Thursday, September 21, 2023
LetsAskBinu.com
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things
No Result
View All Result
LetsAskBinu.com
No Result
View All Result
Home Fintech

ESET APT Activity Report Q4 2022­–Q1 2023

Researcher by Researcher
September 16, 2023
in Fintech
0
ESET APT Activity Report Q4 2022­–Q1 2023
189
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter


Threat Reports, ESET Research

An overview of the activities of selected APT groups investigated and analyzed by ESET Research in Q4 2022 and Q1 2023

Jean-Ian Boutin

09 May 2023
 • 
,
3 min. read

ESET APT Activity Report Q4 2022­–Q1 2023

ESET APT Activity Report Q4 2022–Q1 2023 summarizes the activities of selected advanced persistent threat (APT) groups that were observed, investigated, and analyzed by ESET researchers from October 2022 until the end of March 2023. Attentive readers will notice that a small portion of the report also mentions some events previously covered in APT Activity Report T3 2022. This stems from our decision to release this report on a semi-annual basis, with the current issue encompassing Q4 2022 and Q1 2023, while the forthcoming edition will cover Q2 and Q3 2023.

In the monitored timeframe, several China-aligned threat actors focused on European organizations, employing tactics such as the deployment of a new Ketrican variant by Ke3chang, and Mustang Panda’s utilization of two new backdoors. MirrorFace targeted Japan and implemented new malware delivery approaches, while Operation ChattyGoblin compromised a gambling company in the Philippines by targeting its support agents. India-aligned groups SideWinder and Donot Team continued to target governmental institutions in South Asia with the former targeting the education sector in China, and the latter continued to develop its infamous yty framework, but also deployed the commercially available Remcos RAT. Also in South Asia, we detected a high number of Zimbra webmail phishing attempts.

In the Middle East, Iran-aligned group MuddyWater stopped using SimpleHelp during this period to distribute its tools to its victims and shifted to PowerShell scripts. In Israel, OilRig deployed a new custom backdoor we’ve named Mango and the SC5k downloader, while POLONIUM used a modified CreepySnail.

North Korea-aligned groups such as ScarCruft, Andariel, and Kimsuky continued to focus on South Korean and South Korea-related entities using their usual toolsets. In addition to targeting the employees of a defense contractor in Poland with a fake Boeing-themed job offer, Lazarus also shifted its focus from its usual target verticals to a data management company in India, utilizing an Accenture-themed lure. Additionally, we also identified a Linux malware being leveraged in one of their campaigns. Russia-aligned APT groups were especially active in Ukraine and EU countries, with Sandworm deploying wipers (including a new one we call SwiftSlicer), and Gamaredon, Sednit, and the Dukes utilizing spearphishing emails that, in the case of the Dukes, led to the execution of a red team implant known as Brute Ratel. Finally, we detected that the previously mentioned Zimbra email platform was also exploited by Winter Vivern, a group particularly active in Europe, and we noted a significant drop in the activity of SturgeonPhisher, a group targeting government staff of Central Asian countries with spearphishing emails, leading to our belief that the group is currently retooling.

Malicious activities described in ESET APT Activity Report Q4 2022–Q1 2023 are detected by ESET products; shared intelligence is based mostly on proprietary ESET telemetry and has been verified by ESET Research.

Countries, regions and verticals affected by the APT groups described in this report include:

Targeted countries and regions
Australia
Bangladesh
Bulgaria
Central Asia
China
Egypt
Europe
Hong Kong
India
Israel
Japan
Namibia
Nepal
Pakistan
The Philippines
Poland
Saudi Arabia
South Korea
Southwest Asia
Sri Lanka
Sudan
Taiwan
Ukraine
The United Kingdom
The United States
Targeted business verticals
Data management companies
Defense contractors
Diplomats
Educational institutions
Energy sector
Financial services
Gambling companies
Governmental organizations
Healthcare
Hospitality
Media
Research institutes

ESET APT Activity Reports contain only a fraction of the cybersecurity intelligence data provided in ESET APT Reports PREMIUM. For more information, visit the ESET Threat Intelligence website.

Follow ESET research on Twitter for regular updates on key trends and top threats.





Source link

Related articles

EBANX Furthers Expansion into Africa; Adding 8 new Countries to its Ecosystem

EBANX Furthers Expansion into Africa; Adding 8 new Countries to its Ecosystem

September 21, 2023
Dubai International Financial Centre Reveals Plans for Second Edition of Dubai FinTech Summit

Dubai Ready to Capitalise on Projected 17.2% Global Growth of Fintech Investment, Says DIFC

September 21, 2023
Tags: 2022Q1activityAPTESETreport
Share76Tweet47

Related Posts

EBANX Furthers Expansion into Africa; Adding 8 new Countries to its Ecosystem

EBANX Furthers Expansion into Africa; Adding 8 new Countries to its Ecosystem

September 21, 2023
0

EBANX, the global tech company specialising in payments for rising markets, is expanding its operations to eight more countries across...

