APT

Russia-linked APT Sofacy leverages BREXIT lures in recent attacksRussia-linked APT Sofacy leverages BREXIT lures in recent attacks

Russia-linked APT Sofacy leverages BREXIT lures in recent attacks

Russia-linked cyber-espionage group Sofacy, (aka APT28, Pawn Storm, Fancy Bear, Sednit, Tsar Team, and Strontium) use BREXIT lures in recent attacks. The APT group used Brexit-themed bait documents on…

7 years ago
New PowerShell-based Backdoor points to MuddyWaterNew PowerShell-based Backdoor points to MuddyWater

New PowerShell-based Backdoor points to MuddyWater

Security researchers at Trend Micro recently discovered PowerShell-based backdoor that resembles a malware used by MuddyWater threat actor. Malware researchers at Trend…

7 years ago
North Korea-linked group Lazarus targets Latin American banksNorth Korea-linked group Lazarus targets Latin American banks

North Korea-linked group Lazarus targets Latin American banks

According to security reearchers at Trend Micro, the North Korea-linked APT group Lazarus recently targeted banks in Latin America. The North…

7 years ago
Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habitsExclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits

Exclusive Cybaze ZLab – Yoroi – Hunting Cozy Bear, new campaign, old habits

The experts at Cybaze ZLab – Yoroi continue the analysis of new strain of malware used by the Russia-linked APT29 cyberespionage…

7 years ago
Sofacy APT group used a new tool in latest attacks, the CannonSofacy APT group used a new tool in latest attacks, the Cannon

Sofacy APT group used a new tool in latest attacks, the Cannon

Sofacy APT group (aka APT28, Pawn Storm, Fancy Bear, Sednit, Tsar Team, and Strontium) has a new weapon in its arsenal dubbed Cannon. The Russia-linked APT group delivers Cannon in…

7 years ago
Experts analyzed how Iranian OilRIG hackers tested their weaponized documentsExperts analyzed how Iranian OilRIG hackers tested their weaponized documents

Experts analyzed how Iranian OilRIG hackers tested their weaponized documents

Security experts at Palo Alto Networks analyzed the method used by Iran-linked OilRig APT Group to test weaponized docs before use…

7 years ago
Cybaze ZLab – Yoroi team analyzed malware used in recent attacks on US entities attributed to APT29Cybaze ZLab – Yoroi team analyzed malware used in recent attacks on US entities attributed to APT29

Cybaze ZLab – Yoroi team analyzed malware used in recent attacks on US entities attributed to APT29

Malware researchers from Cybaze ZLab - Yoroi team have detected a new strain of malware that appears to be associated with…

7 years ago
Cybaze ZLab- Yoroi team spotted a new variant of the APT28 Lojax rootkitCybaze ZLab- Yoroi team spotted a new variant of the APT28 Lojax rootkit

Cybaze ZLab- Yoroi team spotted a new variant of the APT28 Lojax rootkit

Malware researchers at the Cybaze ZLab- Yoroi team spotted a new variant of the dangerous APT28 Lojax rootkit. A new…

7 years ago
Chinese TEMP.Periscope cyberespionage group was using TTPs associated with Russian APTsChinese TEMP.Periscope cyberespionage group was using TTPs associated with Russian APTs

Chinese TEMP.Periscope cyberespionage group was using TTPs associated with Russian APTs

Chinese TEMP.Periscope cyberespionage group targeted a UK-based engineering company using TTPs associated with Russia-linked APT groups. Attribution of cyber attacks…

7 years ago
Cyber espionage group used CVE-2018-8589 Windows Zero-Day in Middle East AttacksCyber espionage group used CVE-2018-8589 Windows Zero-Day in Middle East Attacks

Cyber espionage group used CVE-2018-8589 Windows Zero-Day in Middle East Attacks

Kaspersky revealed that the CVE-2018-8589  Windows 0-day fixed by Microsoft Nov. 2018 Patch Tuesday has been exploited by at least one APT group…

7 years ago