Mar 06 2024
Welcome to Gone Phishing, your daily cybersecurity newsletter that brings more cyber fire than Airman Aaron Bushnell π₯ππ That Aaron is so hot right now #Zoolander #Goingtohell
Todayβs hottest cybersecurity news stories:
π« Thread hijack attack is stealing NTLM hashes from IT networks π€
π Novel DNS hijacking technique used by hackers for investment scams π€
π¦ TODDLERSHARK: Exploiting ConnectWise ScreenConnect flaws galore π¨βπ»
giphy.com
The notorious threat actor known as TA577 has resurfaced, this time employing ZIP archive attachments in phishing emails to pilfer NT LAN Manager (NTLM) hashes, according to a report by enterprise security firm Proofpoint. π±ππ§
A Sophisticated Attack Chain π‘οΈππΌ
The newly observed attack chain is crafted for sensitive information gathering, with the ultimate goal of facilitating follow-on malicious activities. At least two campaigns leveraging this approach were detected on February 26 and 27, 2024, targeting hundreds of organisations globally through thousands of messages. ππ πΌ
Thread Hijacking Tactics ππ£π‘οΈ
Utilising the tactic of thread hijacking, the phishing emails masquerade as responses to previous correspondence, aiming to boost the likelihood of success. The ZIP attachments, acting as the primary delivery mechanism, harbour HTML files designed to establish contact with an actor-controlled Server Message Block (SMB) server. ππ§π
The Objective: NTLM Hashes ππ»π°
TA577’s primary objective is to capture NTLMv2 Challenge/Response pairs from the SMB server, enabling them to pilfer NTLM hashes for subsequent pass-the-hash (PtH) attacks. This sophisticated manoeuvre allows adversaries to authenticate sessions without the underlying password, granting unauthorised access to critical data within networks. πππ
A Stealthy Cybercrime Group π΅οΈββοΈπΌπ
Known for its sophistication, TA577 has been associated with distributing malware families like QakBot and PikaBot in the past. The group demonstrates a keen understanding of the evolving cyber threat landscape, swiftly adapting its tactics, techniques, and procedures (TTPs) to evade detection and deploy various payloads. πππΌ
Cybersecurity Recommendations π‘οΈππΌ
In light of this threat, organisations are strongly advised to block outbound SMB traffic to thwart exploitation attempts and bolster their defences against such malicious activities. Vigilance and proactive measures are crucial to mitigating the risks posed by sophisticated threat actors like TA577. π«π‘οΈπ
Signup for Free
Learn AI in 5 minutes a day. We’ll teach you how to save time and earn more with AI. Join 400,000+ free daily readers for trending tools, productivity boosting prompts, the latest news, and more.
A new DNS threat actor dubbed Savvy Seahorse has emerged on the cyber threat landscape, employing sophisticated tactics to lure victims into fake investment platforms and abscond with their hard-earned funds, according to a recent report by Infoblox. π΅οΈββοΈπ»πΈ
The Modus Operandi π£ππΌ
Savvy Seahorse operates by persuading unsuspecting individuals to create accounts on counterfeit investment platforms, enticing them with promises of lucrative returns. Once victims make deposits into a personal account, the funds are swiftly transferred to a bank in Russia, leaving investors in financial distress. π±π³π°
Wide Net of Targets π―ππ
The threat actor’s campaigns cast a wide net, targeting individuals across various regions, including Russian, Polish, Italian, German, Czech, Turkish, French, Spanish, and English speakers. This broad scope indicates a concerted effort to ensnare victims on a global scale. πππ―
Social Media Snares and Fake Bots π²π£π€
Victims are ensnared through enticing advertisements on social media platforms like Facebook, enticing them with the allure of high-return investment opportunities. Additionally, fake ChatGPT and WhatsApp bots are employed to dupe users into divulging personal information in exchange for purported investment prospects. π²π£π€
Evading Detection with DNS Tricks π‘οΈππ΅οΈββοΈ
Savvy Seahorse employs DNS canonical name (CNAME) records to construct a traffic distribution system (TDS), enabling threat actors to evade detection since at least August 2021. By leveraging a domain generation algorithm (DGA) to create short-lived subdomains sharing CNAME records, the threat actor maintains a resilient infrastructure resistant to takedown efforts. π‘οΈππ΅οΈββοΈ
Cybersecurity Recommendations π‘οΈππΌ
