SB

Salim Bitam

Abonnieren
Artikel von Salim Bitam
REVSTEALER ramps up: analysis of up-and-coming infostealer
Security Labs

REVSTEALER ramps up: analysis of up-and-coming infostealer

Elastic Security Labs deep dives into REVSTEALER, an emerging infostealer targeting browsers, wallets, and gaming accounts.

Daniel Stepanic
ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit
Security Labs

ClickFix to Cash-Out: Anatomy of a Mexican Banking-Fraud Toolkit

Elastic Security Labs tracks REF6045, an active operator-assisted banking fraud operation targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges.

Jia Yu Chan
PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT
Security Labs

PHANTOMPULSE: anatomy of a hijackable blockchain-C2 RAT

Elastic Security Labs presents a detailed reverse-engineering analysis of PHANTOMPULSE, the long-lived RAT delivered to crypto-sector victims through the REF6598 intrusion set.

Salim Bitam
Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT
Security Labs

Phantom in the vault: Obsidian abused to deliver PhantomPulse RAT

Elastic Security Labs uncovers a novel social engineering campaign that abuses the popular note-taking application, Obsidian's legitimate community plugin ecosystem. The campaign, which we track as REF6598, targets individuals in the financial and cryptocurrency sectors through elaborate social engineering on LinkedIn and Telegram.

Salim Bitam
Elastic releases detections for the Axios supply chain compromise
Security Labs

Elastic releases detections for the Axios supply chain compromise

Hunting and detection rules for the Elastic-discovered Axios supply chain compromise.

Ruben Groenewoud
Inside the Axios supply chain compromise - one RAT to rule them all
Security Labs

Inside the Axios supply chain compromise - one RAT to rule them all

Elastic Security Labs analyzes a supply chain compromise of the axios npm package delivering a unified cross-platform RAT

Ruben Groenewoud
Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER
Security Labs

Elastic Security Labs uncovers BRUSHWORM and BRUSHLOGGER

Elastic Security Labs observed two custom malware components targeting a South Asian financial institution: a modular backdoor with USB-based spreading and a DLL-side-loaded keylogger.

Salim Bitam
From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect
Security Labs

From Invitation to Infection: How SILENTCONNECT Delivers ScreenConnect

SILENTCONNECT is a multi-stage loader that leverages VBScript, in-memory PowerShell execution, and PEB masquerading to silently deploy the ScreenConnect RMM tool.

Daniel Stepanic
MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites
Security Labs

MIMICRAT: ClickFix Campaign Delivers Custom RAT via Compromised Legitimate Websites

Elastic Security Labs uncovered a ClickFix campaign using compromised legitimate sites to deliver a five-stage chain ending in MIMICRAT, a custom native C RAT with malleable C2, token theft, and SOCKS5 tunneling.

Salim Bitam
RONINGLOADER: DragonBreath’s New Path to PPL Abuse
Security Labs

RONINGLOADER: DragonBreath’s New Path to PPL Abuse

Elastic Security Labs uncovers RONINGLOADER, a multi-stage loader deploying DragonBreath’s updated gh0st RAT variant. The campaign weaponizes signed drivers, thread-pool injection, and PPL abuse to disable Defender and evade Chinese EDR tools.

Jia Yu Chan
TOLLBOOTH: What's yours, IIS mine
Security Labs

TOLLBOOTH: What's yours, IIS mine

REF3927 abuses publicly disclosed ASP.NET machine keys to compromise IIS servers and deploy TOLLBOOTH SEO cloaking modules globally.

Daniel Stepanic
A Wretch Client: From ClickFix deception to information stealer deployment
Security Labs

A Wretch Client: From ClickFix deception to information stealer deployment

Elastic Security Labs detected a surge in ClickFix campaigns, using GHOSTPULSE to deploy Remote Access Trojans and data-stealing malware.

Salim Bitam
The Shelby Strategy
Security Labs

The Shelby Strategy

An analysis of REF8685's abuse of GitHub for C2 to evade defenses.

Salim Bitam
You've Got Malware: FINALDRAFT Hides in Your Drafts
Security Labs

You've Got Malware: FINALDRAFT Hides in Your Drafts

During a recent investigation (REF7707), Elastic Security Labs discovered new malware targeting a foreign ministry. The malware includes a custom loader and backdoor with many features including using Microsoft’s Graph API for C2 communications.

