VMConnect Supply Chain Threat

 In recent months, the cybersecurity landscape has been marred by the persistence of the VMConnect Supply Chain Attack. This blog post aims to provide a professional yet easily understandable overview of this ongoing threat.

Understanding the VMConnect Supply Chain Attack


The VMConnect Supply Chain Attack is a sophisticated cyber threat that targets the software supply chain. This attack vector is particularly concerning because it infiltrates trusted software repositories and distribution channels, making it challenging to detect.
Diving into details
The researchers have discovered that the people behind this operation go to considerable measures to make their actions appear genuine. They set up GitHub repositories with descriptions that appear real and even employ legitimate source code.

  • Tablediter (736 downloads), Request-Plus (43 downloads), and Requestspro (341 downloads) are some of the most recent packages found.
  • Among these recently found packages, the first one appears to pose as a tool for modifying tables, while the other two mimic the widely utilized



Attributions

  • While ReversingLabs was unable to positively identify the threat actor behind this campaign, Crowdstrike's analysts were confident in their identification of the malware's source as Labyrinth Chollima, a branch of the Lazarus Group, a state-sponsored threat organisation based in North Korea
  • JPCERT/CC connected the attack to DangerousPassword, another Lazarus Group affiliate, in addition to the aforementioned information.
  • These attributions, along with the striking code similarities between the packages discovered in the VMConnect campaign and those detailed in JPCERT/CC's investigation, have led researchers to the conclusion that the same threat actor is behind both assaults.

Conclusion

The VMConnect Supply Chain Attack is a persistent threat that demands vigilance and proactive security measures from organizations. By staying informed and taking steps to secure your software supply chain, you can better protect your systems and data from this evolving danger

EVLF DEV: Discovering CypherRAT and CraxsRAT Creator


CypherRAT and CraxsRAT malware, which were bought by more than 100 threat actors, have brought in $75,000 for EVLF DEV, a Malware-as-a-Service provider with a base in Syria.

 Details:

  • Three years,  EVLF has been selling the hazardous Android RAT CraxsRAT via an online store.
  •  By constructing obfuscated packages, the builder enables malicious actors to alter content for assaults. 
  •  CraxsRAT has the ability to locate devices, steal contacts, obtain access to storage, and extract message and call log information. 
  •  At least 100 lifetime licenses for the RAT have been sold. 
  •  The builder is in charge of creating packages that are highly obfuscated, allowing hostile actors to adapt their attacks.

The researchers discovered that the threat actor has been withdrawing money made from selling CypherRAT and CraxsRAT for at least the last three years using a well-known bitcoin wallet.


MaaS Offering in Vogue:

  • DogeRAT, an Android malware that targets a number of businesses, including gaming and banking, was discovered in June.
  •  The alleged Indian originators of DogeRAT advertised it as a MaaS service.
  •  In addition to serving as a remote access tool, this open-source malware may copy data from the clipboard and act as a keylogger.
  •  FusionCore, a new MaaS provider that also developed the AnthraXXXLocker ransomware affiliate business, emerged in April. The threat actor sells a variety of specialized malware, such as ransomware, information thieves, and bitcoin mining software.

Conclusion:

The growth of MaaS providers like EVLF DEV highlights the worrying trend of cyberthreats turning into successful businesses. People should use caution when installing software, avoid clicking on strange links or attachments, and only install apps from trusted marketplaces in order to combat such bad actor efforts.


Over 2 Million Downloads of China-Linked Spyware Found in Google Play Store Apps

 What really happened? 

Google Play Store apps contain malware linked to China, raising concerns about mobile device security and privacy. Over 2 million downloads have exposed users to potential spying and data breaches, raising concerns about potential dangers. 

                           What information did these apps gather?

According to Pradeo's blog post, the app profiles in the Google Play Store make deceptive promises about not collecting any device data. According to research, the apps harvested very sensitive personal information from its users and sent it to over a hundred malicious locations, all of which were located in China.

Data gathered by the spyware programmer included the following:
  • Version of the OS
  • Device type/brand
  • User location in real time
  • Name of the network provider
  • network code for the SIM provider
  • country code for cellular phones
  • material including images, video, and audio
  • Contact lists on the device (from all associated accounts, emails, and social networks)
 How Do the Apps Trick Users? 
Hackers use various strategies to make apps seem real, such as advertising vast user bases without customer reviews, operations, and minimizing user engagement. These apps can start automatically, carry out harmful activities, and are hidden on the home screen to avoid uninstallation.


How can you stay secure? 

Even though Google has removed these apps, if you have downloaded and installed them from a third-party store, delete them right away. Despite having a vast user base, you should never download apps without any reviews. Don't forget to read their reviews, if any, to look for signs of fraud.
 
By screening apps and assessing if they respect to their security requirements, organizations should automate mobile detection and response.


 

Cyber Security Training in Mumbai

  Cybersecurity Training in Mumbai   There has never been a more pressing need for cybersecurity in the modern digital world. Cyber dang...