Showing posts with label malware. Show all posts
Showing posts with label malware. Show all posts

Wednesday, April 10, 2024

Typosquatting with Mikhail

The Infrastructure Boss


by Dominic Alvieri
April 10th, 2024




What does a former Boris Yeltsin era Defense Minister for the Russian Federation have to do with cybercrime and ransomware today?

Since early 2023 I have been tracking a cybercrime infrastructure that now accounts for over 800 phishing websites pretending to be banks, software companies and cryptocurrencies deploying malware and dropping crypto stealers.

All of the 800+ phishing sites have two things in common. They are all registered with NiceNIC.NET and the WHOIS registrant organization is "Mihail Kolesnikov." 

Several countries of origin are used including Belize and Belgrade. A few websites were also registered under the correct spelling of Mikhail with the vast majority registered as "Mihail."

Hunters International is the latest ransomware and data extortion group to join.


Hunters International


Several of the websites were deploying bumblebee malware along with various stealers. Redline stealer and new versions of Rilide and Fletchen stealers. 

A quick look - Fletchen stealer features some of the same wide array of malicious activities as other stealers including credential theft, Wi-Fi login details, browser history and cookie retrieval along with several crypto clipper options. 

Fletchen stealer is written in Rust with simple panel access and is easy to navigate but script kiddies beware, you need technical abilities to encrypt the stealer.exe file.








Hunters International registered their clearnet leak site with the registrant organization of Mihail Kolesnikov in January of this year.



WHOIS data from Hunters International


All of the malicious websites have been registered since 2022 and continue under the typosquatted registrant organization of Mihail Kolesnikov. 



Typosquatting Mikhail.




Clippers replace the destination address and replace them by generating a corresponding address with Fletchen stealer (pictured below) currently stealing Bitcoin, Ethereum, Litecoin USDC, USDT even Dogecoin and other cryptocurrencies.

"history",
"webRequests",
"tabs",
"clipboardWrite",
"clipboardRead",
"management",
"<all_urls>"
],

Fletchen Stealer

Former Rilide C2 domain /silent-scale.com

A full report will be out in the month or so detailing the Chinese registrations and Russian C2's associated with all of these "Mihail Kolesnikov" websites and malware.


The Cyber Show, by Dominic Alvieri



Dominic Alvieri
X @AlvieriD



Wednesday, May 31, 2023

Cracking the Connected Floor

Analytics and Cybersecurity 


By Dominic Alvieri
May 23rd, 2023



This KPI Isn't Pointing in the Right Direction

Fortune 500 companies are expanding their attack surfaces in a new data analytics push.

Cybersecurity takes a back seat for data analytics in a manufacturing executives dream which is turning out to be a security nightmare. It's called the connected shop floor and in this current version isn't going to end well. Corporate executives are unintentionally and unnecessarily exposing themselves to unnecessary risks. 

"This is largely driven by connecting machines using IoT and enabling Ai to digitize the results"

Apple iPads and Microsoft Bi along with several outsourced apps and technologies are involved.




100's of new endpoints and unrestricted devices 


All employees who have access to these new IoT devices running the backbone of this technological shop floor had open browser access and email capabilities. Personal emails as well as corporate and a host of new apps and software.

Oops, an employee just clicked on one of their personal emails and got phished.

Before drilling deeper into the technologies and possible exploits available for a starter there are hundreds of new IoT devices with an unrestricted browser able to view porn, YouTube or TikTok videos. A small time phisherman with a low grade infostealer may unknowingly get access to a Fortune 500 company employee and not even know it. 





The good news

Executives are starting to learn about cybersecurity. The bad news? They are slow and stubborn.

Here is a no brainer-restricting employee browser access.



App Avalanche


Once again executives are slow in embracing cybersecurity. They need the numbers to crunch to squeeze every last ounce of shareholder value that you can. Security often takes a back seat.

"Cybersecurity does not add revenue" one executive told me on the condition of anonymity. 






Exploitable


Querying one of the apps being used in one version of the connected floor returned an interesting response resulting in an error in my SQL syntax. Input sanitation issues are red flags indicating injection flaw exploits. 

Obviously I am unable to mention the firm or app until the issue is resolved. 

There are other exploitable alleys in this project.


The Deeper I Drill...

I have not received  any responses to my questions regarding the above mentioned security issues along with an uncovered topic. 


I am offensive in nature even in a defensive posture.
...

There are more holes in the floor.




Friday, March 17, 2023

SpaceX Contractor Allegedly Breached

 LockBit leaves a message for Elon Musk


By Dominic Alvieri
March 17, 2023
Twitter @AlvieriD



SpaceX contractor allegedly breached.


