Remove sidewinder-infrastructure-revealed
article thumbnail

State-Sponsored Cybercrime Group`s Infrastructure Revealed

Heimadal Security

Researchers have uncovered previously unknown attack infrastructure used by Pakistani and Chinese entities operated by the state-sponsored group SideWinder. At least since 2012, SideWinder has been active, using spear-phishing attacks to gain access to targeted environments.

article thumbnail

APT trends report Q1 2022

SecureList

On March 1, ESET published a blog post related to wipers used in Ukraine and to the ongoing conflict: in addition to HermeticWiper, this post introduced IsaacWiper, used to target specific machines previously compromised with another remote administration tool named RemCom, commonly used by attackers for lateral movement within compromised networks.

Malware 131
article thumbnail

APT trends report Q1 2021

SecureList

The company’s Orion IT, a solution for monitoring and managing customers’ IT infrastructure, was compromised. Kaspersky telemetry revealed a spike in exploitation attempts for these vulnerabilities following the public disclosure and patch from Microsoft. webshells and Exaramel implants.

Malware 139