100. The Adversary Abuses Canarytokens to Collect System Information
Hello everyone! Sapphire Werewolf has updated Amethyst Stealer and now abuses Canarytokens to collect information about compromised systems.
Despite the fact that Canarytokens are used to spot malicious activity, adversaries may use it to be notified about a new victim!
The adversary leveraged the following link to collect information about compromised system, including its IP-address and if it's a virtual machine or not:
hxxp://canarytokens[.]com/traffic/tags/static/xjemqlqirwqru9pkrh3j4ztmf/payments.js
Sure, we can hunt for suspicious domain resolutions:
event_type: "dnsreq"
AND
dns_rname: "canarytokens.com"
You can find more information on Sapphire Werewolf's tactics, techniques and procedures in this report.
See you tomorrow!
Comments
Post a Comment