Researchers at Fortra Intelligence and Research Experts (FIRE) have identified a highly advanced fileless malware campaign specifically targeting large enterprises. The attack is distinguished by its deployment of five distinct layers of obfuscation, engineered to circumvent email, endpoint, and memory-based security systems. This exceptional level of sophistication enables attackers to remain undetected for extended periods, substantially increasing dwell time and complicating forensic inves
edr (4)
Analysts at Sophos' X-Ops group have identified a threat actor operating within a customer environment after an anomalous endpoint generated alerts. The device, located in a tenant, contained multiple malicious files stored in the directory C:\Users\User\Documents\test. These included Cobalt Strike profiles crafted to mimic legitimate web traffic, a Telegram bot application programming interface mechanism for external command and control communication, Python scripts designed to inject shellcod
Automating the on-demand collection of memory dumps, process information, system files, and event logs for inclusion in threat-hunting activities allows for a more comprehensive and proactive approach to adaptive threat-hunting. In the WatchTower Threat Hunting blog series, Sentinel Labs calls out some adaptive threat-hunting methodologies, including Chained Detections, a Multi-Directional Approach, and AI-powered hunts. This shows the benefits of applying a multi-directional approach to adaptiv
Ransomware isn’t new, yet organizations still struggle to guard against this threat. According to the Fortinet 2023 Global Ransomware Report, in 12 months, two-thirds of organizations were targeted by ransomware, with half of those falling victim to an attack. As attackers advance their tactics, security and IT leaders must prepare for the inevitability of a ransomware attack. It is no longer a matter of “if” a business will be breached but “when.” Along with business leaders, those in the C