100. The Adversary Abuses Canarytokens to Collect System Information

Hello everyone! Sapphire Werewolf has updated Amethyst Stealer and now abuses Canarytokens to collect information about compromised systems.

Despite the fact that Canarytokens are used to spot malicious activity, adversaries may use it to be notified about a new victim!

The adversary leveraged the following link to collect information about compromised system, including its IP-address and if it's a virtual machine or not:

hxxp://canarytokens[.]com/traffic/tags/static/xjemqlqirwqru9pkrh3j4ztmf/payments.js

Sure, we can hunt for suspicious domain resolutions:

event_type: "dnsreq"

AND

dns_rname: "canarytokens.com"

You can find more information on Sapphire Werewolf's tactics, techniques and procedures in this report.

See you tomorrow!

Comments

Popular posts from this blog

033. Free Google Threat Intelligence Course

082. Huniting for Malicious Browser Extensions

001. The Zeltser Challenge