Ransom & Dark Web Issues Week 3, July 2024

Ransom & Dark Web Issues Week 3, July 2024

ASEC Blog publishes Ransom & Dark Web Issues Week 3, July 2024      

Threat Trend Report on Deep Web &Dark Web – Ransomware Groups & Cybercrime Forums and Markets in June 2024

Threat Trend Report on Deep Web &Dark Web – Ransomware Groups & Cybercrime Forums and Markets in June 2024

Note   This trend report on the deep web and dark web of June 2024 is sectioned into Ransomware, Forums & Black Markets, and Threat Actor. We would like to state beforehand that some of the content has yet to be confirmed to be true.   Major Issues   1.  

Ddostf DDoS Bot Malware Attacking MySQL Servers

Ddostf DDoS Bot Malware Attacking MySQL Servers

The AhnLab Security Emergency response Center’s (ASEC) analysis team is constantly monitoring malware distributed to vulnerable database servers. MySQL server is one of the main database servers that provides the feature of managing large amounts of data in a corporate or user environment. Typically, in Windows environments, MS-SQL is primarily

Tsunami DDoS Malware Distributed to Linux SSH Servers

Tsunami DDoS Malware Distributed to Linux SSH Servers

AhnLab Security Emergency response Center (ASEC) has recently discovered an attack campaign that consists of the Tsunami DDoS Bot being installed on inadequately managed Linux SSH servers. Not only did the threat actor install Tsunami, but they also installed various other malware such as ShellBot, XMRig CoinMiner, and Log Cleaner.

ChinaZ DDoS Bot Malware Distributed to Linux SSH Servers

ChinaZ DDoS Bot Malware Distributed to Linux SSH Servers

AhnLab Security Emergency response Center (ASEC) has recently discovered the ChinaZ DDoS Bot malware being installed on inadequately managed Linux SSH servers. As one of the Chinese threat groups that were first discovered around 2014, the ChinaZ group installs various DDoS bots on Windows and Linux systems. [1] Major DDoS bots assumed

PYbot DDoS Malware Being Distributed Disguised as a Discord Nitro Code Generator

PYbot DDoS Malware Being Distributed Disguised as a Discord Nitro Code Generator

A major method through which threat actors distribute malware is by uploading them to sites disguised as cracks or illegal software. After a threat actor uploads their malware disguised as a crack or serial keygen for some paid software, users become infected by the malware while installing this illegal software.

Shc Linux Malware Installing CoinMiner

Shc Linux Malware Installing CoinMiner

The ASEC analysis team recently discovered that a Linux malware developed with Shc has been installing a CoinMiner. It is presumed that after successful authentication through a dictionary attack on inadequately managed Linux SSH servers, various malware were installed on the target system. Among those installed were the Shc downloader,

Nitol DDoS Malware Installing Amadey Bot

Nitol DDoS Malware Installing Amadey Bot

The ASEC analysis team recently discovered that a threat actor has been using Nitol DDoS Bot to install Amadey. Amadey is a downloader that has been in circulation since 2018, and besides extorting user credentials, it can also be used for the purpose of installing additional malware. Amadey is being

HackHound IRC Bot Being Distributed via Webhards

HackHound IRC Bot Being Distributed via Webhards

Webhards are the main platforms that the attackers targeting Korean users exploit to distribute malware. The ASEC analysis team has been monitoring malware types distributed through webhards and uploaded multiple blog posts about them in the past. Generally, attackers distribute malware through illegal programs such as adult games and crack

njRAT Being Distributed via Webhards

njRAT Being Distributed via Webhards

Webhards is a platform used to distribute malware, and it is mainly used by attackers that mainly target Korean users. The ASEC analysis team has been monitoring malware types distributed through webhards and has uploaded multiple blog posts about them in the past. Various types of malware are used recently