Rewterz Threat Alert – Hive Ransomware – Active IOCs
August 12, 2022Rewterz Threat Advisory – CVE-2022-28755 – Zoom Client for Meetings and VDI Windows Meeting Clients Vulnerability
August 12, 2022Rewterz Threat Alert – Hive Ransomware – Active IOCs
August 12, 2022Rewterz Threat Advisory – CVE-2022-28755 – Zoom Client for Meetings and VDI Windows Meeting Clients Vulnerability
August 12, 2022Severity
High
Analysis Summary
An emergent and effective data-harvesting tool dubbed Oski is proliferating in North America and China, stealing online account credentials, credit card numbers, crypto wallet accounts, and more. The malware is still in its developing phase but packs a punch with its capabilities. Oski C2’s dashboard revealed that Oski’s theft tactics involve extracting credentials using man-in-the-browser (MitB) attacks by hooking the browser processes using DLL injection, It also extracts credentials from the registry, passwords from the browser SQLite database, and stored session cookies of all stripes, including crypto-wallet cookies from Bitcoin Core, Ethereum, Monero, Litecoin, and others.
Impact
- Credential Theft
- Unauthorized Access
Indicators of Compromise
MD5
- 5be68e2fdd151ab51beb125c8796d3ac
SHA-256
- b1d3c9d99b280d0b6c75efbf271254f8081cf947b77d51ff8fa9fa67e61e6513
SHA-1
- 4eaf09cda6d4ce743b2aa5b274cb66b6a58f7f4f
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.