Rewterz Threat Advisory –IBM QRadar User Behavior Analytics Vulnerability
August 3, 2021Rewterz Threat Alert – Cobalt Strike Malware – IOCs
August 4, 2021Rewterz Threat Advisory –IBM QRadar User Behavior Analytics Vulnerability
August 3, 2021Rewterz Threat Alert – Cobalt Strike Malware – IOCs
August 4, 2021Severity
High
Analysis Summary
APT-C-27 is also known as the GpldMouse threat group. The APT group is reportedly targeting the Middle East region. Android devices are targeted – The researchers also detected multiple samples designed to target Android devices.Those recent Android backdoors are disguised as commonly used applications such as the Android system. Once these false ‘VPN-Secure .apk’ files are downloaded on the device, attackers use the C2 server to capture details such as GPS Positioning and perform tasks like recording and photographing from the device.
Impact
- File Recording
- Information Theft
- Exposure of Data
Indicators of Compromise
Filename
- VPN-Secure [.]apk
MD5
- f2b54eda7c3e19c4e429d7adb1b7560c
SHA-256
- d9aea4cc97508bd71a7fbd88ac72a4097811a7a9dda096bb7cc1d75f477fd6c0
SHA-1
- 9725af7718f750ae4d6eebd80b126f9bdfd1d5ea
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.
- Always download legitimate updates from the play store.