Tag: stealthy attacks

Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks
News

Hackers abuse Microsoft ClickOnce and AWS services for stealthy attacks

Researchers refer to this sophisticated malicious campaign as OneClik, which has been using proprietary Golang backdoors and Microsoft's ClickOnce software deployment tool to infect companies in the oil, gas, and energy industries. The hackers conceal the command and control (C2) infrastructure by using authentic AWS cloud services (AWS, Cloudfront, API Gateway, and Lambda). Microsoft's ClickOnce deployment technique minimises user intervention by enabling developers to construct Windows-based programmes that update themselves. Three versions of the campaign (v1a, BPI-MDM, and v1d) were examined by security experts at cybersecurity firm Trellix. They all used a.NET-based loader disguised as OneClikNet to install "a sophisticated Golanguage backdoor" known as RunnerBeacon read mor...
Russian hackers hijack Ubiquiti routers to launch stealthy attacks
News

Russian hackers hijack Ubiquiti routers to launch stealthy attacks

In a joint alert released with the NSA, the U.S. Cyber Command, and international partners, the FBI claims that Russian military hackers are avoiding detection by utilizing compromised Ubiquiti EdgeRouters. These widely used and compromised routers are being used by Military Unit 26165 cyberspies, who are affiliated with Russia's Main Intelligence Directorate of the General Staff (GRU) and are being tracked as APT28 and Fancy Bear. They are utilizing these routers to create massive botnets that aid in credential theft, NTLMv2 digest collection, and the proxing of malicious traffic. In addition, they host phishing landing sites and customized tools for covert cyber operations aimed at governments, military forces, and other international organizations. The joint advise cautions th...