Iranian Hackers Deliver New ‘Fantasy’ Wiper to Diamond Industry via Supply Chain Attack By Orbit Brain December 9, 2022 0 171 viewsCyber Security News Dwelling › Virus & ThreatsIranian Hackers Ship New ‘Fantasy’ Wiper to Diamond Business through Provide Chain AssaultBy Ionut Arghire on December 08, 2022TweetAn Iran-linked superior persistent risk (APT) actor named Agrius is utilizing a brand new wiper in assaults focusing on entities in South Africa, Israel and Hong Kong, cybersecurity agency ESET studies.Primarily centered on victims in Israel and the United Arab Emirates, Agrius is a risk actor energetic since at the least 2020, exploiting recognized vulnerabilities for preliminary entry.The adversary was beforehand seen utilizing the Apostle wiper disguised as ransomware, and later updating the malware right into a fully-fledged ransomware. Dubbed Fantasy, the newly recognized wiper is constructed based mostly on Apostle, however doesn’t try to masquerade as ransomware.As a part of the not too long ago noticed assaults, Agrius focused an Israeli software program developer that gives a software program suite to organizations within the diamond trade. The availability chain assault allowed the risk actor to contaminate the developer’s prospects with the brand new Fantasy wiper.Fantasy was first used towards a diamond trade agency in South Africa in March 2022, roughly three weeks after the group was contaminated with credential-harvesting instruments, seemingly in preparation for the wiping assault.After performing reconnaissance and lateral motion, Agrius deployed a Fantasy execution device dubbed Sandals, and launched the wiper. Written in C# and .NET, Fantasy and Sandals have been then each utilized in assaults towards victims in Israel and Hong Kong.ESET recognized 5 Fantasy victims, together with a diamond wholesaler, an HR consulting agency, and an IT help providers supplier in Israel, the South African group from the diamond trade, and a jeweler in Hong Kong.All victims have been prospects of the software program developer, the Fantasy wiper was named equally with the reputable software program, and the wiper was executed on all sufferer programs from the Temp listing, inside a 2.5 hours timeframe. All victims seemingly already used PsExec, which Agrius employed to mix in.The assault lasted lower than three hours, with the software program developer pushing out clear updates solely hours later. ESET says that it tried to contact the software program developer in regards to the potential compromise, nevertheless it obtained no response.Different instruments deployed through the assault embody MiniDump (for credential harvesting from LSASS dumps), SecretsDump (hashes dumper), and Host2IP (hostname resolver).Delicate data akin to usernames, passwords, and hostnames harvested utilizing these instruments have been then utilized by Sandals for lateral motion and for the wiper’s execution.“Sandals doesn’t write the Fantasy wiper to distant programs. We imagine that the Fantasy wiper is deployed through a supply-chain assault utilizing the software program developer’s software program replace mechanism,” ESET notes.Fantasy’s wiping routine includes changing the contents of focused information after which deleting these information. The wiper additionally clears all Home windows occasion logs, makes an attempt to delete all information on the system drive, to clear file system cache reminiscence, and to overwrite the system’s Grasp Boot File, and deletes itself.Most of Fantasy’s code base is straight copied from Apostle, with lots of its capabilities solely barely modified from Apostle, and with many execution move similarities additionally noticed, indicating that Agrius is behind this malware as properly, ESET notes.Associated: New Iranian Group ‘Agrius’ Launches Damaging Cyberattacks on Israeli TargetsAssociated: Non secular Minority Persecuted in Iran Focused With Refined Android Spy wareAssociated: Iran Arrests Information Company Deputy After Reported CyberattackGet the Each day Briefing Most CurrentMost LearnEradicating the Obstacles to Safety Automation ImplementationApple Scraps CSAM Detection Software for iCloud ImagesVulnerabilities Enable Researcher to Flip Safety Merchandise Into WipersWAFs of A number of Main Distributors Bypassed With Generic Assault TechniqueIranian Hackers Ship New ‘Fantasy’ Wiper to Diamond Business through Provide Chain AssaultLighting Big Acuity Manufacturers Discloses Two Information BreachesTikTok Hit by US Lawsuits Over Youngster Security, Safety FearsCloudSEK Blames Hack on One other Cybersecurity FirmPwn2Own Toronto 2022, Day 2: Sensible Speaker Exploits Earn Massive Chunk of $280,000 CompleteApple Including Finish-to-Finish Encryption to iCloud BackupIn search of Malware in All of the Mistaken Locations?First Step For The Web’s subsequent 25 years: Including Safety to the DNSTattle Story: What Your Laptop Says About YouBe in a Place to Act By way of Cyber Situational ConsciousnessReport Reveals Closely Regulated Industries Letting Social Networking Apps Run Rampant2010, A Nice Yr To Be a Scammer.Do not Let DNS be Your Single Level of FailureHow you can Determine Malware in a BlinkDefining and Debating Cyber WarfareThe 5 A’s that Make Cybercrime so EngagingHow you can Defend Towards DDoS AssaultsSafety Budgets Not in Line with ThreatsAnycast – Three Causes Why Your DNS Community Ought to Use ItThe Evolution of the Prolonged Enterprise: Safety Methods for Ahead Considering OrganizationsUtilizing DNS Throughout the Prolonged Enterprise: It’s Dangerous Enterprise Agrius Apostle Fantasy Sandals supply chain attack wiper Orbit Brainhttp://orbitbrain.com/ Orbit Brain is the senior science writer and technology expert. Our aim provides the best information about technology and web development designing SEO graphics designing video animation tutorials and how to use software easy waysand much more. Like Best Service Latest Technology, Information Technology, Personal Tech Blogs, Technology Blog Topics, Technology Blogs For Students, Futurism Blog.
Adobe Plugs 46 Security Flaws on Patch TuesdayIntroducing the Cyber Security News Adobe Plugs 46 Security Flaws on Patch Tuesday.... June 14, 2022 Cyber Security News
Australian Health Insurer Medibank Admits Customer Data Stolen in Ransomware AttackIntroducing the Cyber Security News Australian Health Insurer Medibank Admits Customer Data Stolen in Ransomware Attack.... October 20, 2022 Cyber Security News
Mitigation for ProxyNotShell Exchange Vulnerabilities Easily BypassedIntroducing the Cyber Security News Mitigation for ProxyNotShell Exchange Vulnerabilities Easily Bypassed.... October 4, 2022 Cyber Security News
Zoho Urges ManageEngine Users to Patch Serious SQL Injection VulnerabilityIntroducing the Cyber Security News Zoho Urges ManageEngine Users to Patch Serious SQL Injection Vulnerability.... January 5, 2023 Cyber Security News
Bishop Fox Lands $75 Million Series B FundingIntroducing the Cyber Security News Bishop Fox Lands $75 Million Series B Funding.... July 14, 2022 Cyber Security News
Google Reveals Spyware Vendor’s Use of Samsung Phone Zero-Day ExploitsIntroducing the Cyber Security News Google Reveals Spyware Vendor’s Use of Samsung Phone Zero-Day Exploits.... November 9, 2022 Cyber Security News