Microcin is here
#1
Bug 
Quote:
[Image: sl_microcin_02.png]

With asynchronous sockets, steganography, GitLab ban and a sock In February 2020, we observed a Trojan injected into the system process memory on a particular host. The target turned out to be a diplomatic entity. What initially attracted our attention was the enterprise-grade API-like (application programming interface) programming style. Such an approach is not that common in the malware world and is mostly used by top-notch actors.

Due to control server reuse (Choopa VPS service), target profiling techniques and code similarities, we attribute this campaign with high confidence to the SixLittleMonkeys (aka Microcin) threat actor. Having said that, we should note that they haven’t previously applied the aforementioned coding style and software architecture. During our analysis we didn’t observe any similar open source tools, and we consider this to be the actor’s own custom code.

SixLittleMonkeys’ sphere of interest remains the same – espionage against diplomatic entities. The actor is still also using steganography to deliver configuration data and additional modules, this time from the legitimate public image hosting service cloudinary.com. The images include one related to the notorious GitLab hiring ban on Russian and Chinese citizens. In programming terms, the API-like architecture and asynchronous work with sockets is a step forward for the actor.
...
Continue Reading
Reply


Messages In This Thread
Microcin is here - by harlan4096 - 23 June 20, 06:51

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
K-Lite Codec Pack 19.5.0 / 19.5.3 Update
Changes in 19.5.3 ...harlan4096 — 08:46
Mozilla Thunderbird Version 148.0 & 140....
Thunderbird Versio...harlan4096 — 08:39
Microsoft Releases KB5077241 February Op...
Microsoft has just...harlan4096 — 08:37
Brave 1.87.191 (Chromium 145.0.7632.120)
Release v1.87.191 ...harlan4096 — 08:34
Waterfox 6.6.9
Waterfox 6.6.9 ...harlan4096 — 08:33

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
No upcoming birthdays.

[-]
Online Staff
There are no staff members currently online.

>