Tag: 2024-05-11
3 attack reports | 0 vulnerabilities
Attack reports
SugarGh0st RAT Used to Target American Artificial Intelligence Experts
This intelligence report provides details about a SugarGh0st RAT campaign conducted by an unattributed threat actor, tracked as UNK_SweetSpecter, targeting organizations in the United States involved in artificial intelligence (AI) efforts across academia, private industry, and government. The camp…
Downloadable IOCs 9
To the Moon and back(doors): Lunar landing in diplomatic missions
ESET researchers discovered two previously unknown backdoors – LunarWeb and LunarMail – compromising a European ministry of foreign affairs and its diplomatic missions abroad. LunarWeb, deployed on servers, utilizes HTTP(S) for command and control communications, mimicking legitimate requests to av…
Downloadable IOCs 12
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
The report describes a recent campaign by the threat actor Storm-1811, a financially motivated cybercriminal group known for deploying Black Basta ransomware. The campaign begins with social engineering tactics like voice phishing (vishing) and email bombing to trick users into granting remote acce…
Downloadable IOCs 12
SugarGh0st RAT Used to Target American Artificial Intelligence Experts
This intelligence report provides details about a SugarGh0st RAT campaign conducted by an unattributed threat actor, tracked as UNK_SweetSpecter, targeting organizations in the United States involved in artificial intelligence (AI) efforts across academia, private industry, and government. The camp…
Downloadable IOCs 9
To the Moon and back(doors): Lunar landing in diplomatic missions
ESET researchers discovered two previously unknown backdoors – LunarWeb and LunarMail – compromising a European ministry of foreign affairs and its diplomatic missions abroad. LunarWeb, deployed on servers, utilizes HTTP(S) for command and control communications, mimicking legitimate requests to av…
Downloadable IOCs 12
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
The report describes a recent campaign by the threat actor Storm-1811, a financially motivated cybercriminal group known for deploying Black Basta ransomware. The campaign begins with social engineering tactics like voice phishing (vishing) and email bombing to trick users into granting remote acce…
Downloadable IOCs 12
SugarGh0st RAT Used to Target American Artificial Intelligence Experts
This intelligence report provides details about a SugarGh0st RAT campaign conducted by an unattributed threat actor, tracked as UNK_SweetSpecter, targeting organizations in the United States involved in artificial intelligence (AI) efforts across academia, private industry, and government. The camp…
Downloadable IOCs 9
To the Moon and back(doors): Lunar landing in diplomatic missions
ESET researchers discovered two previously unknown backdoors – LunarWeb and LunarMail – compromising a European ministry of foreign affairs and its diplomatic missions abroad. LunarWeb, deployed on servers, utilizes HTTP(S) for command and control communications, mimicking legitimate requests to av…
Downloadable IOCs 12
Threat actors misusing Quick Assist in social engineering attacks leading to ransomware
The report describes a recent campaign by the threat actor Storm-1811, a financially motivated cybercriminal group known for deploying Black Basta ransomware. The campaign begins with social engineering tactics like voice phishing (vishing) and email bombing to trick users into granting remote acce…
Downloadable IOCs 12