TA577 Strikes Again: New Phishing Attack Emerges! ????????????

Mar 06 2024

Gone Phishing Banner

Welcome to Gone Phishing, your daily cybersecurity newsletter that brings more cyber fire than Airman Aaron Bushnell ???????????? That Aaron is so hot right now #Zoolander #Goingtohell

Today’s hottest cybersecurity news stories:

  • ???? Thread hijack attack is stealing NTLM hashes from IT networks ????

  • ???? Novel DNS hijacking technique used by hackers for investment scams ????

  • ???? TODDLERSHARK: Exploiting ConnectWise ScreenConnect flaws galore ????‍????

Hijack attack gypsy cab holla back ????????????????????

 

giphy.com

 

???? TA577 Strikes Again: New Phishing Attack Emerges! ????????????

The notorious threat actor known as TA577 has resurfaced, this time employing ZIP archive attachments in phishing emails to pilfer NT LAN Manager (NTLM) hashes, according to a report by enterprise security firm Proofpoint. ????????????

A Sophisticated Attack Chain ????️????????

The newly observed attack chain is crafted for sensitive information gathering, with the ultimate goal of facilitating follow-on malicious activities. At least two campaigns leveraging this approach were detected on February 26 and 27, 2024, targeting hundreds of organisations globally through thousands of messages. ????????????

Thread Hijacking Tactics ????????????️

Utilising the tactic of thread hijacking, the phishing emails masquerade as responses to previous correspondence, aiming to boost the likelihood of success. The ZIP attachments, acting as the primary delivery mechanism, harbour HTML files designed to establish contact with an actor-controlled Server Message Block (SMB) server. ????????????

The Objective: NTLM Hashes ????????????

TA577’s primary objective is to capture NTLMv2 Challenge/Response pairs from the SMB server, enabling them to pilfer NTLM hashes for subsequent pass-the-hash (PtH) attacks. This sophisticated manoeuvre allows adversaries to authenticate sessions without the underlying password, granting unauthorised access to critical data within networks. ????????????

A Stealthy Cybercrime Group ????️‍♂️????????

Known for its sophistication, TA577 has been associated with distributing malware families like QakBot and PikaBot in the past. The group demonstrates a keen understanding of the evolving cyber threat landscape, swiftly adapting its tactics, techniques, and procedures (TTPs) to evade detection and deploy various payloads. ????????????

Cybersecurity Recommendations ????️????????

In light of this threat, organisations are strongly advised to block outbound SMB traffic to thwart exploitation attempts and bolster their defences against such malicious activities. Vigilance and proactive measures are crucial to mitigating the risks posed by sophisticated threat actors like TA577. ????????️????

 

Signup for Free

 

Learn AI in 5 minutes a day. We’ll teach you how to save time and earn more with AI. Join 400,000+ free daily readers for trending tools, productivity boosting prompts, the latest news, and more.

Hackers: Don’t try and test the rebel DNS ???? #WuTang

???? Beware of Savvy Seahorse: DNS Threat Actor Targets Investors! ????????????

A new DNS threat actor dubbed Savvy Seahorse has emerged on the cyber threat landscape, employing sophisticated tactics to lure victims into fake investment platforms and abscond with their hard-earned funds, according to a recent report by Infoblox. ????️‍♂️????????

The Modus Operandi ????????????

Savvy Seahorse operates by persuading unsuspecting individuals to create accounts on counterfeit investment platforms, enticing them with promises of lucrative returns. Once victims make deposits into a personal account, the funds are swiftly transferred to a bank in Russia, leaving investors in financial distress. ????????????

Wide Net of Targets ????????????

The threat actor’s campaigns cast a wide net, targeting individuals across various regions, including Russian, Polish, Italian, German, Czech, Turkish, French, Spanish, and English speakers. This broad scope indicates a concerted effort to ensnare victims on a global scale. ????????????

Social Media Snares and Fake Bots ????????????

Victims are ensnared through enticing advertisements on social media platforms like Facebook, enticing them with the allure of high-return investment opportunities. Additionally, fake ChatGPT and WhatsApp bots are employed to dupe users into divulging personal information in exchange for purported investment prospects. ????????????

Evading Detection with DNS Tricks ????️????????️‍♂️

Savvy Seahorse employs DNS canonical name (CNAME) records to construct a traffic distribution system (TDS), enabling threat actors to evade detection since at least August 2021. By leveraging a domain generation algorithm (DGA) to create short-lived subdomains sharing CNAME records, the threat actor maintains a resilient infrastructure resistant to takedown efforts. ????️????????️‍♂️

Cybersecurity Recommendations ????️????????

