Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » CERT-UA discovers new malware wave distribution OCEANMAP, MASEPIE, STEELHOOK
    Cyber Security

    CERT-UA discovers new malware wave distribution OCEANMAP, MASEPIE, STEELHOOK

    techempireBy techempireNo Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportDecember 29, 2023Editorial DepartmentEmail Security/Malware

    malware

    烏克蘭電腦緊急應變小組(CERT-UA) 警告稱,與俄羅斯有關的APT28 組織精心策劃了一場新的網路釣魚活動,該活動部署了OCEANMAP、MASEPIE 和STEELHOOK 等以前未記錄的惡意軟體,以獲取敏感information.

    The agency detected the campaign between December 15 and 25, 2023, which targeted government entities with emails urging recipients to click on links to view documents.

    Upcoming webinars

    From user to administrator: Learn how hackers gain total control

    Learn the secret tactics hackers use to become administrators and how to detect and stop it before it’s too late. Register now for our webinar.

    Join now

    However, instead, these links redirect to malicious web resources that abuse JavaScript and the “search-ms:” URI protocol handler to drop Windows shortcut files (LNK) that launch PowerShell commands to launch known new malware chain of infection as Masepi.

    MASEPIE is a Python-based tool for downloading/uploading files and executing commands, and uses the TCP protocol to communicate with command and control (C2) servers over encrypted channels.

    These attacks further paved the way for the deployment of additional malware, including a PowerShell script called STEELHOOK, which collects web browser data and exports it in Base64-encoded format to an attacker-controlled server.

    A C#-based backdoor called OCEANMAP is also provided, designed to execute commands using cmd.exe.

    CERT-UA states that “the IMAP protocol is used as the control channel” and that the added persistence is achieved by creating a URL file named “VMSearch.url” in the Windows startup folder.

    “Commands are included in ‘drafts’ in the corresponding email directory in Base64-encoded form; each draft contains the computer name, username, and operating system version. The results of the command are stored in the inbox directory.”

    Internet security

    The agency further noted that reconnaissance and lateral movement activity was conducted within an hour of the initial intrusion using tools such as Impacket and SMBExec.

    A few weeks ago, IBM X-Force disclosed that APT28 used decoys related to the ongoing Israel-Hamas war to facilitate the delivery of a custom backdoor called HeadLace.

    In recent weeks, a Kremlin-backed hacking group is also believed to have exploited a now-patched critical security vulnerability (CVE-2023-23397, CVSS score: 9.8) in its Outlook email service to gain unauthorized access to victims. material. Account within the Exchange server.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.