Hackers are increasingly executing financially motivated attacks and all due to the lucrative potential of monetizing the stolen data, ransoms, and fraudulent activities.
The digital revolution of businesses has invented more openings to exploit financial transactions and access sensitive financial information.
AttackIQ recently unveiled that the Chinese Winnti group intensifies financially motivated attacks.
Winnti is an established cyber-espionage and financial-gain group linked to the Chinese government since 2010.
Their healthcare targeting activities were ramped up during COVID-19, with medical research as their main objective.
They are known for supply chain attacks and use ShadowPad which is their signature backdoor, as well as PlugX RAT.
Free Webinar on API vulnerability scanning for OWASP API Top 10 vulnerabilities -> Book Your Spot
Winnti’s Operation CuckooBees (2022-05) proceeds in multiple stages.
Here below we have mentioned those stages:-
Here below we have mentioned them:-
This campaign contains multiple stages, and here below we have mentioned them:-
Each stage employs specific MITRE ATT&CK techniques for system infiltration, reconnaissance, and malware deployment.
There are four critical techniques used by Winnti that need to be focused on:-
Continuous testing with these attack graphs helps improve the security control posture against this Chinese government-linked threat actor.
Free Webinar! 3 Security Trends to Maximize MSP Growth -> Register For Free
The Oligo Research team has disclosed a critical vulnerability in Meta’s widely used Llama-stack framework.…
INE Security, a leading global provider of cybersecurity training and certifications, today announced a new…
In a groundbreaking discovery on November 20, 2024, cybersecurity researchers Shubham Shah and a colleague…
A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a grave…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS) advisories…
A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with a…