🚨🚨WARNING 🚨🚨 We have confirmed that #Emotet is dropping CS Beacons on E5 Bots and we have observed the following as of 10:00EST/15:00UTC. The following beacon was dropped: https://t.co/imJDQTGqxV Note the traffic to lartmana[.]com. This is an active CS Teams Server. 1/x
🚨🚨WARNING 🚨🚨 We have confirmed that #Emotet is dropping CS Beacons on E5 Bots and we have observed the following as of 10:00EST/15:00UTC. The following beacon was dropped: https://t.co/imJDQTGqxV Note the traffic to lartmana[.]com. This is an active CS Teams Server. 1/x
This is a big deal. Typically Emotet dropped TrickBot or QakBot, which in turn dropped CobaltStrike. You'd usually have about a month between first infection and ransomware. With Emotet dropping CS directly, there's likely to be a much much shorter delay. https://t.co/QHGU4oq9Zi
據Mandiant的報告,2021年10 月,Sabbath建立了揭秘網站54BB47h,推出租用勒索軟體即服務(Ransomware as a Service;RaaS)的平台並積極地尋找合作夥伴和會員。值得一提的是,Sabbath會向其會員提供預配置(Pre-configure)的Cobalt Strike有效荷載(payloads)。
新型勒索軟體Haron在2021年七月浮出水面,被資安研究員認為是已解散的勒索軟體Avaddon的品牌重塑(rebrand),並提供租用基礎設施(包含勒索軟體)的存取權限給其會員,是一個相對較新的勒索軟體即服務(Ransomware as a Service; RaaS)。Avaddon在解散時向BleepingComputer發布了其總共2,934個的解密密鑰,每個密鑰都屬於一個單獨的受害者。據執法部門稱,Avaddon要求的平均勒索費用約為 40,000 美元。