Potential victims are cautioned against providing personal information or making financial transactions on suspicious platforms advertised on social media. Vigilance is paramount, and individuals should exercise caution when presented with investment opportunities that seem too good to be true. Additionally, cybersecurity measures should be bolstered to detect and mitigate threats posed by DNS-based attacks. ????️????????

Stay alert, stay safe! ????????????

???? Catch of the Day!! ????????????

???? The Motley Fool: “Fool me once, shame on — shame on you. Fool me — you can’t get fooled again.” Good ol’ George Dubya ???? Let us tell who’s not fooling around though; that’s the Crüe ???? at Motley Fool. You’d be a fool (alright, enough already! ????) not to check out their Share Tips from time to time so your savings can one day emerge from their cocoon as a beautiful butterfly! ???? Kidding aside, if you check out their website they’ve actually got a ton of great content with a wide variety of different investment ideas to suit most budgets ???? (LINK)


???? Wander: Find your happy place. Cue Happy Gilmore flashback ????️⛳????????️ Mmmm Happy Place… ???? So, we’ve noticed a lot of you guys are interested in travel. As are we! We stumbled upon this cool company that offers a range of breath-taking spots around the United States and, honestly, the website alone is worth a gander. When all you see about the Land of the free and the home of the brave is news of rioting, looting and school shootings, it’s easy to forget how beautiful some parts of it are. The awe-inspiring locations along with the innovative architecture of the hotels sets Wander apart from your run of the mill American getaway ????️???? (LINK)


???? Digital Ocean: If you build it they will come. Nope, we’re not talking about a baseball field for ghosts ???????? (Great movie, to be fair ????). This is the Digital Ocean who’ve got a really cool platform for building and hosting pretty much anything you can think of. If you check out their website you’ll find yourself catching the buzz even if you can’t code (guilty ????). But if you can and you’re looking for somewhere to test things out or launch something new or simply enhance what you’ve got, we’d recommend checking out their services fo’ sho ???? And how can you not love their slogan: Dream it. Build it. Grow it. Right on, brother! ???? (LINK)

You’re gonna need a bigger boat ????????????

???? North Korean Threat Actors Unleash TODDLERSHARK Malware! ????????

Security experts have uncovered a concerning development in the cyber threat landscape, as North Korean threat actors exploit recently disclosed security vulnerabilities in ConnectWise ScreenConnect to deploy a new malware strain dubbed TODDLERSHARK. ????????????

The Malicious Manoeuvre ????????????️

According to a report shared by Kroll, TODDLERSHARK shares similarities with known Kimsuky malware variants such as BabyShark and ReconShark. The threat actors capitalised on vulnerabilities CVE-2024-1708 and CVE-2024-1709 in ConnectWise ScreenConnect, leveraging the exposed setup wizard to gain access to victim workstations and execute the malicious payload. ????????????️

A New Weapon in the Cyber Arsenal ????️????????

TODDLERSHARK represents the latest evolution of Kimsuky malware, designed to capture sensitive information from compromised hosts while exhibiting polymorphic behaviour to evade detection. This sophisticated malware leverages scheduled tasks for persistence and employs unique C2 URLs, making it a formidable reconnaissance tool in the hands of threat actors. ????️????????

Escalating Cyber Tensions ????????️????

Amidst these revelations, South Korea’s National Intelligence Service (NIS) has accused North Korea of compromising servers belonging to two domestic semiconductor manufacturers, highlighting the escalating cyber tensions between the two nations. The intrusions, characterised by sophisticated living-off-the-land (LotL) techniques, underscore the growing threats posed by state-sponsored cyber operations. ????????️????

Stay Vigilant, Stay Secure! ????️????????

As cyber threats continue to evolve and proliferate, organisations and individuals must remain vigilant against emerging threats and ensure robust cybersecurity measures are in place. Timely patching of software vulnerabilities, employee awareness training, and deployment of advanced threat detection mechanisms are crucial steps in safeguarding against malicious actors’ nefarious activities. ????️????????

Stay safe in the digital realm, cyber squad! ????????????

????️ Extra, Extra! Read all about it!

Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!

  • ????️ Tl;dr sec: Join 30,000+ security professionals getting the best tools, blog posts, talks, and resources right in their inbox for free every Thursday ????

  • ???? Crypto Pragmatist: Crypto made simple. Actionable alpha in 5 minutes, 3x a week. Join 47,000+ investors and insiders, for ????

  • ???? Bitcoin Breakdown: The best in Bitcoin, carefully curated by an alien from the future ????

Let us know what you think!

So long and thanks for reading all the phish!

Recent articles