Rewterz Threat Alert – Lazarus APT Group Targeting China – IOCs
May 27, 2021Rewterz Threat Advisory – CVE-2021-22543 – Linux Kernel Privilege Escalation
May 27, 2021Rewterz Threat Alert – Lazarus APT Group Targeting China – IOCs
May 27, 2021Rewterz Threat Advisory – CVE-2021-22543 – Linux Kernel Privilege Escalation
May 27, 2021Severity
Medium
Analysis Summary
Threat actors are actively dropping phishing emails impersonating Microsoft Outlook app and robbing off credentials of the users with their tactics. This has been the latest ongoing phishing campaign actively targeting multiple organizations by impersonating Microsoft Outlook and Sharepoint. When the targeted victims click on links attached in the emails, they are redirected to fake login pages from where their credentials are stolen and sent to the threat actors. Like previous campaigns, this one is also aimed at credential theft.
Impact
- Credential Theft
- Information Disclosure
Affected Vendors
Microsoft
Affected Products
- Microsoft Outlook
- Microsoft SharePoint
Indicators of Compromise
URL
https[:]//jazonbucket564[.]s3[.]eu-de[.]cloud-object-storage[.]appdomain[.]cloud/avoue/index[.]php
https[:]//drive[.]google[.]com/file/d/1YKP4Uq2jjXZbuKaZqmU4YwyG5O499DP5/view
Remediation
- Block the threat indicators at their respective controls.
- Do not download files attached in untrusted emails.
- Do not click on links given in untrusted emails.
- Verify familiar domains and URLs and look for typos, before clicking on them.