RussianPanda 🐼 🇺🇦(@RussianPanda9xx) 's Twitter Profile Photo

spreads via Fake Browser Updates.

Check out the writeup: esentire.com/blog/fakebat-m…

Generating AI art is probably the main reason why I write blogs 🤣

#FakeBat spreads via Fake Browser Updates.

Check out the writeup: esentire.com/blog/fakebat-m…

Generating AI art is probably the main reason why I write blogs 🤣
account_circle
ThreatDown(@Threat_Down) 's Twitter Profile Photo

⚠️ Malicious Google ad for Inkscape leads to

➡️ Impostor site: inkckape[.]org
➡️ Payload:
hxxps[://]planbooknfly[.]com/data/Inkscape-x86[.]msix
dc471b087413ea64f7693b27e38ac568dea00ec1c7f699e48a6ef96b9cb4e30e
➡️ C2: utm-adschuk[.]com

⚠️ Malicious Google ad for @inkscape leads to #FakeBat

➡️ Impostor site: inkckape[.]org
➡️ Payload:
hxxps[://]planbooknfly[.]com/data/Inkscape-x86[.]msix
dc471b087413ea64f7693b27e38ac568dea00ec1c7f699e48a6ef96b9cb4e30e
➡️ C2: utm-adschuk[.]com
account_circle
CyberXTron Technologies(@CyberxtronTech) 's Twitter Profile Photo

🚨 Threat Campaign Alert - FakeBat Malware Uses Legitimate Websites and Diverse Brand Impersonation Tactics🚨

Summary: February witnessed a significant rise in search-based malvertising incidents, nearly doubling the documented cases. FakeBat malware leverages malvertising…

🚨 Threat Campaign Alert - FakeBat Malware Uses Legitimate Websites and Diverse Brand Impersonation Tactics🚨

Summary:  February witnessed a significant rise in search-based malvertising  incidents, nearly doubling the documented cases. FakeBat malware  leverages malvertising…
account_circle
Yeti(@Yeti_Sec) 's Twitter Profile Photo

DEV-0569 activity: Google ad fake CPUID page --> 'FakeBat' Loader.

Different redirect google ad domain from last Friday, but serving same payload as what Brad shared.

Urlscan:
urlscan.io/result/88610e6…

VirusTotal:
virustotal.com/gui/file/c6e79…

DEV-0569 activity: Google ad fake CPUID page --> 'FakeBat' Loader. 

Different redirect google ad domain from last Friday, but serving same payload as what @malware_traffic shared.

Urlscan:
urlscan.io/result/88610e6…

VirusTotal:
virustotal.com/gui/file/c6e79…
account_circle
Merl(@Merlax_) 's Twitter Profile Photo

+

Hay otras dos publicidades activas en Google apuntando a Bitbucket y Bitwarden

IP
141.98.233.]61

30 dominios relacionados a la ip
pastebin.com/f9igjPnH

Todos los productos apuntados:
Bitwarden
BitBucket
Blender
VMWare
Todoist
Calendly

1/2

#Fakebat + #Rhadamanthys #Stealer

Hay otras dos publicidades activas en Google apuntando a Bitbucket y Bitwarden

IP
141.98.233.]61

30 dominios relacionados a la ip
pastebin.com/f9igjPnH

Todos los productos apuntados:
Bitwarden
BitBucket
Blender
VMWare
Todoist
Calendly

1/2
account_circle
Germán Fernández(@1ZRR4H) 's Twitter Profile Photo

utilizando al menos 10 dominios .ar 🇦🇷 para distribuirse a través de... 🥁 Google Ads.

cecar[.]com[.]ar
estiloplus[.]tur[.]ar
disenoymas[.]com[.]ar
barcala[.]com[.]ar
elchubutense[.]com[.]ar
argentec[.]com[.]ar
culturabritanicacba[.]org[.]ar…

#FakeBat utilizando al menos 10 dominios .ar 🇦🇷 para distribuirse a través de... 🥁 @GoogleAds.

cecar[.]com[.]ar
estiloplus[.]tur[.]ar
disenoymas[.]com[.]ar
barcala[.]com[.]ar
elchubutense[.]com[.]ar
argentec[.]com[.]ar
culturabritanicacba[.]org[.]ar…
account_circle
RussianPanda 🐼 🇺🇦(@RussianPanda9xx) 's Twitter Profile Photo

It's , and it's been delivering payloads with IDAT loader for about 8 months. How is it a new variant? Morphisec

blog.morphisec.com/threat-bulleti…

account_circle
Germán Fernández(@1ZRR4H) 's Twitter Profile Photo

🛑 More / via Google Ads

Autodesk Maya spoofing site maya-autodes[.]cc download Maya-x64.msix from prezemp[.]com.
[+] bazaar.abuse.ch/sample/9e6e04c…

'Fodere Titanium Limited'

1.- New C2: 95.143.191.159:22876 (from https://alexsazo[.]com/1.jpg)
2.-…

🛑 More #FakeBat/#EugenLoader via @GoogleAds

Autodesk Maya spoofing site maya-autodes[.]cc download Maya-x64.msix from prezemp[.]com.
[+] bazaar.abuse.ch/sample/9e6e04c…

#SIGNED 'Fodere Titanium Limited'

1.- New #RedLine C2: 95.143.191.159:22876 (from https://alexsazo[.]com/1.jpg)
2.-…
account_circle
Security Onion(@securityonion) 's Twitter Profile Photo

Today's quick analysis with : FAKEBAT, REDLINE STEALER, and GOZI/ISFB/URSNIF pcap from 2023-02-03!

Thanks to Brad for sharing this pcap!

More screenshots:
blog.securityonion.net/2023/02/quick-…


urity

Today's quick #malware analysis with #SecurityOnion: FAKEBAT, REDLINE STEALER, and GOZI/ISFB/URSNIF pcap from 2023-02-03!

Thanks to @malware_traffic for sharing this pcap!

More screenshots:
blog.securityonion.net/2023/02/quick-…

#infosec
#infosecurity
#ThreatHunting
#IncidentResponse
account_circle
Dr. Dawn Bazely is @DawnBazely@mastodon.world(@dawnbazely) 's Twitter Profile Photo

A majority of the under 4 crowd appear to believe that Billy the 🦇 is real. I wish my husband would just say it’s a and stop saying it’s the household pet.

account_circle
eSentire Threat Intel(@esthreat) 's Twitter Profile Photo

eSentire's Threat Response Unit has observed loader🦇 being distributed via , ultimately leading to infection via a custom-written PaykRunPE provided by the FakeBat Threat Actors.
eSentire

eSentire's Threat Response Unit has observed #FakeBat loader🦇 being distributed via #FakeUpdates, ultimately leading to #LummaC2 infection via a custom-written PaykRunPE provided by the FakeBat Threat Actors. 
@eSentire
account_circle
Tata Communications(@tata_comm) 's Twitter Profile Photo

Malvertisers have moved beyond URL shorteners to compromising legitimate websites, broadening their targets. FakeBat stands out for its use of MSIX installers with heavily obfuscated PowerShell scripts. Learn more in our update: okt.to/sgol2A

Malvertisers have moved beyond URL shorteners to compromising legitimate websites, broadening their targets. FakeBat stands out for its use of MSIX installers with heavily obfuscated PowerShell scripts. Learn more in our #ThreatAdvisoryTuesday update: okt.to/sgol2A
account_circle