News

Google News
socprime. com > active-threats > gammasteel-inside-gamaredons-unfolding-malware-chain

Gamma Steel Uses Registry-Stored Power Shell and Tebi

1+ day, 1+ hour ago  (751+ words) SOC Prime SOC Prime Bias: Critical Gamma Steel: Inside Gamaredon's Unfolding Malware Chain The report describes Gamma Steel, a new Gamaredon ( UAC-0010 ) intrusion chain built around a fileless Power Shell stealer. The malware stores 71 encrypted functions in the HKCU\Printers…...

Symbols: btc-usd,cert-ua
Google News
socprime. com > active-threats > the-demon-arrives-later-a-havoc-stager-hides-behind-microsoft-defender-dlp

Fake Defender DLP MSI Delivers Havoc Stager

5+ day, 5+ hour ago  (352+ words) SOC Prime SOC Prime Bias: Medium The Demon Arrives Later: A Havoc Stager Hides Behind Microsoft Defender DLP Threat actors in Brazil are distributing spoofed electronic invoice NF-e ZIP attachments that deliver a malicious MSI installer. The MSI drops a…...

Symbols: cwe-59
SOC Prime
socprime. com > active-threats > donutloader-reloaded-in-a-modern-remcos-rat-campaign

Donut Loader Delivers Remcos RAT via colorcpl. exe

1+ week, 1+ hour ago  (401+ words) SOC Prime SOC Prime Bias: Medium Donut Loader Reloaded in a Modern Remcos RAT Campaign G DATA has identified a fresh Remcos RAT campaign that begins with a malicious batch file and moves through several scripting layers, including Power Shell,…...

Symbols: setup.js
SOC Prime
socprime. com > active-threats > operation-xenofiscal-sidecopy-deploys-persistent-xenorat-against-afghanistans-ministry-of-finance

Side Copy Deploys Xeno RAT Against Afghanistan's Mo F

1+ week, 1+ hour ago  (388+ words) SOC Prime SOC Prime Bias: Critical Operation XENOFISCAL: Side Copy Deploys Persistent Xeno RAT Against Afghanistan's Ministry of Finance The report outlines a spear-phishing operation in which a malicious LNK file triggers mshta. exe to download and execute a remote…...

SOC Prime
socprime. com > active-threats > operation-dragon-weave-uses-azure-cloud-c2-to-target-czech-republic-and-taiwan

Operation Dragon Weave Uses Azure C2 Against Czech and Taiwan

1+ week, 1+ hour ago  (748+ words) SOC Prime SOC Prime Bias: Critical Operation Dragon Weave Uses Azure Cloud C2 to Target Czech Republic and Taiwan A targeted espionage operation tracked as Operation Dragon Weave uses malicious LNK shortcut files together with a Rust-based executable to launch a…...

Symbols: nyse:kd
Google News
socprime. com > active-threats > ng0002-targets-chinese-academia-with-weaponized-institutional-lures

UNG0002 Targets Chinese Universities with Cobalt Strike

2+ week, 4+ day ago  (346+ words) SOC Prime SOC Prime Bias: Critical NG0002 Targets Chinese Academia with Weaponized Institutional Lures A threat actor tracked as UNG0002 launched a spear-phishing campaign against Chinese universities using a malicious ZIP archive disguised as an official fitness testing notice. Inside the archive…...

SOC Prime
socprime. com > active-threats > shub-reaper-macos-stealer-spoofs-apple-google-and-microsoft-in-a-single-attack-chain

SHub Reaper Targets mac OS with Fake Brand Installers

2+ week, 5+ day ago  (317+ words) SOC Prime SOC Prime Bias: Medium SHub Reaper | mac OS Stealer Spoofs Apple, Google, and Microsoft in a Single Attack Chain The report analyzes a new mac OS infostealer variant called SHub Reaper, which uses fake We Chat and Miro…...

SOC Prime
socprime. com > active-threats > purelogs-delivered-through-pawsrunner-steganography

Pure Logs Delivered via Paws Runner Steganography

3+ week, 1+ day ago  (400+ words) SOC Prime SOC Prime Bias: Medium Pure Logs Delivered Through Paws Runner Steganography The campaign relies on a phishing email carrying a TXZ archive that delivers a Java Script loader, which sets environment variables and launches conhost. exe in headless…...

SOC Prime
socprime. com > active-threats > iranian-nexus-campaign-hits-omani-government-ministries

Iranian-Nexus Campaign Hits Omani Government Ministries

1+ mon, 2+ day ago  (293+ words) SOC Prime SOC Prime Bias: Critical Iranian-Nexus Attack Exposes 26, 000 Citizen Records in Oman A state-aligned Iranian threat actor compromised multiple government ministries in Oman by using webshells, Proxy Shell exploits, and a custom command-and-control environment hosted on a UAE-based VPS....

Google News
socprime. com > active-threats > shadow-earth-053-targets-exchange-servers-in-asia

SHADOW-EARTH-053 Targets Exchange Servers in Asia

1+ mon, 4+ day ago  (460+ words) SOC Prime SOC Prime Bias: Critical Business search APT & Targeted Attacks Inside Shadow-Earth-053: A China-Aligned Cyberespionage Campaign Against Government and Defense Sectors in Asia A China-aligned threat cluster tracked as SHADOW-EARTH-053 has been exploiting unpatched Microsoft Exchange and IIS servers…...