Quick Takeaways
- Threat actors are increasingly using sophisticated delivery methods, such as abused legitimate infrastructure and fake CAPTCHA prompts, to bypass defenses and deploy payloads like Amatera stealer and remote access tools.
- A new WebDAV infection chain linked to Russian actors exploits vulnerabilities and memory-based payloads, posing ongoing risks for cryptocurrency and credential theft.
- Cisco Talos reports active exploitation of vulnerabilities in Cisco Firepower Management, with malware spreading via Google APIs and multi-hop redirects, highlighting evolving evasion tactics.
The Threat, Attack Techniques, and Targets
The recent threat involves a complex WebDAV infection chain discovered during an incident at a Ukrainian government organization. The attack is attributed to a Russian threat actor known as UAT-10820. Attackers use WebDAV to deliver malware, including the Amatera stealer, ZigCryptoStealer, and NetSupport Manager. They abuse legitimate infrastructure, like the BNB Smart Chain, for hosting malicious content and use fake CAPTCHA prompts to evade security filters. The malware can run in memory, making it harder for defenses to detect. Attackers also deploy a vulnerable driver that terminates endpoint detection and response (EDR) software. Additionally, they use unauthorized remote access tools to gain persistent control over infected systems. The targets appear broad, mainly focusing on cryptocurrency and credential theft. They aim to steal valuable data and maintain long-term access.
Impact, Security Implications, and Remediation Guidance
This threat can cause significant damage, including data theft, system compromise, and persistent control over affected networks. The use of evasive techniques like fake verification prompts and in-memory malware makes detection difficult. Attackers’ ability to terminate security tools and deploy remote access tools increases the risk of prolonged system exploitation. Security teams should monitor WebDAV activity and look for suspicious DLL execution through “rundll32.exe” with unusual calls. Educating users about fake prompts can reduce the risk of accidental infection. Because the payload often resides only in memory, endpoint solutions should be configured for strong memory scanning. For detailed indicators of compromise and further guidance, consult the full threat report or your security vendor.
Stay Ahead with the Latest Tech Trends
Learn how the Internet of Things (IoT) is transforming everyday life.
Discover archived knowledge and digital history on the Internet Archive.
ThreatIntel-V1
