Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Enjoy Easier Futures Trading Through CoinEx Futures bitcoin news
  • Following French Montana, Vietnam’s Number 1 Celebrity Singer Son Tung M-TP Joins RACA’s USM Metaverse – Press release Bitcoin News bitcoin news
  • Tron DAO Reserve Acquires Millions in TRX, Bitcoin, and Tether to Safeguard USDD – Bitcoin News bitcoin news
  • Crypto-Related Lawsuits Rising in Russia, Criminal Cases Increase by 40% – Bitcoin News bitcoin news
  • Book by Nigerian Author Reminds New Adopters Why Bitcoin Was Created – Featured Bitcoin News bitcoin news
  • Circle Announces the Stablecoin USDC Is Now Supported by the Polygon Network – Altcoins Bitcoin News bitcoin news
  • Latest Mobile Malware Report Suggests On-Device Fraud is on the Rise cyber security news
  • Binance Suspends Direct Deposits and Withdrawals in Brazil – Bitcoin News bitcoin news

SideWinder Hackers Launched Over a 1,000 Cyber Attacks Over the Past 2 Years

Posted on May 31, 2022 By root


SideWinder Hackers

An “aggressive” advanced persistent threat (APT) group known as SideWinder has been linked to over 1,000 new attacks since April 2020.

“Some of the main characteristics of this threat actor that make it stand out among the others, are the sheer number, high frequency and persistence of their attacks and the large collection of encrypted and obfuscated malicious components used in their operations,” cybersecurity firm Kaspersky said in a report that was presented at Black Hat Asia this month.

SideWinder, also called Rattlesnake or T-APT-04, is said to have been active since at least 2012 with a track record of targeting military, defense, aviation, IT companies, and legal firms in Central Asian countries such as Afghanistan, Bangladesh, Nepal, and Pakistan.

CyberSecurity

Kaspersky’s APT trends report for Q1 2022 published late last month revealed that the threat actor is actively expanding the geography of its targets beyond its victim profile to other countries and regions, including Singapore.

SideWinder has also been observed capitalizing the ongoing Russo-Ukrainian war as a lure in its phishing campaigns to distribute malware and steal sensitive information.

SideWinder Hackers

The adversarial collective’s infection chains are notable for incorporating malware-rigged documents that take advantage of a remote code vulnerability in the Equation Editor component of Microsoft Office (CVE-2017-11882) to deploy malicious payloads on compromised systems.

Furthermore, SideWinder’s toolset employs several sophisticated obfuscation routines, encryption with unique keys for each malicious file, multi-layer malware, and splitting command-and-control (C2) infrastructure strings into different malware components.

The three-stage infection sequence commences with the rogue documents dropping a HTML Application (HTA) payload, which subsequently loads a .NET-based module to install a second-stage HTA component that’s designed to deploy a .NET-based installer.

CyberSecurity

This installer, in the next phase, is both responsible for establishing persistence on the host and loading the final backdoor in memory. The implant, for its part, is capable of harvesting files of interest as well as system information, among others.

No fewer than 400 domains and subdomains have been put to use by the threat actor over the past two years. To add an additional layer of stealth, the URLs used for C2 domains are sliced into two parts, the first portion of which is included in the .NET installer and the latter half is encrypted inside the second stage HTA module.

“This threat actor has a relatively high level of sophistication using various infection vectors and advanced attack techniques,” Noushin Shabab of Kaspersky said, urging that organizations use up-to-date versions of Microsoft Office to mitigate such attacks.





TheHackersNews/

cyber security news

Post navigation

Previous Post: Learn Raspberry Pi and Arduino with 9 Online Developer Training Courses
Next Post: Report – Regulation Bitcoin News

Related Posts

  • Google’s New Safety Section Shows What Data Android Apps Collect About Users cyber security news
  • How to Improve Margins and Scale-Up Service Delivery cyber security news
  • Get Lifetime Access to 2022 Cybersecurity Certification Prep Courses @ 95% Off cyber security news
  • Google Researchers Detail 5-Year-Old Apple Safari Vulnerability Exploited in the Wild cyber security news
  • Zyxel Issues Patches for 4 New Flaws Affecting AP, API Controller and Firewall Devices cyber security news
  • GitLab Issues Security Patch for Critical Account Takeover Vulnerability cyber security news

Archives

  • July 2022
  • June 2022
  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • Russian Media Censor Roskomnadzor Blocks Major Crypto News Website – Bitcoin News
  • Jed McCaleb’s Ripple Stash Down to 81 Million — Co-Founder’s XRP Cache Likely to Dry Up This Year – Altcoins Bitcoin News
  • Exploit Forces Crema Finance to Temporarily Suspend Services, $8.7 Million Stolen – Bitcoin News
  • Blockfi CEO Says FTX Has an ‘Option to Acquire’ Crypto Lender at a Price of up to $240M – Bitcoin News
  • Dogecoin (DOGE) Could Use Some Lift

Recent Comments

No comments to show.
  • ATOM Might Trade Below Its Immediate Support Level Despite A Recent Rally bitcoin news
  • What Makes CoinEx the Most Popular Futures Trading Platform Among Beginners? bitcoin news
  • Binance Obtains Regulatory Approval to Offer Crypto Products in Italy – Regulation Bitcoin News bitcoin news
  • Glassnode Deems 2022 Bear Market As The Most Atrocious For BTC And All Cryptocoins bitcoin news
  • Ethereum Nears Breakout Zone, Why ETH Might Start Recovery bitcoin news
  • Sequel to Iconic RPG Ni No Kuni to Feature NFT Integration and Play-to-Earn Mechanics – News Bitcoin News bitcoin news
  • Government Agencies Warned of Increase in Cyberattacks Targeting MSPs cyber security news
  • Why Bitcoin Still At Risk of A Fresh Decline Below $29K bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme