Rewterz Threat Alert – IcedID banking Trojan – Active IOCs
August 16, 2022Rewterz Threat Alert – AZORult Malware – Active IOCs
August 16, 2022Rewterz Threat Alert – IcedID banking Trojan – Active IOCs
August 16, 2022Rewterz Threat Alert – AZORult Malware – Active IOCs
August 16, 2022Severity
High
Analysis Summary
APT29 aka Nobelium and Cozy Bear are the group which were behind the infamous Solar Wind attacks in 2020. APT29 threat group has previously targeted commercial entities and government organizations in Germany, Uzbekistan, South Korea and the US, including the US State Department and the White House in 2014. They have also targeted several vaccine manufacturers in attempt to sabotage the process to combat the Coronavirus pandemic. This time they’ve come up with a current campaign to target government organizations in attempt to steal sensitive information.
Impact
- Information Theft and Espionage
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 21b4dce85eecdb039ec69d5b8fdc0a30
- ae38c423ef7c47ee4468e3c65e9acca5
SHA-256
- 644980943a29325d76ede2fcdec12638c7e07154cc08b2badf822e7261819220
- d059f27c42b461704fc10e62820a607d1f893606e1596acc8e37670e4c952ed8
SHA-1
- ef903fd1a90b3b102bdabacdb927811a568402e6
- 7a3fbe5b42e946bf393f92e19f0e86ce6fe0d80d
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment