Rewterz Threat Advisory – CVE-2022-28890 – Apache Jena Vulnerability
May 6, 2022Rewterz Threat Alert – Docker Engine Honeypots Used in Attacks on Russia – Active IOCs – Russian-Ukrainian Cyber Warfare
May 6, 2022Rewterz Threat Advisory – CVE-2022-28890 – Apache Jena Vulnerability
May 6, 2022Rewterz Threat Alert – Docker Engine Honeypots Used in Attacks on Russia – Active IOCs – Russian-Ukrainian Cyber Warfare
May 6, 2022Severity
High
Analysis Summary
APT29 aka Nobelium and Cozy Bear are the group which were behind the infamous Solar Wind attacks in 2020. APT29 threat group has previously targeted commercial entities and government organizations in Germany, Uzbekistan, South Korea and the US, including the US State Department and the White House in 2014. They have also targeted several vaccine manufacturers in attempt to sabotage the process to combat the Coronavirus pandemic. This time they’ve come up with a current campaign to target government organizations in attempt to steal sensitive information.
Impact
- Information Theft and Espionage
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 578dfb9145f65c15d538584b9de1992f
- 933b3c5d3728ef6e08af4ae579c00d11
- b59199877e0d68a5e93fc8ea76374ed1
SHA-256
- 9766dbce6dd4982605e839993abc4931fc992061549e544c1bbd25ca33cae59b
- 47f3405ab0da5af125bcc6ebb6d17a1573b090c54d7a0a00630ec170ccc4b9d1
- 5b50e26a01b320f05d66727e9d220d5858cdac203ff62e4b9ced1cafc2683637
SHA-1
- 44202138d5d3861e893ab35276710f21c86123a0
- 42dbfbedd813e6dbea1398323f085a88fa014293
- 7803f160af428bcfb4b9ea2aba07886f232cde4e
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.