Now Boarding: Clickfix
ibiza-airport.org is hosting clickfix. As it turns out the EtherHiding C2 reveals are campaign affecting over 2100 sites globally.
author
ibiza-airport.org is hosting clickfix. As it turns out the EtherHiding C2 reveals are campaign affecting over 2100 sites globally.
How a dependency confusion campaign hid its C2 behind a one-byte XOR, why hashes will not detect it, and what to hunt for instead. 1,046 samples analysed.
Breaking down North Korea's continuation of the BeaverTail campaign
I do a lot of open-source dependency threat hunting, and recently I've been seeing something that is both incredibly annoying and
300 packages on NPMJS, credential theft, token exfil and a reverse-SSH RAT calling moika.tech. Full malware and analysis of this ongoing campaign.
Sometimes, when I've had enough of package manager supply-chain attacks, I like to browse twitter.com. And sometimes, I see something
A comprehensive analysis of npm package intercom-client@7.0.4 malware, as part of the Shai Hulud 3 campaign
A look inside how your mates' football apps actually work.
Trivy supply chain attack, GitHub Actions, CI/CD security, software supply chain, teamPCP, CanisterWorm, npm worm, security scanners. What was detectable, what wasn't, and why the first stage defeated every automated tool in the game.
Amongst the IOCs and remediation advice from the Trivy supply chain attack is something cool. A blockchain canister being used as C2 infrastructure. Here's what it is, how it works, and why it matters.
From a fake steam friend, an invitation to a counter-strike tournament, to a phishing page. Taking a dive into a sophisticated phishing attack, involving social engineering and a UK based bullet-proof hosting provider
Another day, another malware package on NPMJS. Investigating NPM malware apache-httpclient10 with HNTR.
Detecting & Analysing the Nodelogex NPM malware backdoor with Ossprey Security's detection engine. You're telling me this logger has a logger in it ?
Detecting interceptor jets using OSINT and machine-learning.
Take this block of code. A self contained JS script that exfiltrates system and project info. I can read it, you can read it,
Below are links and downloads for data set related to the talk Threat Hunting the Node Package Manager. Scraper: https://github.com/veryserious-systems/
In some of my previous posts I've written about threat hunting the NodeJS Package manager, these posts go into methodology and some
This is part 1 of a multi part series, where we will be gathering, enriching, processing and analysing hopefully millions of open source packages
Today, we'll be looking at public certificate transparency logs, to determine if we can identify malicious websites at the point of certificate