Cybersecurity researchers have uncovered a targeted attack campaign affecting multiple Israeli organizations, utilizing accessible tools such as Donut and Sliver. Dubbed "Supposed Grasshopper" by HarfangLab, the campaign employs custom infrastructure and WordPress sites tailored to distribute payloads across diverse sectors. Initially, a Nim-written downloader connects to "auth.economy-gov-il[.]com/SUPPOSED_GRASSHOPPER.bin" to fetch second-stage malware, often via virtual hard disk (VHD) files through compromised WordPress platforms using drive-by download techniques. The second-stage payload, Donut, serves as a shellcode generator facilitating the deployment of Sliver, an open-source alternative to Cobalt Strike. The attackers have invested in dedicated infrastructure and convincingly crafted WordPress sites to optimize their payload delivery, suggesting a well-resourced, potentially small team orchestrating the campaign. The precise objectives of these attacks remain ambiguous, although HarfangLab speculates they could involve legitimate penetration testing or attempts to mimic Israeli government entities, raising significant transparency concerns. In parallel, SonicWall Capture Labs has identified another threat named Orcinius, propagated through malicious Excel spreadsheets. Orcinius, a multi-stage trojan, utilizes Dropbox and Google Docs to download subsequent payloads. It employs obfuscated VBA macros for persistence and monitors system activities such as keystrokes and running applications. These developments underscore ongoing cybersecurity challenges, with attackers leveraging sophisticated techniques and publicly-available tools to target specific organizations, potentially for espionage or disruption purposes. Vigilance in updating defenses and monitoring for unusual network activity remains crucial in mitigating such threats.
Europol has announced the disruption of Audia6, a large-scale cryptocurrency investment fraud network responsible for defrauding victims across multiple countries through sophistic...
Researchers have identified a new campaign in which the Russia-linked threat group APT28 has been leveraging the Moobot botnet to compromise internet-facing routers and Internet of...
Cybersecurity researchers at Tenet Security have uncovered a new attack technique called Agentjacking, which targets AI-powered coding assistants and can trick them into executing ...