Newly-Discovered Chinese-linked APT Has Been Quietly Spying On Organizations For Years

Cado Labs’ honeypot infrastructure was recently compromised by a complex and multi-stage cryptojacking attack.
Although the attack utilised many TeamTNT TTPs, It is assessed with high confidence that the group WatchDog is continuing to repurpose TeamTNT payloads – as they’ve done in the past.
The attack targets exposed Docker Engine API endpoints and Redis servers, and can propagate in a worm-like fashion.
Several sophisticated techniques were employed, including timestomping, process hiding and exploitation of a misconfigured Redis database that leaves it vulnerable to remote code execution.

Sign Up For Threat Alerts

Loading...
Threats Icon

Jun 30, 2022

YTStealer Malware: YouTube Cookies! Om Nom Nom...

The Dark Web Market for YouTube Account Access In 2006, the term "data is the...

Threats Icon

Jun 27, 2022

Bronze starlight Ransomware Operations Use HUI Loader

The BRONZE RIVERSIDE threat group is likely responsible for stealing intellectual property from Japanese organizations....

Threats Icon

Jun 27, 2022

The Black Basta ransomware is a new...

Although active for just two months, the group already rose to prominence claiming attribution of...

Threats Icon

Jun 27, 2022

Gallium APT Group

Researchers from Palo Alto Networks defined the PingPull RAT as a "difficult-to-detect" backdoor that leverages...

Threats Icon

Jun 26, 2022

US Cert Alert – Malicious Cyber Actors...

The Cybersecurity and Infrastructure Security Agency (CISA) and United States Coast Guard Cyber Command (CGCYBER)...

Threats Icon

Jun 23, 2022

Matanbuchus: Malware-as-a-Service with Demonic Intentions

A new malware-as-a-service (MaaS) called Matanbuchus Loader was discovered in underground markets by Unit42. Malware...

Threats Icon

Jun 22, 2022

Websites Hosting Fake Cracks Spread Updated CopperStealer...

Analysts noticed a new version of CopperStealer and analyzed these samples to be related to...

Threats Icon

Jun 21, 2022

Symbiote Deep-Dive: Analysis of a New, Nearly-Impossible-to-Detect...

Symbiote is a shared object (SO) library that is loaded into all running processes using...

Threats Icon

Jun 19, 2022

HelloXD Ransomware Installing Backdoor on Targeted Systems

Systems are being targeted by a ransomware variant called HelloXD, with the infections also involving...

Threats Icon

Jun 16, 2022

Panchan’s Mining Rig: New Golang Peer-to-Peer Botnet

Akamai security researchers discovered Panchan, a new peer-to-peer botnet and SSH worm that emerged in...

Threats Icon

Jun 15, 2022

PureCrypter: A Fully-Functional Loader Distributing Remote Access...

PureCrypter is a fully-featured loader being widely sold The malware has been observed distributing a...

Threats Icon

Jun 14, 2022

CERT-IL Alert: an active phishing campaign in...

Recently new information was passed to the CERT-IL team indicating that there is an active...

Threats Icon

Jun 13, 2022

Follina suspected state aligned phishing campaign

Proofpoint blocked a suspected state aligned phishing campaign targeting European gov & local US gov...

Threats Icon

Jun 08, 2022

Active Exploitation of Confluence CVE-2022-26134

Atlassian published a security advisory for CVE-2022-26134, a critical unauthenticated remote code execution vulnerability in...

Threats Icon

Jun 07, 2022

Msiexec Impersonation – Exploit Leads to Data...

In this multi-day intrusion, The DFIR Report observed a threat actor gain initial access to...