To breach a contractor. That is in one sense a back door into a companies product or service without hacking into the company itself. This perfect example is the alleged breach of Maximum Industries from Texas. Maximum is a precision manufacturer and AS-9100 certified meaning their parts can be and are supplied to the aerospace industry. AS-9100 is a management standard for manufacturers in the aerospace industry supply chain.

LockBit posted Maximum Industries earlier in the week with an explicit message to Elon Musk. Last night LockBit posted alleged evidence composing of a mutual non-disclosure agreement and "certified" SpaceX drawings. 

LockBit message to Elon in the post below.




LockBit post.



Elon Musk is possibly the number one target in the world. So are his companies and their suppliers.

LockBit claims upwards of 3,000 SpaceX drawings. Catching up with several in the know each one product may have 100 or more drawings with variations and modifications fit to scale so the actual number of products compiled in any LockBit claim would have to be reduced significantly.

What is it worth?


Hard to say without additional evidence, and I'm not in the rocket parts market but there has to be some value to any and all competitors. The part in question does not seem high tech per se but neither is a pencil until you need to write something down. Remember writing?

Is that a 2019 model rocket in your garage?



Mutual non-disclosure agreement


This is tricky. Under normal business disclosure by either side would void the agreement. What are the legal ramifications? I am not a lawyer but did speak with one under the condition of anonymity and was advised not to comment on this. So much for hindsight.

Anyone could have made that copy of the alleged NDA btw. The alleged document is cutoff, unsigned and unverified at the moment. If it was authentic copies would be available to forensically match what was shown including handwriting analysis if needed. 

What happens when a ransomware group discloses an NDA?


This is the current situation. Once again I am not a lawyer and you a reading a free cybersecurity blog so no legal advice. This one is playing out live now.

"...SpaceX contractors were more talkative"

Analyzing this statement would lead one to believe that LockBit might have contractor emails. Take that with a bit of salt. A bit of salt. Cyber dork.





Neither company has made any comment as of this writing and I don't expect Elon Musk to respond to my tweet. Oh well, cyber goes on.

The deadline is Monday pending further drama this weekend.







The Cyber Show

Happy Saint Patrick's Day

@AlvieriD

Friday, February 3, 2023

I Can Name That Exploit in One Note

 Another New Day and Another New Way...


By Dominic Alvieri
February 3rd, 2023

The Cyber Show, by Dominic Alvieri.


Do your steganographic skills suck? Never fear 2023 is here. I guess I wasted years practicing the dark art of stego now with so many new ways to discretely infect, compromise and take over your target. 

How? Hiding your malicious file in an empty element is one way recently disclosed by researchers. Needless to say there are several other ways to play around with elements.





Another popular choice... embedding a malicious file within One Note. 


One Note.

You can't hard code all of your website. It's just not practical. Now that Microsoft has disabled macros threat actors are finding new ways to infiltrate networks. One Note has taken center stage and Microsoft Visual Studio just joined the fray. 

Here is a short list of files to closely examine or block that are being abused by TAs

.msha
.htm
.lnk
.js

You can do this with many different files and ways.

Ill leave you with this partial...

c:\ encrypt files
\"what?"\ attrib -h (?) -r  ("nice-try")

Redacted



 

Monday, January 30, 2023

Undisputed LockBit

LockBit is clearly the leading group left standing...for now.


By Dominic Alvieri

January 30th, 2023

@AlvieriD 


LockBit is the undisputed number one group.


In the early morning hours of Thursday, January 26th a multi-governmental offensive seized the Hive Ransomware leak site. No arrests have been made in the never ending ransomware whack-a-mole game. LockBit is now the undisputed leading ransomware operation.



Hive Ransomware leak site was seized on Thursday.


That evening LockBit was ready with a new game, comments and plenty of leaks ready to go. The Hive Ransomware leak site was seized early Thursday morning and the first comment or post from LockBit was a freaking game below.


LockBit playing games.

The post above was removed by LockBit. Researchers at VX Underground were able to get a comment from Mr. LockBit about the post and the news that followed. LockBit is one group I do not have communications with and do not care to. 

By Sunday evening it was business as usual as LockBit posted affiliate offerings of 14 new victims not willing to pay them from around the world. 


14 new companies ransomed by LockBit.

Spain

France

Mexico

Austria

Albania

Portugal

Australia

United States

United Kingdom


LockBit KVIE post.

Air Albania ransomed by LockBit.


