Month: November 2024
-
Unmasking Phishing: Strategies for identifying 0ktapus domains and beyond
This analysis examines phishing tactics used by threat actors, particularly focusing on the 0ktapus group. It outlines techniques for investigating…
-
Analysis of AsyncRATs Infection Tactics via Open Directories
This analysis explores two distinct methods used to infect systems with AsyncRAT through open directories. The first technique involves a…
-
Wreaking havoc in cyberspace: threat actors experiment with pentest tools
Recent research reveals adversaries increasingly using the Havoc post-exploitation framework to bypass cybersecurity systems. Two campaigns utilizing this framework were…
-
Investigating a SharePoint Compromise: IR Tales from the Field
An incident response investigation uncovered an attacker who exploited a SharePoint vulnerability (CVE-2024-38094) to gain initial access. The attacker remained…
-
G700: The Next Generation of Craxs RAT
G700 RAT, an advanced variant of Craxs RAT, targets Android devices and cryptocurrency applications. It employs sophisticated techniques like privilege…
-
Attacker Abuses Victim Resources to Reap Rewards from Titan Network
An attacker exploited the Atlassian Confluence vulnerability CVE-2023-22527 to achieve remote code execution for cryptomining via the Titan Network. The…
-
Cryptocurrency Enthusiasts Targeted in MultiVector Supply Chain Attack
A sophisticated malware campaign targeting cryptocurrency enthusiasts has been uncovered, utilizing multiple attack vectors including a malicious Python package on…
-
LastPass Warns of Hackers Misusing Reviews for Fake Support Numbers
LastPass has alerted users about a social engineering campaign targeting customers through fraudulent 5-star reviews on the Chrome Web Store.…
-
Ngioweb Proxy
This pulse contains IOCs related to Ngioweb Infrastructure. Additions are automatically added based on OTX sandboxed samples. Author: AlienVault Related…
-
Cobalt Strike Beacon Detected – 82[.]202[.]173[.]170:4434
* [Cobalt Strike](https://www.redpacketsecurity.com/category/cobalt-strike/)Cobalt Strike Beacon Detected — 82-[.-]202-[.-]173-[.-]170:4434================================================================[November 3, 2024](https://www.redpacketsecurity.com/2024/11/) Cobalt Strike Beacon Detection Alerts > The Information provided at…