blog.sekoia.io/phishing-cam...
blog.sekoia.io/phishing-cam...
It includes their use of the ClickFix tactic, PyInstaller, Node.js, Cloudflare Tunnels, and new PowerShell loader/backdoor ⬇️
bsky.app/profile/seko...
✍️ @kseznec.bsky.social
It includes their use of the ClickFix tactic, PyInstaller, Node.js, Cloudflare Tunnels, and new PowerShell loader/backdoor ⬇️
bsky.app/profile/seko...
✍️ @kseznec.bsky.social
blog.sekoia.io/interlock-ra...
blog.sekoia.io/interlock-ra...
e.g.
hxxps://ymi.bvyunz.]ru/3v4jfQ-cUo/
hxxps://xau.kolivax.]ru/ckYHFJN/
hxxps://ffqt.lzirleg.]es/VajlR/
⬇️
e.g.
hxxps://ymi.bvyunz.]ru/3v4jfQ-cUo/
hxxps://xau.kolivax.]ru/ckYHFJN/
hxxps://ffqt.lzirleg.]es/VajlR/
⬇️
ClearFake is injected into thousands of compromised sites to distribute the #Emmental Loader, #Lumma, #Rhadamanthys, and #Vidar.
⬇️
bsky.app/profile/seko...
buff.ly/vbiVbsN
ClearFake is injected into thousands of compromised sites to distribute the #Emmental Loader, #Lumma, #Rhadamanthys, and #Vidar.
⬇️
bsky.app/profile/seko...
buff.ly/vbiVbsN
buff.ly/vbiVbsN
cc @plebourhis.bsky.social @sekoia.io
1. ClearFake framework is injected on compromised WordPress and relies on EtherHiding
2. The #ClickFix lure uses a fake Cloudflare Turnstile with unusual web traffic
⬇️
cc @plebourhis.bsky.social @sekoia.io
1. ClearFake framework is injected on compromised WordPress and relies on EtherHiding
2. The #ClickFix lure uses a fake Cloudflare Turnstile with unusual web traffic
⬇️
- the targeted phishing attack against extension developers
- malicious code
- the adversary's infrastructure
⬇️
bsky.app/profile/seko...
https://buff.ly/4auQ0HN
- the targeted phishing attack against extension developers
- malicious code
- the adversary's infrastructure
⬇️
bsky.app/profile/seko...
https://buff.ly/4auQ0HN
https://buff.ly/4auQ0HN
These archives contain an AutoIT dropper, we internally named #SelfAU3 Dropper at @sekoia.io, which executes #Lumma Stealer
IoCs ⬇️
These archives contain an AutoIT dropper, we internally named #SelfAU3 Dropper at @sekoia.io, which executes #Lumma Stealer
IoCs ⬇️
We provide an in-depth analysis of the phishing pages, the associated service, detection opportunities and multiple IoCs.
⬇️
bsky.app/profile/seko...
https://blog.sekoia.io/sneaky-2fa-exposing-a-new-aitm-phishing-as-a-service/
#detection #sneaky2fa
We provide an in-depth analysis of the phishing pages, the associated service, detection opportunities and multiple IoCs.
⬇️
bsky.app/profile/seko...
HTTP Location header set to "hxxps://t.]me", instead of "hxxps://google.]com"
Heuristic to track C2 IPs and domains on Censys:
search.censys.io/search?resou...
Dead Drop Resolvers (DDR) of the week:
hxxps://t.]me/no111p
⬇️
HTTP Location header set to "hxxps://t.]me", instead of "hxxps://google.]com"
Heuristic to track C2 IPs and domains on Censys:
search.censys.io/search?resou...
Dead Drop Resolvers (DDR) of the week:
hxxps://t.]me/no111p
⬇️
Featuring @crep1x.bsky.social from @sekoia.io!
intel471.com/resources/po...
Featuring @crep1x.bsky.social from @sekoia.io!
intel471.com/resources/po...