Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Severity
Medium
Analysis Summary
APT28 aka Sofacy or Fancy Bear has recently resurfaced with its Lojax rootkit, as reported by a Twitter handle called blackorbird as well as many others. A variant of the malware is being used in ongoing attacks, hitting targets in the Central Asian nations, as well as diplomatic and foreign affairs organizations.
A few sources including the Kaspersky Lab believe that the malware resembles XTunnel, a tool APT28 used to breach the DNC in 2016. Indicators of Compromise have been retrieved for this APT group and are reported below.
APT28 has targeted governments in Europe and Latin America and is believed to have ties with the Russian government.
Impact
Cyber Intrusion
Indicators of Compromise
URLs
Malware Hash (MD5/SHA1/SH256)
Remediation
Block the threat indicators at their respective controls.