Is Emotet gang targeting companies with external SOC?

Introduction The group behind Emotet malware is getting smarter and smarter in the way the deliver such a Malware. While the infection schema looks alike from years; the way the group tries to infect victims improves from day to day.Today I’d like to share a quick analysis resulted by a very interesting email which claimed […]

Read more "Is Emotet gang targeting companies with external SOC?"

Frequent VBA Macros used in Office Malware

Nowadays one of the most frequent cybersecurity threat comes from Malicious (office) document shipped over eMail or Instant Messaging. Some analyzed threats examples include: Step By Step Office Dropper Dissection, Spreading CVS Malware over Google, Microsoft Powerpoint as Malware Dropper, MalHIDE, Info Stealing: a New Operation in the Wild, Advanced All in Memory CryptoWorm, etc. […]

Read more "Frequent VBA Macros used in Office Malware"

Similarities and differences between MuddyWater and APT34

Many state sponsored groups have been identified over time, many of them have different names (since discovered by different organizations) and there is no an agreed standardization on the topic but many victims and some interests look very tight together. From here the idea to compare the leaked source code of two different state sponsored […]

Read more "Similarities and differences between MuddyWater and APT34"

“Collection #I” Data Breach Analysis – Part 2

On January 19th we downloaded Collectoin #1 to make statistics on its content (you might find more information here). During these days we finished the two main activities to be able to answer some more questions about it data: (i) ELK import and (ii) building of simple views to visualise desired informations. The following image shows […]

Read more "“Collection #I” Data Breach Analysis – Part 2"

MartyMcFly Malware: Targeting Naval Industry

Today I’d like to share an interesting analysis of a Targeted Attack found and dissected by Yoroi (technical details are available here). The victim was one of the most important leader in the field of  security and defensive military grade Naval ecosystem in Italy. Everything started from a well crafted  email targeting the right office […]

Read more "MartyMcFly Malware: Targeting Naval Industry"

Hacking The Hacker. Stopping a big botnet targeting USA, Canada and Italy

Today I’d like to share a full path analysis including a KickBack attack which took me to gain full access to an entire Ursniff/Gozi BotNet .   In other words:  from a simple “Malware Sample” to “Pwn the Attacker Infrastructure”. NB: Federal Police has already been alerted on such a topic as well as National […]

Read more "Hacking The Hacker. Stopping a big botnet targeting USA, Canada and Italy"