Rewterz Threat Alert – Web Skimming (Magecart) attacks Targeted by North Korean Hackers
July 6, 2020Rewterz Threat Advisory – CVE-2020-9498 – Apache Guacamole code execution vulnerability
July 6, 2020Rewterz Threat Alert – Web Skimming (Magecart) attacks Targeted by North Korean Hackers
July 6, 2020Rewterz Threat Advisory – CVE-2020-9498 – Apache Guacamole code execution vulnerability
July 6, 2020Severity
High
Analysis Summary
Taurus a new stealer in town that this stealer is capable of stealing passwords, cookies, and autofill forms along with the history of Chromium- and Gecko-based browsers. Taurus can also steal some popular cryptocurrency wallets, commonly used FTP clients credentials, and email clients credentials. This stealer also collects information, such as installed software and system configuration, and sends that information back to the attacker.
The recent campaign is targeting users via phishing emails and luring users to click on malicious attachments.
Impact
- Credential theft
- Cookie theft
- Exposure of sensitive data
Indicators of Compromise
MD5
- 3e08e18ccc55b17eeaeedf3864abca78
- 221bbac7c895453e973e47f9bce5bfdc
SHA-256
- b3c75db5faa9b7afe98f081d5654b1e612065020542638e4b09c136b4023fc9c
- 2fd1db4e9314696c11da1ea15707de31c2e115ffb01c8d3b569a10441ddb6369
SHA1
- 8bb9a4ddb199c0d5aad1fd7ed2f14ae21dd7d4ca
- 349ddf1412999df1e51aef5248b15aa7f2af1e02
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on the links/attachments sent by unknown senders.