Potential victims are cautioned against providing personal information or making financial transactions on suspicious platforms advertised on social media. Vigilance is paramount, and individuals should exercise caution when presented with investment opportunities that seem too good to be true. Additionally, cybersecurity measures should be bolstered to detect and mitigate threats posed by DNS-based attacks. π‘οΈππΌ
Stay alert, stay safe! π¨ππ
πΒ The Motley Fool: βFool me once, shame on β shame on you. Fool me β you can’t get fooled again.β Good olβ George Dubya π Let us tell whoβs not fooling around though; thatβs the CrΓΌe π at Motley Fool. Youβd be a fool (alright, enough already! π) not to check out their Share Tips from time to time so your savings can one day emerge from their cocoon as a beautiful butterfly! π Kidding aside, if you check out their website theyβve actually got a ton of great content with a wide variety of different investment ideas to suit most budgets π€Β (LINK)
π΅Β Wander: Find your happy place. Cue Happy Gilmore flashback ποΈβ³πποΈ Mmmm Happy Placeβ¦ π So, weβve noticed a lot of you guys are interested in travel. As are we! We stumbled upon this cool company that offers a range of breath-taking spots around the United States and, honestly, the website alone is worth a gander. When all you see about the Land of the free and the home of the brave is news of rioting, looting and school shootings, itβs easy to forget how beautiful some parts of it are. The awe-inspiring locations along with the innovative architecture of the hotels sets Wander apart from your run of the mill American getaway ποΈπΒ (LINK)
πΒ Digital Ocean: If you build it they will come. Nope, weβre not talking about a baseball field for ghosts βΎπ»πΏ (Great movie, to be fair π). This is the Digital Ocean whoβve got a really cool platform for building and hosting pretty much anything you can think of. If you check out their website youβll find yourself catching the buzz even if you canβt code (guilty π). But if you can and youβre looking for somewhere to test things out or launch something new or simply enhance what youβve got, weβd recommend checking out their services foβ sho π And how can you not love their slogan: Dream it. Build it. Grow it. Right on, brother! πΏΒ (LINK)
Security experts have uncovered a concerning development in the cyber threat landscape, as North Korean threat actors exploit recently disclosed security vulnerabilities in ConnectWise ScreenConnect to deploy a new malware strain dubbed TODDLERSHARK. π¨ππ»
The Malicious Manoeuvre π¦π»π‘οΈ
According to a report shared by Kroll, TODDLERSHARK shares similarities with known Kimsuky malware variants such as BabyShark and ReconShark. The threat actors capitalised on vulnerabilities CVE-2024-1708 and CVE-2024-1709 in ConnectWise ScreenConnect, leveraging the exposed setup wizard to gain access to victim workstations and execute the malicious payload. π¦π»π‘οΈ
A New Weapon in the Cyber Arsenal π‘οΈππ€
TODDLERSHARK represents the latest evolution of Kimsuky malware, designed to capture sensitive information from compromised hosts while exhibiting polymorphic behaviour to evade detection. This sophisticated malware leverages scheduled tasks for persistence and employs unique C2 URLs, making it a formidable reconnaissance tool in the hands of threat actors. π‘οΈππ€
Escalating Cyber Tensions ππ‘οΈπ
Amidst these revelations, South Korea’s National Intelligence Service (NIS) has accused North Korea of compromising servers belonging to two domestic semiconductor manufacturers, highlighting the escalating cyber tensions between the two nations. The intrusions, characterised by sophisticated living-off-the-land (LotL) techniques, underscore the growing threats posed by state-sponsored cyber operations. ππ‘οΈπ
Stay Vigilant, Stay Secure! π‘οΈππ»
As cyber threats continue to evolve and proliferate, organisations and individuals must remain vigilant against emerging threats and ensure robust cybersecurity measures are in place. Timely patching of software vulnerabilities, employee awareness training, and deployment of advanced threat detection mechanisms are crucial steps in safeguarding against malicious actors’ nefarious activities. π‘οΈππ»
Stay safe in the digital realm, cyber squad! π¨ππ
Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!
π‘οΈ Tl;dr sec: Join 30,000+ security professionals getting the best tools, blog posts, talks, and resources right in their inbox for free every Thursday π
π΅Β Crypto Pragmatist: Crypto made simple. Actionable alpha in 5 minutes, 3x a week. Join 47,000+ investors and insiders, for π
πΒ Bitcoin Breakdown: The best in Bitcoin, carefully curated by an alien from the future πΎ
Let us know what you think!
So long and thanks for reading all the phish!