New digital skimmer/#magecart technique: steganography
A colleague found this a couple of days ago while searching through our SIEM. The skimmer group uploads or modifies an existing image and appends the JS code.
1/5
OMG someone actually discovered malware (on the official Monero website) because the attackers changed the download binary but didn't change the hashes posted on the website github.com/monero-project…arstechnica.com/information-te…
this is a big day for hash checkers everywhere
It’s been over a year since I’ve released a sysmon-config update, but the wait will be worth it. Tightening up rule bypasses, leveraging new Sysmon features, adding rule tags with @MITREattack to give entry-level analysts more context why stuff they’re seeing could be important.
4K Followers 1K FollowingHacker, security research architect for @Microsoft Defender.
Member of @thegooniesctf. Linux, Windows, Android, MacOS, iOS, ChromeOS, bare metal.
日本語オーケーです👌
129K Followers 60 FollowingProviding Cyber Threat Intelligence from the Dark Web & Clearnet: Breaches, Ransomware, Darknet Markets, Threat Alerts & more. https://t.co/Fi7VW9lg94
44K Followers 2K FollowingHelping Secure the Internet | Long Island elder emo surviving in ATX | Expect: infosec current events, DFIR, appsec & cloudsec - and me!
9K Followers 2K FollowingThreat Researcher | Co-Host of Atomics on a Friday | LOLDrivers & Atomic Red Team Maintainer | I'm Everywhere and Nowhere - BSG.
18K Followers 801 FollowingThreat Intelligence Analyst |
See my Linktree for other socials |
In case I post false intel, contact me!
Support me: https://t.co/5WgDqr0K8p
🇪🇺🇩🇪🇺🇦🌈
1K Followers 12 FollowingDetection: Challenging Paradigms. The premiere adversary detection podcast. Powered by @SpecterOps. Link below to all supported platforms:
13K Followers 310 FollowingThreat Researcher, Blue Team, DFIR, Malware Analysis, and Reverse Engineering.
“⚔️What do we say to God of malware, Not today⚔️”
8K Followers 530 FollowingThreat Intel researcher! Technical tweets only; not reflective of employer's views. No endorsement of political groups/entities.
30K Followers 1K Following24/7/365 threat detection and response across your cloud, identity, endpoints and everything in-between. We got you: https://t.co/pFNwBJN3d5
61K Followers 804 FollowingSecurity Researcher. Previously Google Project Zero and TAG | 0days all day. Love all things bytes, assembly, and glitter. she/her.
229K Followers 229 Following#1 Cyber Performance Center, providing a human-first platform to create and maintain high-performing cybersecurity individuals and organizations.
880 Followers 2K FollowingSenior security analyst at Defendable. Co-founder Oslo hackerspace Hackeriet. Former head of Norwegian Unix User Group. https://t.co/HuK8ccOXJL