Is Now on VT!(@Now_on_VT) 's Twitter Profileg
Is Now on VT!

@Now_on_VT

Get notified when interesting APT/FIN indicators of compromise appear on https://t.co/Sb3PFMresB. A threat intelligence project by @craiu

ID:1705129706004111360

linkhttp://www.noh.ro calendar_today22-09-2023 08:00:40

69 Tweet

1,4K Takipçi

312 Takip Edilen

Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

Sample is now on VT!

🚩Hash: 5a23a868620ba33a4948bc6b9260f530
🎯Actor name: CloudChat Stealer
🔹Comment: We came across a file on VT named Clip that had some red flags that warranted further investigation.
🌐URL: blog.kandji.io/cloudchat-info…
🔎OnVT: virustotal.com/gui/file/db3ec…

account_circle
Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

Sample is now on VT!

🚩Hash: c6aafc99a0d01670ab765dcc7f1f4659
🎯Actor name: LightSpy
🔹Comment: We link the DragonEgg malware to the sophisticated iOS implant LightSpy and its Android component
🌐URL: threatfabric.com/blogs/lightspy…
🔎OnVT: virustotal.com/gui/file/bd6ec…

account_circle
Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

Sample is now on VT!

🚩Hash: f7eb86f60458ea8888b8df86dd4baf93
🎯Actor name: Blackwood
🔹Comment: ESET analysis of a sophisticated implant named used by the China-aligned threat actor
🌐URL: welivesecurity.com/en/eset-resear…
🔎OnVT: virustotal.com/gui/file/796d0…

account_circle
Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

Sample is now on VT!

🚩Hash: 7536b375e05135eb1e9123c28e2326cf
🎯Actor name: Ke3chang
🔹Comment: We look at a previously undocumented malware family and the other Ke3chang malware families detected from 2015 to 2019
🌐URL: web-assets.esetstatic.com/wls/2019/07/ES…
🔎OnVT: virustotal.com/gui/file/10bd6…

account_circle
Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

Sample is now on VT!

🚩Hash: 4e46218da434ed4da24dc086f6262c27
🎯Actor name: Earth Krahang
🔹Comment: Since early 2022, we have been monitoring an APT campaign that targets several government entities worldwide
🌐URL: trendmicro.com/en_us/research…
🔎OnVT: virustotal.com/gui/file/6d03c…

account_circle
Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

Sample is now on VT!

🚩Hash: a739bd4c2b9f3679f43579711448786f
🎯Actor name: Multiple, UNC5221
🔹Comment: Mandiant has identified multiple new variants of WARPWIRE across our response engagements and in the wild
🌐URL: mandiant.com/resources/blog…
🔎OnVT: virustotal.com/gui/file/a739b…

account_circle
Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

Thanks for sharing the IOCs! We've added the two missing hashes to monitoring and we'll let y'all know when they show up on VT!

account_circle
Kim Zetter(@KimZetter) 's Twitter Profile Photo

Great excerpt from Byron Tau's new book - how the Pentagon learned to use targeted ad data to locate and track Putin and other targets wired.com/story/how-pent…

Great excerpt from @ByronTau's new book - how the Pentagon learned to use targeted ad data to locate and track Putin and other targets wired.com/story/how-pent…
account_circle
Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

Sample is now on VT!

🚩Hash: b4a31fa229cd1074c5cbd1c84a01c6ae
🎯Actor name:
🔹Comment: is a passive backdoor used by after exploiting CVE-2023-46805 and CVE-2024-21887 on Ivanti devices
🌐URL: mandiant.com/resources/blog…
🔎OnVT: virustotal.com/gui/file/8cad7…

account_circle
Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

Sample is now on VT!

🚩Hash: 991461b86aebecfd096dc11ff2a04b4b
🎯Actor name: COATHANGER
🔹Comment: The NL MOD was impacted in 2023 by an intrusion into one of its networks with previously unknown malware
🌐URL: github.com/JSCU-NL/COATHA…
🔎OnVT: virustotal.com/gui/file/99146…

account_circle
Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

Sample is now on VT!

🚩Hash: 88e38e212591ffaf3c3400b22b8988d6
🎯Threat name: Ov3r_Stealer
🔹Comment: Trustwave SpiderLabs discovered a new malware named Ov3r_Stealer
🌐URL: trustwave.com/hubfs/Web/Libr…
🔎OnVT: virustotal.com/gui/file/88e38…

account_circle
Is Now on VT!(@Now_on_VT) 's Twitter Profile Photo

It's always open season on Volt Typhoon around here. 4 hashes from the CISA report added to monitoring, we'll let you know when they show up on VT!

account_circle