Rewterz Threat Alert – Cyberium Is Fanning Out Mirai Variants Through Its Malware Hosting Domain – Active IOCs
June 16, 2021Rewterz Threat Advisory – CVE-2021-30641 – Apache HTTP Server Remote Code Execution
June 16, 2021Rewterz Threat Alert – Cyberium Is Fanning Out Mirai Variants Through Its Malware Hosting Domain – Active IOCs
June 16, 2021Rewterz Threat Advisory – CVE-2021-30641 – Apache HTTP Server Remote Code Execution
June 16, 2021Severity
Medium
Analysis Summary
The REvil ransomware group made headlines by targeting the US’s nuclear weapons contractors. Sol Oriens was targeted by the threat actors and their employees’ data was leaked online. Along with the employees’ information, business data was also stolen and leaked.
The company added that it is not aware that threat actors have stolen classified or critical security-related information belonging to its clients. However, the social security numbers of employees along with their payroll were leaked online.
“Sol Oriens, LLC did not take all necessary action to protect personal data of their employees and software developments for partner companies. We hereby keep a right to forward all of the relevant documentation and data to military agencies of our choice, including all personal data of employees.” reads the statement published by REvil on its leak site.
Impact
- Credential Theft
- Information Disclosure
- Data Breach
Indicators of Compromise
URL
- http[:]//aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd[.]onion/4DD2F2803EC112D7
- https[:]//decoder[.]re/4DD2F2803EC112D7
Remediation
- Block the threat indicators at their respective controls.
- Search for IOCs in your environment.