Dubai International Financial Centre Reveals Plans for Second Edition of Dubai FinTech Summit

Dubai Ready to Capitalise on Projected 17.2% Global Growth of Fintech Investment, Says DIFC

September 21, 2023
0

Investment in fintech is projected to grow by 17.2 per cent CAGR to $949billion from 2022 to 2030 and is...

UK Fintech News Round-Up: The Latest Stories 02/03

UK Fintech News Roundup: The Latest Stories 20/09

September 20, 2023
0

Every Wednesday, we delve into the latest fintech updates from across the UK. This week brings updates from HSBC, Vestd,...

The Importance of SEO in Fintech

The Importance of SEO in Fintech

September 19, 2023
0

The fintech industry is worth a staggering £141billion, and more than 64 per cent of all consumers have used a...

This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 19/09

September 19, 2023
0

The Fintech Times Bi-Weekly News Roundup on Tuesday 19 September 2023 AppointmentsNovatus Global, a risk and regulation consultancy and technology solution...

Load More
  • Trending
  • Comments
  • Latest
This Week in Fintech: TFT Bi-Weekly News Roundup 08/02

This Week in Fintech: TFT Bi-Weekly News Roundup 15/03

March 15, 2022
Supply chain efficiency starts with securing port operations

Supply chain efficiency starts with securing port operations

March 15, 2022
Microsoft to Block Macros by Default in Office Apps

Qakbot Email Thread Hijacking Attacks Drop Multiple Payloads

March 15, 2022
QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

QNAP Escalation Vulnerability Let Attackers Gain Administrator Privileges

March 15, 2022
Beware! Facebook accounts being hijacked via Messenger prize phishing chats

Beware! Facebook accounts being hijacked via Messenger prize phishing chats

0
Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

Shoulder surfing: Watch out for eagle‑eyed snoopers peeking at your phone

0
Remote work causing security issues for system and IT administrators

Remote work causing security issues for system and IT administrators

0
Elementor WordPress plugin has a gaping security hole – update now – Naked Security

Elementor WordPress plugin has a gaping security hole – update now – Naked Security

0
LUCR-3 Attacking Fortune 2000 Companies Using Victims’ Own Tools

LUCR-3 Attacking Fortune 2000 Companies Using Victims’ Own Tools

September 21, 2023
EBANX Furthers Expansion into Africa; Adding 8 new Countries to its Ecosystem

EBANX Furthers Expansion into Africa; Adding 8 new Countries to its Ecosystem

September 21, 2023
Trend Micro Zero-day Vulnerability Let Attackers Run Arbitrary Code

Trend Micro Zero-day Vulnerability Let Attackers Run Arbitrary Code

September 21, 2023
Intel Reveals New 288-Core Sierra Forest CPU, Core Ultra Processors at Intel Innovation 2023

Intel Reveals New 288-Core Sierra Forest CPU, Core Ultra Processors at Intel Innovation 2023

September 21, 2023

Recent Posts

LUCR-3 Attacking Fortune 2000 Companies Using Victims’ Own Tools

LUCR-3 Attacking Fortune 2000 Companies Using Victims’ Own Tools

September 21, 2023
EBANX Furthers Expansion into Africa; Adding 8 new Countries to its Ecosystem

EBANX Furthers Expansion into Africa; Adding 8 new Countries to its Ecosystem

September 21, 2023
Trend Micro Zero-day Vulnerability Let Attackers Run Arbitrary Code

Trend Micro Zero-day Vulnerability Let Attackers Run Arbitrary Code

September 21, 2023

Categories

  • Cyber Threats
  • Cybersecurity
  • Fintech
  • Hacking
  • Internet Of Things
  • LetsAskBinuBlogs
  • Malware
  • Networking
  • Protection

Tags

Access attack Attacks banking BiWeekly bug Cisco cloud code critical Cyber Cybersecurity Data Digital exploited financial Fintech Flaw flaws Google Group Hackers Krebs Latest launches malware Microsoft million Network News open patches platform Ransomware RoundUp security Software Stories TFT Threat Top vulnerabilities vulnerability warns Week

© 2022 Lets Ask Binu All Rights Reserved

No Result
View All Result
  • Home
  • Cybersecurity
  • Cyber Threats
  • Hacking
  • Protection
  • Networking
  • Malware
  • Fintech
  • Internet Of Things

© 2022 Lets Ask Binu All Rights Reserved