Cyril François
Under the SADBRIDGE with GOSAR: QUASAR Gets a Golang Rewrite
Security Labs

Under the SADBRIDGE with GOSAR: QUASAR Gets a Golang Rewrite

Elastic Security Labs share details about the SADBRIDGE loader and GOSAR backdoor, malware used in campaigns targeting Chinese-speaking victims.

Jia Yu Chan
Katz and Mouse Game: MaaS Infostealers Adapt to Patched Chrome Defenses
Security Labs

Katz and Mouse Game: MaaS Infostealers Adapt to Patched Chrome Defenses

Elastic Security Labs breaks down bypass implementations from the infostealer ecosystem’s reaction to Chrome 127's Application-Bound Encryption scheme.

Jia Yu Chan
Tricks and Treats: GHOSTPULSE’s new pixel-level deception
Security Labs

Tricks and Treats: GHOSTPULSE’s new pixel-level deception

The updated GHOSTPULSE malware has evolved to embed malicious data directly within pixel structures, making it harder to detect and requiring new analysis and detection techniques.

Salim Bitam
Globally distributed stealers
Security Labs

Globally distributed stealers

This article describes our analysis of the top malware stealer families, unveiling their operation methodologies, recent updates, and configurations. By understanding the modus operandi of each family, we better comprehend the magnitude of their impact and can fortify our defences accordingly.

Salim Bitam
Invisible miners: unveiling GHOSTENGINE’s crypto mining operations
Security Labs

Invisible miners: unveiling GHOSTENGINE’s crypto mining operations

Elastic Security Labs has identified REF4578, an intrusion set incorporating several malicious modules and leveraging vulnerable drivers to disable known security solutions (EDRs) for crypto mining.

Salim Bitam
PIKABOT, I choose you!
Security Labs

PIKABOT, I choose you!

Elastic Security Labs observed new PIKABOT campaigns, including an updated version. PIKABOT is a widely deployed loader malicious actors utilize to distribute additional payloads.

Daniel Stepanic
Ransomware in the honeypot: how we capture keys with sticky canary files
Security Labs

Ransomware in the honeypot: how we capture keys with sticky canary files

This article describes the process of capturing encryption keys from ransomware using Elastic Defend ransomware protection.

Salim Bitam
Introduction to Hex-Rays decompilation internals
Security Labs

Introduction to Hex-Rays decompilation internals

In this publication, we delve into Hex-Rays microcode and explore techniques for manipulating the generated CTree to deobfuscate and annotate decompiled code.

Salim Bitam
Unmasking a Financial Services Intrusion: REF0657
Security Labs

Unmasking a Financial Services Intrusion: REF0657

Elastic Security Labs details an intrusion leveraging open-source tooling and different post-exploitation techniques targeting the financial services industry in South Asia.

Daniel Stepanic
GHOSTPULSE haunts victims using defense evasion bag o' tricks
Security Labs

GHOSTPULSE haunts victims using defense evasion bag o' tricks

Elastic Security Labs reveals details of a new campaign leveraging defense evasion capabilities to infect victims with malicious MSIX executables.

Salim Bitam
Introducing the REF5961 intrusion set
Security Labs

Introducing the REF5961 intrusion set

The REF5961 intrusion set discloses three new malware families targeting ASEAN members. The threat actor leveraging this intrusion set continues to develop and mature their capabilities.

Daniel Stepanic
Revisiting BLISTER: New development of the BLISTER loader
Security Labs

Revisiting BLISTER: New development of the BLISTER loader

Elastic Security Labs dives deep into the recent evolution of the BLISTER loader malware family.

Salim Bitam
The DPRK strikes using a new variant of RUSTBUCKET
Security Labs

The DPRK strikes using a new variant of RUSTBUCKET

Watch out! We’ve recently discovered a variant of RUSTBUCKET. Read this article to understand the new capabilities we’ve observed, as well as how to identify it in your own network.

