A Well known APT group called Energetic Bear/Crouching Yeti attacked various companies servers with a strong focus on energy and industrial sectors around the World.
This cybercrime group attacking various companies webservers around the world using countless malware since 2010 and stolen a huge amount of sensitive data.
Mainly during 2016 and in early 2017, Energetic Bear group Compromising several webservers from the various organization.
The main task of these attack is to search and identify the vulnerabilities to gain the access to the various host and stealing the Authentication Data.
Cyber Criminals using phishing Emails with the malicious document to compromise the various servers and some of the compromised servers used for an auxiliary purpose that act as s host tools and logs.
Compromised server based on Russia, Ukraine, UK, Germany, Turkey, USA and other countries with the various role of Attack.
An attacker using the Specific pattern to infect the water whole servers by injecting a link into a web page or JS file ( file://IP/filename.png.).
Particular injected link initially request for images but eventually, it makes user connected to the Command & control server over SMB to extract the following data from infected servers.
Cyber Criminals using Various hacking Tools such as such as nmap, dirsearch, sqlmap, etc. to scan the vulnerable servers and compromised servers are used to conduct attacks on other resources.
Scanned resources are highly sensitive information such as medical data, cryptocurrency, confidential data including server activities and financial information.
According to Kaspersky Research, Most of the tools used found on compromised servers are open-source and publicly available on GitHub:
After they find the vulnerable servers then attackers try to bypass and inject the exploit to gain more access and pull out logs file and other sensitives data From compromised Victims.
A breakthrough framework named SCAVY has been introduced to proactively detect memory corruption targets that could potentially…
Researchers have exposed a systemic vulnerability within the Windows operating system, leveraging its "Best-Fit" charset…
GitLab, the widely adopted DevOps platform, has announced the immediate release of versions 17.8.1, 17.7.3, and…
The Oligo Research team has disclosed a critical vulnerability in Meta’s widely used Llama-stack framework.…
INE Security, a leading global provider of cybersecurity training and certifications, today announced a new…
In a groundbreaking discovery on November 20, 2024, cybersecurity researchers Shubham Shah and a colleague…