Intrusions discovered earlier this week commenced with the delivery of a malicious email purporting to be from a CrowdStrike employment agent that includes a link for downloading an employee CRM app, which when clicked redirected to a CrowdStrike-spoofing website offering Windows and macOS versions of the app, according to CrowdStrike.
Included in the discovered web shells were China Chopper — which is a fixture among advanced persistent threat operations — c99shell, and r57shell, as well as a backdoor that integrated Lazarus Group-like capabilities, according to a report from WatchTowr Labs.
After performing client app initialization, NonEuclidRAT — which has been proliferating in the dark web since late November — conducts detection bypass checks and establishes a TCP socket while adding Microsoft Defender Antivirus exclusions and leveraging Windows API calls for process enumeration.
DNA sequencer vulnerabilities, threat actor naming conventions, new CNAs and problems, backdoors are not secrets (again), The RP2350 is hacked!, they know where your car is, treasury department hacked, what if someone hacked license plate cameras? Tenable CEO passes away, and very awkwardly, a Nessus plugin update causes problems, who needs fact-ch...
Vulnerable Illumina iSeq devices, which lacked firmware read and write protections and had Secure Boot disabled, could be subjected to privileged escalation attacks and subsequent arbitrary code execution in their firmware, according to an Eclypsium report.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.