Government
Active Cyber Defence (ACD) - the fourth year
The year four report covers 2020 and aims to highlight the achievements and efforts made by the Active Cyber Defence programme.
The year four report covers 2020 and aims to highlight the achievements and efforts made by the Active Cyber Defence programme.
Group-IB specialists detected GrelosGTM group started to abuse Google Tag Manager legitimate functionality for their own purposes in infections of online shops.
We’ve been focused on expanding our platform and helping you better protect your customers. And we’re just getting started.
In this blog, we look at some malicious PowerShell code breadcrumbs that one hacker left behind to unravel how they maintained access during a cyberattack.
A vulnerability in AWS Cognito's password reset function allowed attackers to brute-force the six-digit reset code, potentially leading to account takeovers. Using concurrent HTTP requests, an attacker could make up to 1587 guesses instead of the documented limit of 20. The issue affected accounts without multi-factor authentication and was fixed by AWS on April 20, 2021.
Are you ready to scale your MSP or SMB? Level up your threat detection and response so you can focus on what's important: your business.
Back in action with JS sniffers redesigned to steal crypto
Keep your MSP armed and ready for attacks, hacks and data breaches with the latest trends in cybersecurity.
Group-IB's Computer Emergency Response Team built a solid phishing kit database, which helps Group-IB fight phishing that targets specific brands.
The rise and fall of illicit cardshop breached twice in two years
We hunt for persistent footholds, but what exactly does that mean? In this blog, we define what a foothold is and why it's a hacker favorite.
The analysis of phishing campaigns carried out by a new threat actor
A recap of hack_it 2021, a virtual security training event packed with interactive exercises, malware analysis, hacking workshops and more.
Windows' administrative shares feature is often overlooked by users, but not by hackers. Learn how attackers abuse administrative shares to propagate.
Let's hunt some bootkits
GCP provides an OS Login service for managing SSH access to compute instances using IAM roles. An attacker could abuse this feature via LXD, Docker (if available on the target system) and DHCP poisoning of the metadata server to escalate their privileges on a Google Compute Engine VM.
At the end of this tunnel, we find some shady hackers using ngrok to gain remote control access to victim networks.
Analysis of the E1RB JS sniffer family
If attacker controlled data is viewed in Cloudshell it could have led to code execution. This exact same issue existed in Azure previously.
A vulnerability in the Azure Linux VM extension mechanism allowed an unprivileged user to leak any Azure VM extension’s private data. An attacker could have abused this to gain credentials for the VM itself as well as credentials for extensions associated with the VM. Paired with the design of the VMAccess extension (an official Azure extension for managing VM credentials), this could have been used to achieve privilege escalation, as an unprivileged attacker would have been able to elevate the…
Hackers always try to cover up their tracks. In this blog, we step through layers of obfuscation to uncover the real intent of a .NET malware sample.
On-prem Microsoft Exchange Server vulnerabilities are being actively exploited in the wild. Read our blog for Huntress' most up-to-date research and IOCs.
In this blog, we define what threat hunting is, the differences between human analysis and automation, plus an example of human-powered threat hunting.
A deep dive into Classiscam: automated scam as a service designed to steal money and payment data
We unveil zero-day vulnerabilities we discovered in virtual event platforms used in MSP/Fortune 500 communities, plus some insight on supply chain attacks.
The year three report covers 2019 and aims to highlight the achievements and efforts made by the Active Cyber Defence programme.
In cybersecurity, education and training are the key to winning. Read our blog to learn how you can grow your skills through continuous security education.
An attacker could gain root privileges on their Azure Cloud Shell container, escape from the container, and then gain root privileges on the underlying node, the root cause being an insecure kubelet port (10250), among other cluster misconfigurations. Once they could access the node filesystem, an attacker could extract kubelet API credentials which allowed listing all pods and nodes in the cluster, including those belonging to other tenants. Moreover, an attacker could bypass RBAC policies in …
To avoid detection, hackers often turn a system’s own tools against itself. Here, we examine a malicious payload that was executed using PowerShell.