Mar 06 2024

Today's hottest cybersecurity news stories:

  • ???? Thread hijack attack is stealing NTLM hashes from IT networks ????

  • ???? Novel DNS hijacking technique used by hackers for investment scams ????

  • ???? TODDLERSHARK: Exploiting ConnectWise ScreenConnect flaws galore ????‍????

Hijack attack gypsy cab holla back ????????????????????




???? TA577 Strikes Again: New Phishing Attack Emerges! ????????????

The notorious threat actor known as TA577 has resurfaced, this time employing ZIP archive attachments in phishing emails to pilfer NT LAN Manager (NTLM) hashes, according to a report by enterprise security firm Proofpoint. ????????????

A Sophisticated Attack Chain ????️????????

The newly observed attack chain is crafted for sensitive information gathering, with the ultimate goal of facilitating follow-on malicious activities. At least two campaigns leveraging this approach were detected on February 26 and 27, 2024, targeting hundreds of organisations globally through thousands of messages. ????????????

Thread Hijacking Tactics ????????????️

Utilising the tactic of thread hijacking, the phishing emails masquerade as responses to previous correspondence, aiming to boost the likelihood of success. The ZIP attachments, acting as the primary delivery mechanism, harbour HTML files designed to establish contact with an actor-controlled Server Message Block (SMB) server. ????????????

The Objective: NTLM Hashes ????????????

TA577’s primary objective is to capture NTLMv2 Challenge/Response pairs from the SMB server, enabling them to pilfer NTLM hashes for subsequent pass-the-hash (PtH) attacks. This sophisticated manoeuvre allows adversaries to authenticate sessions without the underlying password, granting unauthorised access to critical data within networks. ????????????

A Stealthy Cybercrime Group ????️‍♂️????????

Known for its sophistication, TA577 has been associated with distributing malware families like QakBot and PikaBot in the past. The group demonstrates a keen understanding of the evolving cyber threat landscape, swiftly adapting its tactics, techniques, and procedures (TTPs) to evade detection and deploy various payloads. ????????????

Cybersecurity Recommendations ????️????????

In light of this threat, organisations are strongly advised to block outbound SMB traffic to thwart exploitation attempts and bolster their defences against such malicious activities. Vigilance and proactive measures are crucial to mitigating the risks posed by sophisticated threat actors like TA577. ????????️????


Hackers: Don’t try and test the rebel DNS ???? #WuTang

???? Beware of Savvy Seahorse: DNS Threat Actor Targets Investors! ????????????

A new DNS threat actor dubbed Savvy Seahorse has emerged on the cyber threat landscape, employing sophisticated tactics to lure victims into fake investment platforms and abscond with their hard-earned funds, according to a recent report by Infoblox. ????️‍♂️????????

The Modus Operandi ????????????

Savvy Seahorse operates by persuading unsuspecting individuals to create accounts on counterfeit investment platforms, enticing them with promises of lucrative returns. Once victims make deposits into a personal account, the funds are swiftly transferred to a bank in Russia, leaving investors in financial distress. ????????????

Wide Net of Targets ????????????

The threat actor’s campaigns cast a wide net, targeting individuals across various regions, including Russian, Polish, Italian, German, Czech, Turkish, French, Spanish, and English speakers. This broad scope indicates a concerted effort to ensnare victims on a global scale. ????????????

Social Media Snares and Fake Bots ????????????

Victims are ensnared through enticing advertisements on social media platforms like Facebook, enticing them with the allure of high-return investment opportunities. Additionally, fake ChatGPT and WhatsApp bots are employed to dupe users into divulging personal information in exchange for purported investment prospects. ????????????

Evading Detection with DNS Tricks ????️????????️‍♂️

Savvy Seahorse employs DNS canonical name (CNAME) records to construct a traffic distribution system (TDS), enabling threat actors to evade detection since at least August 2021. By leveraging a domain generation algorithm (DGA) to create short-lived subdomains sharing CNAME records, the threat actor maintains a resilient infrastructure resistant to takedown efforts. ????️????????️‍♂️

Cybersecurity Recommendations ????️????????

Potential victims are cautioned against providing personal information or making financial transactions on suspicious platforms advertised on social media. Vigilance is paramount, and individuals should exercise caution when presented with investment opportunities that seem too good to be true. Additionally, cybersecurity measures should be bolstered to detect and mitigate threats posed by DNS-based attacks. ????️????????

Stay alert, stay safe! ????????????

You’re gonna need a bigger boat ????????????

???? North Korean Threat Actors Unleash TODDLERSHARK Malware! ????????

Security experts have uncovered a concerning development in the cyber threat landscape, as North Korean threat actors exploit recently disclosed security vulnerabilities in ConnectWise ScreenConnect to deploy a new malware strain dubbed TODDLERSHARK. ????????????

The Malicious Manoeuvre ????????????️

According to a report shared by Kroll, TODDLERSHARK shares similarities with known Kimsuky malware variants such as BabyShark and ReconShark. The threat actors capitalised on vulnerabilities CVE-2024-1708 and CVE-2024-1709 in ConnectWise ScreenConnect, leveraging the exposed setup wizard to gain access to victim workstations and execute the malicious payload. ????????????️

A New Weapon in the Cyber Arsenal ????️????????

TODDLERSHARK represents the latest evolution of Kimsuky malware, designed to capture sensitive information from compromised hosts while exhibiting polymorphic behaviour to evade detection. This sophisticated malware leverages scheduled tasks for persistence and employs unique C2 URLs, making it a formidable reconnaissance tool in the hands of threat actors. ????️????????

Escalating Cyber Tensions ????????️????

Amidst these revelations, South Korea’s National Intelligence Service (NIS) has accused North Korea of compromising servers belonging to two domestic semiconductor manufacturers, highlighting the escalating cyber tensions between the two nations. The intrusions, characterised by sophisticated living-off-the-land (LotL) techniques, underscore the growing threats posed by state-sponsored cyber operations. ????????️????

Stay Vigilant, Stay Secure! ????️????????

As cyber threats continue to evolve and proliferate, organisations and individuals must remain vigilant against emerging threats and ensure robust cybersecurity measures are in place. Timely patching of software vulnerabilities, employee awareness training, and deployment of advanced threat detection mechanisms are crucial steps in safeguarding against malicious actors’ nefarious activities. ????️????????

Stay safe in the digital realm, cyber squad! ????????????

