

Rewterz Threat Alert – Panda Continues to Target Cryptocurrency Miners
September 23, 2019
Rewterz Threat Alert – Tofsee Malware Resurfaces with Fresh IoCs
September 23, 2019
Rewterz Threat Alert – Panda Continues to Target Cryptocurrency Miners
September 23, 2019
Rewterz Threat Alert – Tofsee Malware Resurfaces with Fresh IoCs
September 23, 2019Severity
Medium
Analysis Summary
Turla, also known as Snake or Uroburos is one of the most sophisticated ongoing cyber-espionage campaigns. Targets of “Epic” belong to the following categories: government entities (Ministry of Interior, Ministry of Trade and Commerce, Ministry of Foreign/External affairs, intelligence agencies), embassies, military, research and education organizations and pharmaceutical companies.
The attackers use both direct spear-phishing e-mails and watering hole attacks to infect victims. Watering holes are websites commonly visited by potential victims. These websites are compromised in advance by the attackers and injected to serve malicious code. Depending on the visitor’s IP address (for instance, a government organization’s IP), the attackers serve Java or browser exploits, signed fake Adobe Flash Player software or a fake version of Microsoft Security Essentials.
Impact
Exposure of sensitive information
Indicators of Compromise
Malware Hash (MD5/SHA1/SH256)
- 4dc26b3b144826569bc2601fb20dcef124abf9fe63944c029a52eda48
- 6874b387a1c07d85bbedbd196cae3f06539cbcc724395723034196a3ad016724
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on the link/attachments sent by unknown senders.