Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
MITRE ATT&CK Walkthrough: T1140 (Deobfuscate/Decode Files or Information), T1105.
Broadcom's Symantec examines the detection gap for MITRE ATT&CK techniques T1140 (Deobfuscate/Decode Files) and T1105 (Ingress Tool Transfer). The walkthrough helps improve detection capabilities.
This case study from AhnLab ASEC describes the distribution of a CoinMiner targeting Linux SSH servers. The attackers use malware with propagation capabilities, including ShellBot, MIG LogCleaner, and XHide, to install the XMRig CoinMiner.
AhnLab ASEC observed attacks using malware to distribute XMRig CoinMiner on poorly managed Linux servers.
The AhnLab SEcurity intelligence Center (ASEC) is monitoring attacks targeting poorly managed Linux servers using multiple honeypots.
This article from Unit 42 examines the operations of The Gentlemen ransomware, highlighting how its affiliate model fuels rapid growth. The analysis provides insight into the group's strategies and the role of affiliates in expanding its impact.