Low lights from the new posts include PBS member television station KVIE in Sacramento, California, Air Albania, CPL Industries...



PBS station KVIE ransomed by LockBit.

 

LockBit is clearly the top operation remaining and is arrogantly making it known. Alphv Black Cat Ransomware is behind LockBit and there is a clear distinction from the remaining groups including new up and coming Play Ransomware, Black Basta, Vice Society...


Several other groups and former members are not included in this article including Black Matter, DarkSide and the other variations, spinoffs and new groups pending like Endurance Ransomware.


No Hive arrests to date.


Affiliates have to go somewhere...





The never ending ransomware whack-a-mole game continues in 2023.

The Cyber Show

Saturday, November 5, 2022

2 Minute Social Media Account Protection Guide

Some Old Tricks Are Back


By Dominic Alvieri
October 5th, 2022

The bird is ill.


The Bird is Being Fished


Twitter staff has just been cut in half.

Half of the cybersecurity department and every department is missing staff and that might bring out more scammers. There has already been an increase in verification phishing targeting Twitter in the past week in addition to the usual scams.

Several old tricks are back. Secure your accounts with phishing resistant MFA. Here is a quick list of several of the old scams that have returned and what to look for.



Twitter challenges with half of the staff missing.


Is the official social media account with a hyphen or an underscore? or without them?


Is the official login with a dot or a hyphen?


One of the most dangerous Twitter phishing domains came back to life yesterday, login-twitter.com

The official Twitter login is login.twitter.com

One of the original scams is the hyphen replacing the dot on an URL. The hyphen can replace an underscore on a social media account and the other way around. An underscore is viewed as a continuation while a hyphen is a separation. Both are used. 

The good news-Very easy to spot and search engines consider hyphens spammy which helps deter SEO poisoning making it difficult for a major SEO poisoning campaign. 

The bad news-Still easy to fall for and still subject to major phishing and smishing campaigns.


openseablog and OpenSeaBlog


Both of these accounts are active now tweeting a fake critical vulnerability scare pointing to a new malicious domain name shown below.



Twitter @AlvieriD





The official Twitter login is not hyphenated

The official Twitter login does not have a hyphen.


Getting phished at Twitter?



Is the official domain a dotcom, dotnet or an xyz?


Malicious domain registrations are a continuous battle with every new TLD approved. Twitter is a dotcom. MetaMask is an io. You need to know the official domain of the company or service you plan to utilize.

The large "i" that replaces the small "L"


The title says it all. Lookalike social media handles can cause havoc.

On your left is my Twitter account and your right is a spoof. Both appear to be @AlvieriD



Dominic Alvieri, Twitter @AlvieriD


Copy a few lines of text and a few photos and you have a near perfect fake account impersonating me. 

This again is not new but making a comeback. Domains and social media companies are vulnerable to this scam. Even Elon Musk had his account spoofed with this scam as shown below.

The account on your left is his official account while the one on the right is @ e"I"onmusk 


Fake Elon Musk Twitter account.


Any company or person with an "L" in their name is vulnerable to this social media account scam. Website domains have been vulnerable to this since the start of the commercial internet.

There are so many other scams and frauds to watch out for. It's always the little things.


The Cyber Show by Dominic Alvieri.


The Cyber Show
Dominic Alvieri
Twitter @AlvieriD

Thursday, October 13, 2022

New Chinese Misinformation Campaign

Fake Campaign Attempts to Attribute Chinese Advanced Persistent Threat Group APT 41 to the NSA


By Dominic Alvieri 

@AlvieriD

October 12th, 2022


New Chinese misinformation campaign


A new Chinese misinformation campaign has been spreading this past week attempting to attribute the Chinese APT 41 to the National Security Agency. Many are using the Intrusion Truth name. 


Global Times Chinese domain article tweet.





Several new accounts tweeted in Chinese Mandarin for the local media in Asia while others have been created in English for a wider audience. All accounts use the APT 41 hashtag. 


Kimberly Allen Fake FireEye Attribution in Mandarin





The above tweet translates to FireEye attributing Chinese APT 41 to the NSA.


The tweet above has been removed but the account remains.





The FBI reports concludes what we all know while some are trying to create confusion in typical APT 41 style.



Dominic Alvieri, @AlvieriD Twitter

This is a new and current campaign with all accounts still currently open. No new activity has been spotted since the initial report this week with fake attribution tweets.


Blog will be updated as needed. Stay safe.





Friday, March 11, 2022

The DarkWeb is Pretty Bright on Telegram and Twitter

Dark net services displayed on social media.


