@SecurityAurai
iAccount based inNorth America
About this account
- Account based in
- North America
- Connected via
- North America App Store
Account-level information from X, not a live location or the device used for a specific post.
GCIH, GCFE, GDAT | DFIR, TH, DE | @CuratedIntel DFIR https://nitter.cf/t.co/BMWUwziTLh https://nitter.cf/t.co/MmX2YNVqdk https://nitter.cf/t.co/R20zseQfLk
Québec, Canada
Joined December 2014
- Tweets4.8K
- Following679
- Followers5.9K
- Likes17K
Aura retweeted
We’re really excited to publish this one alongside @malbearlabs 🥳
For the first time at Threat Hunting Labs, we’re releasing a real intrusion as both a public investigation report and a hands-on lab:
*️⃣ From SEO Poisoning to Custom RMM and Cobalt Strike
Read exactly what happened in this real intrusion, then open the lab and investigate the same evidence yourself.
It started with an administrator searching for RVTools and executing two malicious downloads on the same workstation. The activity then split into separate paths involving browser process injection, Level RMM, another custom RMM-style service, and eventually a Python-hosted Cobalt Strike Beacon.
What stood out to us was the amount of remote-access tooling involved. Instead of relying on one method, the attackers ended up with multiple access paths using legitimate RMM software, custom tooling, and Cobalt Strike.
You can investigate the evidence across Threat Hunting, Incident Response, Detection Engineering, and Malware Analysis.
🎥 When you finish, every lab includes a recorded walkthrough where we explain how we investigated the activity and arrived at the answers.
MalBear Labs went much deeper into the recovered payloads and malware, complementing our intrusion analysis with their own companion report.
And a big thank you to @securityaura for helping us with the threat intelligence context around the SEO poisoning and malicious samples.
Lab:
threathuntinglabs.com/threat…
Intrusion report:
threathuntinglabs.com/blog/f…
MalBear Labs:
malbearlabs.com/posts/novel-…
Aura retweeted
New @MalbearLabs collab with @ThruntingLabs and this one is a GOOD one: four payloads from one intrusion, all built to waste an analyst's time.
PavokwiLoader was the spicy one - WinMain is a single function with over 80,000 instructions and over 2,000 MBA clusters in that one function.
Also in there: RMMCRAT, a custom C++ payload wearing an RMM agent's clothes, a fake RMM service, and a Python loader that brute-forces its own decryption key instead of storing it.
@ThruntingLabs traced the intrusion and turned it into a hands-on lab. Big thanks to @SecurityAura for the threat intel context on the SEO poisoning and the samples 🐼
MalbearLabs teardown: malbearlabs.com/posts/novel-…
Aura retweeted
We are super stoked to publish this collab with @ThruntingLabs: four payloads from one intrusion, all built to waste an analyst's time.
@ThruntingLabs traced the intrusion and turned it into a hands-on lab. Big thanks to @SecurityAura again for the threat intel context on the SEO poisoning and the samples 🐼
Our teardown: malbearlabs.com/posts/novel-…
THL Lab:
threathuntinglabs.com/threat…
THL Intrusion report:
threathuntinglabs.com/blog/f…
Aura retweeted
Have you read some of our @HuntressLabs blogs and thought to yourself, damn, this looks like fun?
Do you love logs and investigating incidents ?
Want to help protect the 99 percent?
If it's a yasss across the board then I have good news for you, I'm hiring for 2 positions on our Tactical Response team!
Check out the posting below and apply!
job-boards.greenhouse.io/hun…
Aura retweeted
Giveaway: I've got 5 FREE entries to the first public Threat Hunting League competition from @ThruntingLabs! Hunt an Iranian APT campaign in a 4-hour personal lab using Splunk, Elastic or Azure Log Analytics. All levels welcome.
Leave a comment and I'll draw 5 winners on Wednesday 9/23.
🏆 Prizes:
🥇 13Cubed Investigating Windows Endpoints (1 yr access)
🥈 2 months THL + a private 1:1 threat hunting coaching session
🥉 1 month THL
Competition runs Sep 25–27. Details:
threathuntinglabs.com/compet…
Aura retweeted
Releasing EntraTrace
EntraTrace is a defensive security research tool for tracking and identifying the behavior of offensive tooling targeting Microsoft Entra ID.
The tool is still in early development, feel free to have a look and share your feedback!
github.com/Bert-JanP/EntraTr…
Organization implements MFA for sign-ins.
User receives a phishing email.
Performs a full sign-in on the phishing domain, INCLUDING passing the MFA challenge, manually, WILLINGLY, of his own violation.
"MFA BYPASS ACHIEVED!"
Bypass probably means something entirely in InfoSec
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
bleepingcomputer.com/news/se…
bleepingcomputer.com/news/se…
GTG, BleepingComputer and Malwarebytes Forums are how I got started in cybersecurity and got me to where I am today.
Malware Removal online, to DFIR.
A lot of what I learned and do everyday comes directly from these forums and the time I spent there as MRT.
RIP to an era.
Say goodbye to Geeks to Go (GTG) help forum. 😔
tinyurl.com/mv4t2yf8
The fact that normal people/users are still discovering ClickFix today and calling it new and highly dangerous because it looks so legit is probably why macro-laced documents and Invoice.pdf.exe worked all these years.
And still works to be honest.
DOMAIN\svc_sql - Domain Admins
I could run a search for that exact setup (or svcsql) across all my IR reports, and I can guarantee you I'll have more than one result.
Bonus points for LDAP bind users in the Domains Admins group.
Aura retweeted
Seriously, if you aren't following IR folks like @SecurityAura or reading things like @TheDFIRReport, you are missing out on what happens in the real world
Stop listening to vendors, listen to those dealing with real incidents
There's always alerts somebody didn't respond to
Replying to @SecurityAura
You know why the ransomware attack goes through anyway?