Salim Bitam
Initial research exposing JOKERSPY
Security Labs

Initial research exposing JOKERSPY

Explore JOKERSPY, a recently discovered campaign that targets financial institutions with Python backdoors. This article covers reconnaissance, attack patterns, and methods of identifying JOKERSPY in your network.

Colson Wilhoit
Elastic Security Labs steps through the r77 rootkit
Security Labs

Elastic Security Labs steps through the r77 rootkit

Elastic Security Labs explores a campaign leveraging the r77 rootkit and has been observed deploying the XMRIG crypto miner. The research highlights the different modules of the rootkit and how they’re used to deploy additional malicious payloads.

Salim Bitam
BLISTER Loader
Security Labs

BLISTER Loader

The BLISTER loader continues to be actively used to load a variety of malware.

Cyril François
Attack chain leads to XWORM and AGENTTESLA
Security Labs

Attack chain leads to XWORM and AGENTTESLA

Our team has recently observed a new malware campaign that employs a well-developed process with multiple stages. The campaign is designed to trick unsuspecting users into clicking on the documents, which appear to be legitimate.

Salim Bitam
Not sleeping anymore: SOMNIRECORD's wake-up call
Security Labs

Not sleeping anymore: SOMNIRECORD's wake-up call

Elastic Security Labs researchers identified a new malware family written in C++ that we refer to as SOMNIRECORD. This malware functions as a backdoor and communicates with command and control (C2) while masquerading as DNS.

Salim Bitam
CUBA Ransomware Malware Analysis
Security Labs

CUBA Ransomware Malware Analysis

Elastic Security has performed a deep technical analysis of the CUBA ransomware family. This includes malware capabilities as well as defensive countermeasures.

Salim Bitam
Update to the REF2924 intrusion set and related campaigns
Security Labs

Update to the REF2924 intrusion set and related campaigns

Elastic Security Labs is providing an update to the REF2924 research published in December of 2022. This update includes malware analysis of the implants, additional findings, and associations with other intrusions.

Salim Bitam
NETWIRE Dynamic Configuration Extraction
Security Labs

NETWIRE Dynamic Configuration Extraction

Elastic Security Labs discusses the NETWIRE trojan and is releasing a tool to dynamically extract configuration files.

Seth Goodwin
FLARE-ON 9 Solutions:
Security Labs

FLARE-ON 9 Solutions:

This year's FLARE-ON consisted of 11 different reverse engineering challenges with a range of interesting binaries. We really enjoyed working on these challenges and have published our solutions here to Elastic Security Labs.

Daniel Stepanic
SiestaGraph: New implant uncovered in ASEAN member foreign ministry
Security Labs

SiestaGraph: New implant uncovered in ASEAN member foreign ministry

Elastic Security Labs is tracking likely multiple on-net threat actors leveraging Exchange exploits, web shells, and the newly discovered SiestaGraph implant to achieve and maintain access, escalate privilege, and exfiltrate targeted data.

Samir Bousseaden
Exploring the REF2731 Intrusion Set
Security Labs

Exploring the REF2731 Intrusion Set

The Elastic Security Labs team has been tracking REF2731, an 5-stage intrusion set involving the PARALLAX loader and the NETWIRE RAT.

Salim Bitam
Doing time with the YIPPHB dropper
Security Labs

Doing time with the YIPPHB dropper

Elastic Security Labs outlines the steps collect and analyze the various stages of the REF4526 intrusion set. This intrusion set uses a creative approach of Unicode icons in Powershell scripts to install a loader, a dropper, and RAT implants.

Seth Goodwin
BUGHATCH Malware Analysis
Security Labs

BUGHATCH Malware Analysis

Elastic Security has performed a deep technical analysis of the BUGHATCH malware. This includes capabilities as well as defensive countermeasures.

Salim Bitam
CUBA Ransomware Campaign Analysis
Security Labs

CUBA Ransomware Campaign Analysis

Elastic Security observed a ransomware and extortion campaign leveraging a combination of offensive security tools, LOLBAS, and exploits to deliver the CUBA ransomware malware.

Daniel Stepanic
LUNA Ransomware Attack Pattern Analysis
Security Labs

LUNA Ransomware Attack Pattern Analysis

In this research publication, we'll explore the LUNA attack pattern — a cross-platform ransomware variant.

Salim Bitam