Threat Researchers Live Episode 20, Thursday, April 28.
In today's episode:
Hacktivist groups: DoomSec, DragonForce Malaysia, Hackers of Savior, Killnet
DDoS Attacks: Currency[.]com, UA Postal Service, Finland Defense & Foreign Affairs sites, Czech critical services, Israel
Botnets: B3astmode, Enemybot, Fodcha, Fatebot, Mirai+
Raids and takedowns: Hydra Marketplace, RaidForum, Sandworm's Cyclops Blink, ZLoader botnet
And more...
Live at 4pm Paris, 10am New York, 7am Los Angeles, 11pm Tokyo. Join us as we go through the recent and notable security events.
References & Resources:
DoomSec
https://t.me/DoomSec
https://doomsec.org/
https://pastebin.com/ftVRU1nG
Currency.com DDoS attack
https://currency.com/currency-com-halts-operations-for-clients-from-Russia
https://currency.com/currency-targeted-in-failed-cyber-attack
https://twitter.com/franakviacorka/status/1515689761150849033
https://www.bankinfosecurity.com/crypto-firm-currencycom-mitigates-ddos-attack-a-18922
https://www.cityam.com/currency-com-faces-russian-cyberattack-hours-after-exit/
UA Postal Service DDoS Attack
https://www.reuters.com/world/europe/ukraines-postal-service-hit-by-cyberattack-after-sales-warship-stamp-go-online-2022-04-22/
Finland Defense & Foreign Affairs DDoS Attacks
https://yle.fi/news/3-12397024
https://securityscorecard.com/blog/zhadnost-strikes-again-this-time-in-finland
https://www.infosecurity-magazine.com/news/finland-government-sites-offline/
Killnet DDoS attacks on Czech Critical Services
https://www.expats.cz/czech-news/article/pro-russian-hackers-target-czech-websites-in-a-series-of-attacks
https://www.bankinfosecurity.com/pro-russian-killnet-group-in-ddos-attacks-on-czech-entities-a-18949
The Politics of Denial-of-Service Attacks
https://restofworld.org/2022/blackouts-ddos/
Russia Hacked at an Unprecedented Scale
https://www.wired.co.uk/article/russia-hacked-attacks
DDoS Attacks in Israel
https://www.engadget.com/israel-faces-cyberattack-211021103.html
https://www.timesofisrael.com/airports-authority-website-targeted-by-pro-iranian-hackers-in-suspected-cyberattack/
DragonForce Malaysia
https://www.radware.com/security/threat-advisories-and-attack-reports/opsbedil-dragonforce-malaysia/
Hackers of Savior – Jerusalem Day
https://hackersofsavior.xyz/
https://www.timesofisrael.com/israel-cyber-directorate-issues-annual-warning-ahead-of-irans-jerusalem-day/
B3astmode
https://www.bleepingcomputer.com/news/security/beastmode-botnet-boosts-ddos-power-with-new-router-exploits/
https://www.youtube.com/watch?v=4GnGe1Ic504
https://www.fortinet.com/blog/threat-research/totolink-vulnerabilities-beastmode-mirai-campaign
Enemybot
https://www.fortinet.com/blog/threat-research/enemybot-a-look-into-keksecs-latest-ddos-botnet
https://twitter.com/_odisseus/status/1514589694297788423
https://threatpost.com/keksec-simps-botnet-gaming-ddos/166306/
https://en.irz.ru/
Fodcha
https://blog.netlab.360.com/fodcha-a-new-ddos-botnet/
https://twitter.com/Quad9DNS/status/1515295914847576070
Mirai & Spring4Shell
https://www.bleepingcomputer.com/news/security/mirai-malware-now-delivered-using-spring4shell-exploits/
https://www.trendmicro.com/en_us/research/22/d/cve-2022-22965-analyzing-the-exploitation-of-spring4shell-vulner.html
Mirai code branches
https://github.com/ware255/Mirai-Source-Code-plus
https://github.com/boz3r/Fatebot
Commander X Pleads Guilty
https://www.sfchronicle.com/bayarea/article/Anonymous-hacktivist-to-plead-guilty-to-16993702.php
Facebook Removes 400 Accounts
https://about.fb.com/news/2022/04/philippines-2022-general-election/
Is DDoS a Crime?
https://blog.radware.com/security/2022/04/is-ddos-a-crime/
Scraping Isn't Illegal
https://techcrunch.com/2022/04/18/web-scraping-legal-court/
Hydra Marketplace Shut Down
https://www.bka.de/DE/Presse/Listenseite_Pressemitteilungen/2022/Presse2022/220405_PM_IllegalerDarknetMarktplatz.html
RaidForum Arrest and Takedown
https://www.justice.gov/opa/pr/united-states-leads-seizure-one-world-s-largest-hacker-forums-and-arrests-administrator
Sandworm’s Cyclops Blink Takedown
https://www.justice.gov/opa/pr/justice-department-announces-court-authorized-disruption-botnet-controlled-russian-federation
https://www.techtarget.com/searchsecurity/news/252515708/How-the-FBI-took-down-the-Cyclops-Blink-botnet
https://blog.talosintelligence.com/2022/02/threat-advisory-cyclops-blink.html
Zloader Takedown
https://blogs.microsoft.com/on-the-issues/2022/04/13/zloader-botnet-disrupted-malware-ukraine/
FSB Detained Crimea Resident
https://www.securitylab.ru/news/531066.php
https://twitter.com/iiyonite/status/1512757397193904128
CTA Webinar – A Hell of a Ride
https://youtu.be/7NVuuf503BI
Comments
Post a Comment