Nobody look at the console.
Bad assessment of the alerts that were raised by the humans behind it.
Key impacted assets didn't have the EDR on it.
EDR was running OOTB config.
Everyone who worked ransomware IR knows it.
If you have some time, check this out! Thank you to Kostas for making it available to everyone! 🙏
The articles he linked are also worth a read, so is the live analysis of a related malware sample on YouTube by @AzakaSekai_
lnkd.in/g7evWv6k
Really happy to introduce the Hunting Leads! 🥳
The idea is to share smaller pieces of real intrusion activity that are too narrow for a full lab, but still have interesting TTPs and useful telemetry. Telemetry that ANYONE can check out for FREE on our platform.
✅Windows Logs (including Sysmon)
✅EDR Logs
✅EDR Detections / Sigma Detections
✅Zeek Logs
The first threat-hunting lead we’re sharing appears related to the BoryptGrab/BlackSeeStealer lineage previously covered by @AzakaSekai_, Trend Micro, and Arctic Wolf (links below).
Also, big thanks to @SecurityAura for sharing the initial intel that put this activity on our radar 🙏
The chain we captured is pretty nice:
Signed vsdbg.exe renamed as a Balsamiq installer -> DLL side-loading -> ServiceModelReg.exe hollowing -> Chrome/Edge collection -> local file staging.
We also looked at the DLL separately and found a diagnostic mode triggered by C:\ExploitTests\purosangue.txt, which logs the hollowing flow in surprising detail.
A new PR has also been opened to add the DLL to the HijackLibs repo (github.com/wietze/HijackLibs…). This is a big win for me personally, as this is my first contribution to the project (@wietze🙏)
This is exactly the type of small, focused activity we want to keep sharing through Hunting Leads. There are more to come! Happy hunting!
Source:
- trendmicro.com/en_us/researc…
- arcticwolf.com/resources/blo…
Regarding #ShieldBreak, a few quick notes.
It didn't seem to work on a system where another EDR was present and registered as the primary Antivirus (Security Center).
Defender ate ShieldBreak.exe the minute I disabled the other EDR (Exploit:Win32/NghtMrShldBrk.BB).
CONT
There may be additional detection opportunities (I have 1-2 more I think, some relying on Sysmon and not MDE) but this one seems like the quick win/low-hanging fruit one.
As far as prevention goes, see this tweet by @CyberCakeX
Kind of explains the low-hanging fruit detection too. And the nice comment you get in the code if you look for "phoneinfo".
nitter.cf/CyberCakeX/status/2087…
A quick fix for this PoC, run in PowerShell 👇
[IO.File]::OpenWrite("$env:windir\System32\phoneinfo.dll").Dispose()
Why? wermgr.exe is hardcoded to load a non-existent DLL in System32 folder, so we create a 0-byte file in it as Admin so the vulnerability Fails to run unelevated
Aura retweeted
Folks @HuntressLabs were in full swing this Friday analyzing the latest and greatest of CVE-2026-15409 and CVE-2026-15410, affecting SonicWall SMA 1000-series appliances.
DCSync on the DC's, Sliver on the SMA's, and more below.
Our first hint of adversarial access was remote registry dumping across numerous environments, detected and mitigated by Defender. This was Impacket's Secretsdump. github.com/fortra/impacket/b…
We began to analyze Huntress' SIEM data for signs of compromise from affected SMA devices within these environments. We found two distinct patterns.
1.) Adversaries acting to validate exploitation against these appliances from a variety of low rep providers.
2.) Anomalous curl activity from the 'root' user of an appliance; fetching payloads from 153.75.81[.]30.
Two different payloads-- ".sshd" and ".rsyncd" were noted. They were stashed in /var/tmp/ and executed through cron (rsyncd-update and sshd-update) on the SMA appliance.
Analysis of the payloads confirmed these were Sliver implants, an adversary emulation framework by BishopFox. These were configured to callback to the same staging IP.
github.com/bishopfox/sliver
This would allow an adversary to linger covertly after remediation efforts.
Meanwhile, @xorJosh was busy cooking away on his own analysis-- and located an open directory containing CVE validation scripts (a CN-localized Rapid7 script), "autodcsync" and "autosecretsdump" Python files, and exfiltrated credentials from numerous environments.
Of note, contained next to the credentials and scripts in the open dir was 'iox' and 'frp', two direct-tunnel tools.
github.com/eddieivan01/iox
github.com/fatedier/frp
These are noteworty chiefly because they have been favorites of numerous nation-state APT groups.
The key takeaways here are clear:
- SIEM saves lives; make sure logs are being forwarded and retained.
- Patching might not mean you're out of the woods, adversaries are already weaponizing persistent implants to maintain access.
IOCs
IPv4/Port: 153.75.81[.]30:30303 - Stager
Resource: 153.75.81[.30:30303/a - .rsyncd
Resource: 153.75.81[.30:30303/c - .sshd
IPv4/Port: 153.75.81[.30:80 - Sliver C2 Callback
Cron: /etc/cron.d/rsync-update - .rsyncd Cronjob
Cron: /etc/cron.d/sshd-update - .sshd Cronjob
Binary: 5aa0bb8a8a298fc00935dad22e73e1effc648b1739628b782727ba7bb123cbc3 (.rsyncd)
Binary: 098db74319d0798291264c643522db59fc12d65ef649d7e12c7334ea75a74a4e (.sshd)
Path: /var/tmp/.rsyncd
Path: /var/tmp/.sshd
If you are a one-person shop selling "antivirus" to your clients just for checkbox/compliance and never checks the alerts or else.
You are a big part of the problem.
Get a MDR for "MSP" or whatever, but don't do this. You're just selling a fake feeling of security.