Most downloaded among the malicious packages was "blockscan-api," which is a backdoored copy of etherscan-api, followed by "passport-js," which is a backdoored passport copy, and the backdoored bcryptjs copy dubbed "bcrypts-js," an analysis from the Datadog Security Research team showed.
UNC5812 under the guise of "Civil Defense" on Telegram distributed free Ukrainian military recruiter locator software, which when downloaded on Android devices triggered the deployment of the CraxsRat backdoor, which has keystroke tracking, contact and credential exfiltration, and file and SMS management capabilities, as well as the decoy mapping app Sunspinner.
After leveraging numerous initial attack vectors, including vulnerability exploitation and DNS poisoning, to infiltrate targeted networks, Evasive Panda proceeds with the distribution of the MgBot and Nightdoor payloads, with the former leveraged to deploy 10 CloudScout modules, three of which target Google Drive, Gmail, and Microsoft Outlook, according to an analysis from ESET.
Such crackdown efforts have enabled access to the infostealers' source code, including REST-API services, license servers, stealer binaries, and Telegram bots, as well as the IP addresses, credentials, and registration details of their users, said the agencies in a video posted on Operation Magnus website.
Aside from featuring Chacha 20 encryption retained from older variants of the ransomware, Qilin.B has been strengthened with AES-256-CTR encryption, which could be leveraged to compromise AESNI-capable systems, as well as RSA-4096 with OAEP padding.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.