealed telltale signs pointing to a deleted GitHub profile, leading to a repository housing Python scripts utilised to fetch additional payloads and steal browser credentials. ????????️

???? Connections to North Korean Actors Uncovered! ????

The discovery of similar JavaScript-based malware, including BeaverTail, suggests ties to known North Korean threat campaigns, like Contagious Interview. ????????

Attempts to obfuscate identities through fake job postings and repository names underscore the adversaries’ sophisticated tactics. ????????

As developers remain prime targets, heightened awareness and vigilance are essential to combating these insidious attacks. ????️????

