Rewterz Threat Alert – Quasar RAT – Active IOCs
July 25, 2022Rewterz Threat Advisory – Multiple Oracle MySQL Server Vulnerabilities
July 26, 2022Rewterz Threat Alert – Quasar RAT – Active IOCs
July 25, 2022Rewterz Threat Advisory – Multiple Oracle MySQL Server Vulnerabilities
July 26, 2022Severity
High
Analysis Summary
APT29 aka Nobelium and Cozy Bear are the group which were behind the infamous Solar Wind attacks in 2020. APT29 threat group has previously targeted commercial entities and government organizations in Germany, Uzbekistan, South Korea and the US, including the US State Department and the White House in 2014. They have also targeted several vaccine manufacturers in attempt to sabotage the process to combat the Coronavirus pandemic. This time they’ve come up with a current campaign to target government organizations in attempt to steal sensitive information.
Impact
- Information Theft and Espionage
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- eb8e5a4aadf435fc9eb5a14c7321ce92
- 37091dc082f0427a863f2420d633a0aa
SHA-256
- 0b43a026be9ac35367452063910c374cd377778f1612f7751a3654793433e656
- b9758a1c10cb96b9191d9467cb59f9a4157406a4a73dc0b90a6152ffb43a6fdb
SHA-1
- 08bb446618fb67cb78d835d07a2ae2f7b13e99a3
- 824b03737adc068db18410888fd8c07ff89f6588
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment