InfobloxThreatIntel , to Cybersecurity
@InfobloxThreatIntel@infosec.exchange avatar

A malicious lookalike domain for Scotiabank Canada scotiabankcanada-auth[.]com was recently registered 5/5/2024. This domain features a landing page with a reCAPTCHA that changes languages depending on the user's geolocation. It resolves to a Russian IP 141[.]8[.]193[.]14 hosting a number of other malicious lookalikes for Scotiabank, the Royal Bank of Canada, and Telus Mobility. These domains appear to be used for phishing. auth-scotiaonline-scotiabank-secure[.]com previously resolved to a page imitating the Scotiabank login page shown in the screenshot below.

Domains: secure-scotiabankcanada[.]com, ,auth-scotiabankcanada-secure[.]com, info-securerbcroyalbank[.]com, rbcroyalbank-infosecure[.]com, rbcroyalbankinfo-secure[.]com, secure-inforbcroyalbank[.]com, secure-rbcroyalbankinfo[.]com, telusmobility-securerefund[.]com

image/png

InfobloxThreatIntel , to China
@InfobloxThreatIntel@infosec.exchange avatar

CISA has sounded the alarm of Chinese prepositioning activities in critical infrastructure. We uncovered an ongoing Chinese nation state DNS operation that is alarming in how perplexing it is. Muddling Meerkat can control the Great Firewall and is probing DNS infrastructure worldwide. When you find malware in a network, you can usually figure out what it is doing -- but a DNS attack is often a puzzle with missing pieces.

https://www.infoblox.com/threat-intel/threat-actors/muddling-meerkat/

InfobloxThreatIntel , to Cybersecurity
@InfobloxThreatIntel@infosec.exchange avatar

VexTrio is one of the longest operating cybercriminal actors around and their traffic distribution system (TDS) is one of a kind. We hosted a live discussion with @gentleshep who discovered them and @rmceoin who connected them to other notorious malware families in January. If you didn't see it, take a listen. https://www.infoblox.com/resources/webinars/traffic-distribution-systems-at-the-heart-of-cybercrime/

InfobloxThreatIntel , to Cybersecurity
@InfobloxThreatIntel@infosec.exchange avatar

Hi. This is Renée, the head of Infoblox Threat Intel (@knitcode). Myself and a few of my researchers are sharing this Mastodon account. Our plan is to toot about suspicious and malicious activity in DNS. Our team tends to write very in-depth papers and want to use Mastodon to complement that with nuggets we've seen, updates on the DNS threat actors or TTPs we are seeing, and articles we are reading. Here goes!

knitcode , to Cybersecurity

While we still don't know what devices are being compromised for the Decoy Dog malware, we know that they are ones that can persist a single process for over a year at a time... not your average laptop or phone. Things that come to mind are routers, switches, and firewalls. Unfortunately there are likely many more unknown vulnerabilities in other infrastructure products beyond the Cisco IOS XE one being discussed today. Some day, someone will figure out where Decoy Dog malware is hiding... and odds on: it is infrastructure. In particular, firewalls can organically create DNS traffic that is overlooked. In the meantime, time to patch up all the devices using Cisco IOS XE. https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/ https://insights.infoblox.com/resources-whitepaper/infoblox-whitepaper-decoy-dog-is-no-ordinary-pupy-distinguishing-malware-via-dns

knitcode , to Cybersecurity

As MFA has become more widely adopted, it's also become more widely targeted by threat actors. We've seen a large rise in MFA lookalike attacks over the last 18 months. This new blog discusses these trends, drawing out detail of the recent Retool breach through this kind of attack. https://blogs.infoblox.com/cyber-threat-intelligence/how-bad-guys-are-undermining-trust-in-multi-factor-authentication-mfa/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • Mordhau
  • WatchParties
  • Rutgers
  • steinbach
  • Lexington
  • cragsand
  • mead
  • RetroGamingNetwork
  • mauerstrassenwetten
  • loren
  • xyz
  • PowerRangers
  • AnarchoCapitalism
  • kamenrider
  • supersentai
  • itdept
  • neondivide
  • space_engine
  • AgeRegression
  • WarhammerFantasy
  • Teensy
  • learnviet
  • bjj
  • khanate
  • electropalaeography
  • MidnightClan
  • jeremy
  • fandic
  • All magazines