Posts

Showing posts with the label Zetta Hosting

Tracking A Renewable Energy Intelligence Gathering Campaign

Image
  For my first research blog of 2022, I analysed a suspected intelligence gathering campaign targeting renewable energy and industrial technology organisations, with a particular focus on Bulgaria. This long-running espionage campaign leveraged multiple credential harvesting pages to target the email accounts of employees at a number of organisations between 2019 and is ongoing in 2022. The attackers use the same 'Mail Box' phishing kit and host many of the pages on them infrastructure, supported by also compromising some legitimate websites. This research was conducted using OSINT techniques such as query public sandbox submissions and passive DNS scan results. From this up to 40 individuals at target organisations from a variety of sectors  were identified , but there was a focus on a few such as renewable energy, environmental protection organisations, and industrial technology. This research using OSINT alone is unable to acquire the full story, but  hopefully can pai...

OZH RAT - New .NET malware

Image
Introducing a new remote access tool (RAT) I recently discovered: Filenames include ‘OzhSecSys.exe’ or ‘system.exe’. Interestingly, the IP address used to host the OZH RAT domain (185[.]176.43[.]94) is used in prior #Konni attack campaigns, but is not thought to be connected to the North Korean APT. #OZHRAT IOCs: https://t.co/B5KNjQBWUX — Will | BushidoToken 👁‍🗨 (@BushidoToken) May 28, 2020 Malpedia link:  https://malpedia.caad.fkie.fraunhofer.de/details/win.ozh_rat IOCs in my OTX feed for this threat have been attached  here . More info: Florian Roth's THOR APT Scanner picked it up early on: Windows Forms & System Configuration checks: OZH RAT is a new malware as far as I can tell. I would be very much interested if another security researcher is able to investigate or share samples of OZH RAT for further malware analysis. Updated - 2nd June 2020: I recently discovered the OZH RAT #crimware website, which is written in Turkish. The #malware has an exceptionally ...