Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / String of fileless malware assaults probably tied to unmarried hacker group

String of fileless malware assaults probably tied to unmarried hacker group

Latest Govt. Jobs 21:54:00 News Edit
A financially motivated hacker group is launching stealthy fileless attacks.

Several attacks observed over the past few months that rely heavily on PowerShell, open-source tools, and fileless malware techniques might be the work of a single group of hackers.
An investigation started by security researchers from Morphisec into a recent email phishing attack against high-profile enterprises pointed to a group that uses techniques documented by several security companies in seemingly unconnected reports over the past two months.
"During the course of the investigation, we uncovered a sophisticated fileless attack framework that appears to be connected to various recent, much-discussed attack campaigns," Michael Gorelik, Morphisec's vice president of research and development, said in a blog post. "Based on our findings, a single group of threat actors is responsible for many of the most sophisticated attacks on financial institutions, government organizations, and enterprises over the past few months."
The Morphisec investigation started with a phishing email that distributed a Microsoft Word document with malicious macros inside. When opened, the document asked the victim to click on the "Enable Content" button in order to view the supposedly protected content. Doing so allowed the malicious embedded code to execute.
From that point on, the attack used a succession of scripts written in PowerShell, a powerful scripting engine included in Windows, to set up persistence through registry keys and establish a communication channel with the attacker's server.
The attackers then downloaded and executed various open-source tools that allowed them to perform a deeper investigation of the system, steal locally stored Windows credentials, and open reverse shells to their server.
Some of the observed tools included Mimikatz, Lazagne, and Meterpreter, the payload of the popular Metasploit penetration testing framework. These programs were loaded directly into the computer's memory and left no traces on disk.
In February, researchers from Kaspersky Lab reported a string of stealthy, fileless attacks against more than 100 enterprises, banks, and government organizations from around the world. Those attacks used very similar techniques and tools, including PowerShell, Mimikatz, and Meterpreter.
In the attack investigated by Morphisec, the attackers also used a PowerShell script that established a two-way communication channel using DNS TXT records. A similar script was documented by researchers from Cisco Talos in early March in a PowerShell-based attack that they dubbed DNSMessenger.
The fileless malware techniques and DNS communication method were also described by researchers from FireEye in a March report about attacks targeting employees from various U.S. organizations whose jobs involved Securities and Exchange Commission (SEC) filings. FireEye attributed those attacks to a financially motivated attack group that the company has been tracking for a while under the name FIN7.
Previous FIN7 operations used the same malware as a group that Kaspersky tracks as Carbanak and is believed to be responsible for the theft of more than US$500 million from financial organizations and other companies.
The Morphisec researchers couldn't establish the identity of the group but had a brief interaction with one of the attackers.
"It was clear that a person from the other side was waiting to connect on his Meterpreter session," Gorelik said. "During the brief interaction, our researchers tried to identify the actor. The attackers immediately blocked the connection and later shut down the C2 server entirely, thereby losing their foothold in the systems of victims connected to that communication server."
In light of these attacks, organizations, especially those from the financial sector, should ensure that they have monitoring systems in place that can detect dual-use tools like Mimikatz and Meterpreter. They should also monitor for unauthorized PowerShell scripts and code loaded directly in memory that creates no executable files on disk.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


Oppo F7 India launch confirmed

Alcatel 1x with Android Oreo (Go ed...

Huawei P20, P20 Pro, P20 Lite price
String of fileless malware assaults probably tied to unmarried hacker group String of fileless malware assaults probably tied to unmarried hacker group Reviewed by Latest Govt. Jobs on 21:54:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Fitbit Zip 2017 review
    Fitbit PROS: Clever, accurate tracking Expandable online service Integration with 3rd ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...

Random Posts

  • What exactly is root?
    What exactly is root?
    18.02.2017 - 0 Comments
    When you root your Android, you're simply adding a standard Linux function that was removed. Root, at…
  • New Samsung Galaxy Tab S3 release date, news and rumors
    New Samsung Galaxy Tab S3 release date, news and rumors
    01.03.2017 - 0 Comments
    Update: A leaked Samsung Galaxy Tab S3 shot shows it alongside a keyboard and gives us…
  • Download Power Clean 2.7.13 for Android
    Download Power Clean 2.7.13 for Android
    29.02.2016 - 0 Comments
    Download Power Clean 2.7.13 for AndroidIn Tools by Developer LIONMOBI(4.5/5 average…
  • [New Offer Added] Pockets App – Get Rs 25 Off On Recharge Of Rs 100 [All Users] www.ultimateztricks.com
    [New Offer Added] Pockets App – Get Rs 25 Off On Recharge Of Rs 100 [All Users] www.ultimateztricks.com
    11.03.2016 - 0 Comments
    [New Offer Added] Pockets App – Get Rs 25 Off On Recharge Of Rs 100 [All Users]Posted on March 10,…
  •  Surface book 2 is probably a no-show at Microsoft’s next hardware release
    Surface book 2 is probably a no-show at Microsoft’s next hardware release
    28.03.2017 - 0 Comments
    The latest rumor about Microsoft’s spring device announcement event is that it won’t feature one…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Taotronics TT-BH22 Headphones Review
    We make it a ...
  • Bank wallets growing faster than e-wallets
    In the  bank ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on ...
  • Fitbit Zip 2017 review
    Fitbit PROS ...

Random Posts

  • Xiaomi Mi Pad 3 With Windows 10, 8GB RAM Rumoured to Launch on December 30
    Xiaomi Mi Pad 3 With Windows 10, 8GB RAM Rumoured to Launch on December 30
    16.12.2016 - 0 Comments
    HIGHLIGHTS Mi Pad 3 pricing is said to start at CNY 1,999 (roughly Rs. 20,000) It is likely to sport a…
  • Politicians' web browsing records focused after privateness vote
    Politicians' web browsing records focused after privateness vote
    06.04.2017 - 0 Comments
    Two GoFundMe campaigns have raised more than US$290,000 in an effort to buy the web browsing histories of…
  • Top 5 android Apps & Games 2017
    Top 5 android Apps & Games 2017
    17.01.2017 - 0 Comments
    1. Baton Battery life is the one thing a lot of us keep a very close eye on, but your phone isn’t…
  • Apps, social media pushing again sleep time over 1.5 hrs
    Apps, social media pushing again sleep time over 1.5 hrs
    23.03.2017 - 0 Comments
    Is WhatsApp keeping you up way past your bedtime? Yo u're not the only one, say doctors at…
  • No, cord reducing will now not spoil the internet
    No, cord reducing will now not spoil the internet
    30.03.2017 - 0 Comments
    File this one under “unexpected defenses of cable TV.” A couple of recent opinion pieces suggest that cord…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!