Archive for July 22, 2023

GitHub Warns Of Hackers Targeting Developers With Malicious Projects

Posted in Commentary with tags on July 22, 2023 by itnerd

Github posted a security alert that warns its users of a social engineering campaign that is targeting developers:

GitHub has identified a low-volume social engineering campaign that targets the personal accounts of employees of technology firms, using a combination of repository invitations and malicious npm package dependencies. Many of these targeted accounts are connected to the blockchain, cryptocurrency, or online gambling sectors. A few targets were also associated with the cybersecurity sector. No GitHub or npm systems were compromised in this campaign.

And:

We assess with high confidence that this campaign is associated with a group operating in support of North Korean objectives, known as Jade Sleet by Microsoft Threat Intelligence and TraderTraitor by the U.S. Cybersecurity and Infrastructure Security Agency (CISA). Jade Sleet mostly targets users associated with cryptocurrency and other blockchain-related organizations, but also targets vendors used by those firms.

Ken Westin, Field CISO, Panther Labs has this comment:

As organizations move to the cloud, they are also building custom applications, this makes source code repositories as GitHub a hot target, as attackers can inject malicious code that enables them to not only compromise one organization, but multiple. 

It’s pretty clear that this is yet another new attack vector that threat actors are exploiting. Thus people who use GitHub and services like it need to be aware of this so that they aren’t compromised by said threat actors.

Mallox Ransomware Activity Is Up 174% Says Unit 42

Posted in Commentary with tags on July 22, 2023 by itnerd

Mallox ransomware activities have seen a surge of almost 174% compared to the previous year. Unit 42 researchers have noticed this sharp increase, with the ransomware exploiting MS-SQL servers for distribution.

The group behind Mallox ransomware employs brute forcing, data exfiltration, and network scanners. Indications point to the group actively expanding its operations and recruiting affiliates on hacking forums.

Carol Volk, Executive with BullWall had this comment: 

Attackers will use all tools available to them, stacking every available vulnerability whether old or new as weapons to breach cyber defenses. Once in their sights a network breach is practically inevitable and we must prepare for it with a mindset of how to survive the breach, not simply defending against it.

The fact that this ransomware group is increasing their activities is yet another indicator of how dangerous the current threat landscape is. That means that anyone in the business of defending against these attacks needs to make sure that they are doing everything possible to make sure that they are not the next victim of this campaign.