zw01f.github.io/malware%20an...
Would love to hear your feedback!
#RokRat #APT37 #ScarCruft #malware #APT #MalwareAnalysis #Infosec
zw01f.github.io/malware%20an...
Would love to hear your feedback!
#RokRat #APT37 #ScarCruft #malware #APT #MalwareAnalysis #Infosec
This is solid-solid-SOLID B+ malware, very close to A- malware.
APT37 is using a old-school playbook. They're doing EPO (Entry Point Obfuscation) on a self-delivered binary for evasion. They also unironically are using something akin to cavity infection ...
This is solid-solid-SOLID B+ malware, very close to A- malware.
APT37 is using a old-school playbook. They're doing EPO (Entry Point Obfuscation) on a self-delivered binary for evasion. They also unironically are using something akin to cavity infection ...
#crypto #blockchain #news
#crypto #blockchain #news
-Storm-1516 campaigns shift from US to Ukraine's EU backers
-FAMOUS CHOLLIMA active with 26 npm packages
-APT37 adds air-gap malware
-Unfixed Matrix and Node.js bugs
-RCEs in Unitree robots
-3k Google API keys leaked online
-Log4j calls out AI sloppers
-Ton of new tools
-Storm-1516 campaigns shift from US to Ukraine's EU backers
-FAMOUS CHOLLIMA active with 26 npm packages
-APT37 adds air-gap malware
-Unfixed Matrix and Node.js bugs
-RCEs in Unitree robots
-3k Google API keys leaked online
-Log4j calls out AI sloppers
-Ton of new tools
Despite all of these super cool features, APT37 shoots themselves in the foot immediately.
- EAT walking for Kernel32 functionality (???)
- XOR decryption is a huge red flag
- Allocating with PAGE_EXECUTE_READWRITE (???)
-
Despite all of these super cool features, APT37 shoots themselves in the foot immediately.
- EAT walking for Kernel32 functionality (???)
- XOR decryption is a huge red flag
- Allocating with PAGE_EXECUTE_READWRITE (???)
-
-FlowerStorm PhaaS adds VM-based obfuscation
-APT37 poses as the police
-Twill Typhoon's FDMTP backdoor
-New TencShell attacks
-Sandworm and Leek Likho activity still going
-UK sanctions Russian disinfo firms
-Malware reports on Gremlin Stealer, Vidar, XWorm
-FlowerStorm PhaaS adds VM-based obfuscation
-APT37 poses as the police
-Twill Typhoon's FDMTP backdoor
-New TencShell attacks
-Sandworm and Leek Likho activity still going
-UK sanctions Russian disinfo firms
-Malware reports on Gremlin Stealer, Vidar, XWorm
www.bleepingcomputer.com/news/securit...
www.bleepingcomputer.com/news/securit...
-DDoS booters attempt comebacks in hours
-Ransomware gangs live around one year
-New Desolator and The Gentlemen RaaS
-New ZynorRAT, MostereRAT, RatOn, Salat Stealer, GPUGate malware
-New Salt Typhoon and APT37 infrastructure
-Patch Tuesday is out
-SessionReaper vuln
-DDoS booters attempt comebacks in hours
-Ransomware gangs live around one year
-New Desolator and The Gentlemen RaaS
-New ZynorRAT, MostereRAT, RatOn, Salat Stealer, GPUGate malware
-New Salt Typhoon and APT37 infrastructure
-Patch Tuesday is out
-SessionReaper vuln