« 2023 »

627 reports

2023-04-20 • Mandiant

Mandiant found that the 3CX Desktop App supply-chain compromise began with an earlier compromised X_TRADER installer from Trading Technologies, making it a cascading software supply-chain attack. The X_TRADER package deployed VEILEDSIGNAL through DLL side…

#YARA #SupplyChain #3CXDesktopApp #SmoothOperator #UNC4736 #X_Trader #UNC4469 #UNC3782 #T1082 #T1140 #T1070.004 #T1071.001 #T1195.002 #T1112 #T1083 #T1497 #T1036 #T1027 #T1071 #T1195 #T1497.001 #T1105 #T1055 #T1620 #T1574.002 #T1622 #T1190 #T1588 #T1574 #T1573.002 #T1614 #T1573 #T1608 #T1070 #T1614.001 #T1071.004 #T1012 #T1588.004 #T1565.001 #T1036.001 #T1070.001 #T1608.003 #T1565
2023-04-20 • ESET

ESET links a Lazarus Operation DreamJob campaign against Linux users to broader evidence connecting the group with the 3CX supply-chain compromise. The Linux intrusion chain used a ZIP archive containing a fake HSBC job offer lure, where a deceptive Unico…

#DreamJob #YARA #3CXDesktopApp #SmoothOperator #T1090 #T1140 #T1585.003 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1083 #T1204.002 #T1566.002 #T1132.001 #T1573.001 #T1497.003 #T1593.001 #T1584.001 #T1134.002 #T1027.009 #T1562.003 #T1546.004
2023-04-18 • Microsoft

Microsoft announced a shift from its older Elements, Trees, Volcanoes, and DEV naming systems to a weather-themed threat actor taxonomy. The taxonomy is intended to make actor references clearer by grouping names around attribution or motivation and using…

#Sleet