By Dominic Alvieri

@AlvieriD

3-9-2022



More and more services and communications that were once reserved for the deepest depths of the DarkWeb are crawling up the stack, if you will to social media platforms. Ransomware group posts are now mainstream on Telegram and Twitter with calls for action, mis or disinformation and fake data leaks.

The hacking free for all


The Russian invasion of Ukraine on February 24th brought about armies of hacktivists, some real while the majority are unskilled and caught up in the wave. Legitimate groups like LAPSUS have taken to social media to announce high profile breaches from Samsung and Nvidia while other groups pretend to have hacked the world.

IT Army of Ukraine

The IT group turned army calls on users to for action providing details of direct targets the group requires taken down. More and more the IT Army of Ukraine posts targets in English and Ukrainian.





Network Battalion 65' posted a fake leak that was so embarrassing for the group but yet they post again. Not shown.


Network Battalion 65'



Like many groups constantly changing members. Brief synopsis is that the group revamping after a fallout and fake Kaspersky leak attempt. Keep an eye out.

Outrageous breach claims have been the norm. Unverified claims ranging from The National Bank of Russia to the FBI itself have been hacked. Hack the Planet until there is nothing left. Peak infosec I believe it was called. Thanks Carl.

Epic leak fail award goes to Network Battalion 65'


Right now this is a black eye that needs to be addressed. Kaspersky itself is facing intense pressure from security staff but this data breach was confirmed fake.


Kaspersky fake data leak.


Kaspersky has issued an official response courtesy of @ajvicens



Kaspersky official response to March 9th NB65 breach claim.

GhostSec

GhostSec like many malicious groups has several channels. IntelGS is Intel GhostSec a darker splintered part of the group that has also joined in the cyber war.


GhostSec


GhostSec channels appear to be currently fragmented and not coordinated.




Lapsus$


After two successful high profile leaks of Samsung and Nvidia last week LAPSUS is toying around with an anonymous poll when allegedly they have already breached Vodafone.

Mercado Libre just disclosed a breach on their latest 8k release this week with the Securities and Exchange commission. Mercado did not release a timeline or provide more vector details at this moment. 

Impresa the Portuguese media giant was hacked by Lapsus$ over the new years holiday and has had several website and platform issues ever since. The main Impresa website /impresa.pt has been down and is currently down as of March 11th, 2022.


Impresa of Portugal hacked by Lapsus.



Lapsus$ is seen toying with companies they have already hacked and allegedly hacked. Vodafone is unconfirmed at the moment.



LAPSUS Vodafone breach claim.


Groups regularly post claims and recruit people of all types. Anonymous groups large and small have taken over social media with misinformation and disinformation campaigns creating profiles, hashtags and using automated software and bots to promote their goals.

Videos and photoshopped imagers are the norm. 


IY Army of Ukraine post.


Against the West / Blue Hornet


The group appears to be restructuring and has been quiet this week as of last check. Like all groups use caution so that you don't get stung.


Against the West.

Trolls

Don't waste your time.

Stormus group tops that list. Others come to mind.

Verify any information or disinformation before you respond in any way, if at all.



Gazprom alleged data leak on Telegram




Lapsus$ live post as I blog taking credit for Ubisoft hack and advertising The Verge article about it on one of their channels.


Ubisoft hacked by Lapsus$


Lapsus$ appears to have several flaws, youth, inexperience in several key areas, smashing and grabbing what they can, the group is buying inside access from either an employee or vendor and then getting to work. Access is usually gained through a VPN or AnyDesk remote control application, recon, targeting and then deploying payloads. Social engineering methods and other low grade tactics.

Check your employees and vendors.

Currently advertising for services now.

Updated: 7 members of Lapsus$ have been arrested aged 16-21. Other members are still at large and doubtful ring leader or mastermind is teenager arrested in Oxford, England as media claims. I do not believe that to be true. There are more members at large. To be continued...


Lapsus$ advertising for hackers.

Conti

Still alive and kicking albeit smaller and segmented. Looking to reform in Russia.

Samsung Leak

Lapsus$ again.



LockBit has just allegedly leaked several companies from Singapore, verification pending. LockBit has been very active in the past 30 days. Lapsus has a mock vote due this weekend to leak another high profile company and I'm sure they will be plenty of fake anonymous group claims. 

There are other groups but this was intended to be a brief account.  
Stay safe.




Dominic Alvieri

Twitter @AlvieriD

The Kremlin, Politics and Ransomware

Qilin Ransomware caught with politically motivated fake document (and old data) in post. by Dominic Alvieri March 8th, 2025 @AlvieriD Was it...