Threats Feed
- Public
Agonizing Serpens APT Targets Israeli Education and Tech Sectors in Sophisticated Cyberattacks
The Agonizing Serpens APT group conducted a series of cyberattacks on Israel's education and technology sectors from January to October 2023. These attacks involved stealing sensitive data, including personal and intellectual property, followed by deploying various wipers like MultiLayer, PartialWasher, and BFG Agonizer to erase traces and disable endpoints. Techniques used included exploiting web servers, deploying web shells, network scanning with Nbtscan and WinEggDrop, credential theft via Mimikatz, and data exfiltration using tools like WinSCP. The group's upgraded capabilities aimed to bypass endpoint detection and response (EDR) systems, employing a mix of known and custom tools for evasion.
read more about Agonizing Serpens APT Targets Israeli Education and Tech Sectors in Sophisticated Cyberattacks - Public
Jennlog and Apostle: Unpacking Agrius's Ransomware Attack on Israeli Academia
Apostle ransomware was resurrected in a targeted attack by Agrius against Bar-Ilan University in Israel. The report details the use of a custom loader, Jennlog, to obfuscate, encrypt, and compress the ransomware. Jennlog disguises the payload within seemingly innocuous log files and conducts environment checks to evade detection. This version of Apostle, compiled on the day of the attack, encrypts victim data, demanding a ransom and altering desktop wallpapers to display a clown image. Additionally, another Jennlog variant was found loading OrcusRAT, indicating broader malicious capabilities of the threat actor.
read more about Jennlog and Apostle: Unpacking Agrius's Ransomware Attack on Israeli Academia - Public
Agrius: From Espionage to Destructive Cyber Attacks in the Middle East
The Agrius threat actor evolved from conducting espionage to destructive attacks, notably using wipers disguised as ransomware. Initially engaging in data destruction under the guise of encryption for ransom, Agrius later developed fully functional ransomware, targeting primarily Israel and the UAE's critical facilities. Utilizing VPNs for anonymity, Agrius exploited public-facing applications, deploying webshells for initial access, and custom .NET malware, 'IPsec Helper', for persistence and data exfiltration. Their toolkit includes the .NET-based 'Apostle' wiper-turned-ransomware and the DEADWOOD wiper, indicating a sophisticated approach to cyber sabotage and espionage.
read more about Agrius: From Espionage to Destructive Cyber Attacks in the Middle East