Nation-StateWeLiveSecurity·9 months ago

PlushDaemon compromises network devices for adversary-in-the-middle attacks

ESET researchers have identified a network implant deployed by the China-aligned PlushDaemon APT group that enables adversary-in-the-middle attacks against compromised network devices. The implant allows threat actors to intercept and manipulate network traffic, positioning the attacker between legitimate communications to potentially steal data or inject malicious content.

RansomwareCybereason Blog·9 months ago

License to Encrypt: “The Gentlemen” Make Their Move

The Gentlemen ransomware group emerged around July 2025 and employs a dual-extortion strategy that combines file encryption with data exfiltration, threatening to publish stolen information on dark web leak sites to pressure victims into paying ransom. Cybereason's analysis indicates the group demonstrates advanced methodologies and rapid adaptability to new attack vectors, positioning them as a persistent and evolving threat to organizations globally.

PhishingCybereason Blog·9 months ago

Tycoon 2FA Phishing Kit Analysis

Tycoon 2FA is a sophisticated Phishing-as-a-Service platform that emerged in August 2023 and uses an Adversary-in-the-Middle approach with reverse proxy servers to bypass two-factor and multi-factor authentication on Microsoft 365 and Gmail accounts. The kit captures credentials and session cookies by hosting deceptive phishing pages that mimic legitimate login interfaces, and has been reported in over 64,000 incidents according to Any.run's malware trends tracker.

IDA Free Reverse Engineering - Step-by-Step EXE Analysis

OALabs·17K views · 9 months ago

Step-by-step reverse engineering tutorial with IDA Free covering decompiling, types, enums, function definitions, and naming for EXEs. Sample can be found on unpac.me 7b5b060d9013725413f3f77719d0881035246b281e18005c0040e78a32e1c6cc Full tutorial series on the OALABS Patreon

VulnerabilityArs Technica·10 months ago

Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking

A leaker has disclosed that Cellebrite's phone hacking tools can extract data from the majority of Pixel devices, with the notable exception of phones running GrapheneOS. The revelation highlights a significant security gap for standard Android users on Pixel phones compared to those using the hardened GrapheneOS alternative.

MalwareCybereason Blog·10 months ago

From Scripts to Systems: A Comprehensive Look at Tangerine Turkey Operations

Cybereason Security Services has published a threat analysis examining Tangerine Turkey, a VBS worm threat actor that facilitates cryptomining operations. The report traces the campaign's progression as observed in Cybereason EDR and offers practical recommendations for detection and mitigation. This analysis provides security teams with actionable intelligence on the attack flow and defensive measures against this cryptomining threat.

The Easy Way to Analyze Linux Memory

13Cubed·4.8K views · 10 months ago

In this episode, we'll take a look at a quick and easy way to find the Intermediate Symbol File (ISF) for the Linux memory image you're analyzing. This method will save you time and help streamline your memory analysis workflow. *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** 📖 Chapters 00:00 - Intro 00:37 - Demo 🛠 Resources Abyss-W4tcher ISFs:

OtherCybereason Blog·10 months ago

Cybereason TTP Briefing Q3 2025: LOLBINs and CVE Exploits Dominate

Explore the latest trends, techniques, and procedures (TTPs) our incident response (IR) experts are actively facing with the TTP Briefing Q3 2025, a report built on frontline threat intelligence from our global incident response investigations, enriched by noteworthy detections from our SOC.

RansomwareCybereason Blog·10 months ago

Addressing CL0P Extortion Campaign Targeting Oracle EBS CVE-2025-61882

The CL0P ransomware group has conducted a widespread extortion campaign targeting on-premises Oracle E-Business Suite deployments, exploiting CVE-2025-61882—a critical, unauthenticated remote code execution vulnerability—to gain unauthorized access and exfiltrate data between July and September 2025. Beginning in late September through early October, CL0P launched coordinated email extortion threats against affected organizations, with evidence suggesting threat actor activity dating back to at least August 9, 2025, and the group providing proof of stolen data to some targets during ongoing investigations.

PhishingThe DFIR Report·11 months ago

From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion

Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo! Table of Contents: Case Summary Analysts Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Command and Control Exfiltration Impact Timeline Diamond Model Indicators Detections MITRE ATT&CK Case Summary The intrusion […] The post From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion appeared first on The DFIR Report.

IDA Free Reverse Engineering - Step-by-Step DLL Analysis

OALabs·19K views · 11 months ago

Step-by-step reverse engineering tutorial with IDA Free covering decompiling, types, enums, function definitions, and naming for DLLs. Sample can be found on unpac.me 93f9703cc7339014cd1bc82da0ab8909957112b93fba2430b5ee90a1d424a5ed Full tutorial series on the OALABS Patreon

Will AI Replace Digital Forensics Experts?

13Cubed·6.2K views · 11 months ago

Is AI going to replace digital forensic investigators? In this episode, we'll test a local instance of DeepSeek-R1 in Windows forensics to see how it compares to a human investigator. Let’s find out if AI can handle the job! *** If you enjoy this video, please consider supporting 13Cubed on Patreon at patreon.com/13cubed. *** 📖 Chapters 00:00 - Intro 01:23 - The Questions Begin 10:43 - Closing Thoughts 🛠 Resources #Forensics #DigitalForensics #DFIR #ComputerForensics #WindowsForensics #AI #DeepSeek

RansomwareThe DFIR Report·11 months ago

Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs

Key Takeaways Private Threat Briefs: 20+ private DFIR reports annually. Contact us today for pricing or a demo! Table of Contents: Case Summary Analysts Initial Access Execution Persistence Privilege Escalation Defense Evasion Credential Access Discovery Lateral Movement Collection Command and Control Exfiltration Impact Timeline Diamond Model Indicators Detections MITRE ATT&CK Case Summary The intrusion began in […] The post Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs appeared first on The DFIR Report.

Load more