FEBRUARY'S THREAT: CLOP RANSOMWARE |
The New Kid on the Block: the Clop RansomwareClop is ransomware that uses the .clop extension after having encrypted the victim's files. Another unique characteristic belonging with Clop is in the string: Dont Worry C0P included into the ransom notes. It is a variant of CryptoMix ransomware, but it additionally attempts to disable Windows Defender and to remove the Microsoft Security Essentials in order to avoid userspace detection.
You can validate your defenses against Ryuk malware samples with threats 789990, 536388, 864037, 752292 in Picus Threat Library. |
FEBRUARY'S THREAT ACTORS |
UNC2456
Hidden Cobra
For more information on Hidden Cobra Advanced Persistent Threat (APT) Group, here is the blog post you can read: Lazarus (Hidden Cobra) Group Employs HTA Embedded BMP FilesGamaredon
|
ATTACK SCENARIOS |
Atomic AttacksDisable Windows Defender for Endpoint by using Firewall Rules
Bypass User Access Control via ComputerDefaults.exe
Credential Dumping by using Custom MiniDumpWriteDump
|
MALICIOUS CODE |
Clop Ransomware
Hancitor Malware Downloader
DEWMODE Dropper used by UNC2546 Threat Group
|
WEB APPLICATION ATTACKS |
Atlassian Confluence Remote Code Execution via Macro Preview Feature
SAP Solution Manager Remote Code Execution Vulnerability Variant-1
Cisco ASA and Firepower Arbitrary File Deletion
Adobe Magento Commerce Cross-Site Scripting (XSS) Vulnerability
|
VULNERABILITY EXPLOITATIONS |
Google Chrome V8 Out of Bounds Read Vulnerability
Python PyCArg_repr Buffer Overflow Vulnerability
Windows Kernel CSRSS Denial of Service Vulnerability
|
SIGMA RULES |
Privilege Escalation via Modifying Group Policy Objects
System Information Discovery by Gathering OS Build Number Information via WMIC Tool
Windows Defender Disable via Firewall Rules
|
PICUS LABS MONTHLY #February 2021

Emerging Threat
Palo Alto CVE-2024-0012 and CVE-2024-9474 Vulnerabilities Explained

Emerging Threat
Understanding and Mitigating Midnight Blizzard's RDP-Based Spear Phishing Campaign

Emerging Threat
CVE-2024-47575: FortiManager Missing Authentication Zero-Day Vulnerability Explained

Emerging Threat
Iranian Cyber Actors’ Brute Force and Credential Access Attacks: CISA Alert AA24-290A

Emerging Threat
CISA Alert AA24-249A: Russian GRU Unit 29155 Targeting U.S. and Global Critical Infrastructure

Emerging Threat
CVE-2024-38063: Remote Kernel Exploitation via IPv6 in Windows

Emerging Threat
RansomHub Ransomware Analysis, Simulation, and Mitigation - CISA Alert AA24-242A

Emerging Threat
Pioneer Kitten: Iranian Threat Actors Facilitate Ransomware Attacks Against U.S. Organizations

Emerging Threat
Andariel: North Korean APT Group Targets Military and Nuclear Programs