Quantcast
Channel: ClearSky Cyber Security
Browsing index pages (59 articles)
↧

Image may be NSFW.
Clik here to view.

Exposing a Russian Campaign Targeting Ukraine Using New Malware Duo: BadPaw...

ClearSky Team has identified a targeted Russian cyber campaign against Ukraine utilizing twonovel malware strains, BadPaw and MeowMeow. The attack chain initiates with a phishing email containing a...

View Article


Houthi Influence Campaign

In early April, ClearSky’s team discovered a persistent Yemeni/Houthi influence campaignoperating in Israel and the Gulf states. We first exposed the campaign in 2019. It continuesto operate in a...

View Article


CVE-2024-43451: A New Zero-Day Vulnerability Exploited in the wild

A new zero-day vulnerability, CVE-2024-43451, was discovered by ClearSky Cyber Security in June 2024. This vulnerability affects Windows systems and is being actively exploited in attacks against...

View Article

Iranian “Dream Job” Campaign 11.24

ClearSky Cyber Security research identified a campaign named “Iranian Dream Job campaign”, in which the Iranian threat actor TA455 targeted the aerospace industry by offering fake jobs.  The campaign...

View Article

Doppelgänger NG | Russian Cyberwarfare campaign

ClearSky Cyber Security and SentinelLabs have discovered a new wave of Russian information warfare campaign named Doppelgänger NG. “Doppelgänger” (meaning spirit double, an exact but usually invisible...

View Article


Image may be NSFW.
Clik here to view.

“Homeland Justice” targets Albanian organizations with “No-justice” wiper

This blog post will elaborate on “Homeland justice” group’s background and provide an in-depth analysis of the tools used in the current attack, including reverse engineering of the NACL executable –...

View Article

Fata Morgana: Watering hole attack on shipping and logistics websites

ClearSky Cyber Security has detected a watering hole attack on at least eight Israeli websites. The attack is highly likely to be orchestrated by a nation-state actor from Iran, with a low confidence...

View Article

Lyceum suicide drone

ClearSky discovered a new malware associated with the Iranian SiameseKitten (Lyceum) group withmedium-high confidence.The file is downloaded from a domain registered on June 6th, and it communicates...

View Article


EvilNominatus Ransomware

As part of our monitoring of malicious files in current use, we detected a malicious BAT file that was uploaded to VirusTotal from Iran. This file executes a ransomware that we associated with the...

View Article


New Iranian Espionage Campaign By “Siamesekitten” – Lyceum

At the beginning of May 2021, we detected the first attack by Siamesekitten on an IT company in Israel. Siamesekitten (also named Lyceum/Hexane) is an Iranian APT group active in the Middle east and...

View Article

Attributing CryptoCore Attacks Against Crypto Exchanges to LAZARUS (North Korea)

CryptoCore is an attack campaign against crypto-exchange companies that has been ongoing for three years and was discovered by ClearSky researchers. This cybercrime campaign is focused mainly on the...

View Article

Image may be NSFW.
Clik here to view.

CONTI Ransomware – Negotiation and Bitcoin Tracking

Originated by the ‘Wizard Spider’ Russian hacking group, CONTI ransomware is an evolution of one of the group’s most successful ransomware – Ryuk. CONTI is a more accessible version of Ryuk, built for...

View Article

Image may be NSFW.
Clik here to view.

‘Lebanese Cedar’ APT

In early 2020, suspicious network activities and hacking tools were found in a range of companies. Comprehensive forensic research of the infected systems revealed a strong connection to a threat...

View Article


Image may be NSFW.
Clik here to view.

Operation ‘Kremlin’

Introduction ClearSky researchers identified a malicious “.docx” file that was uploaded to VirusTotal from Russia in mid-December. The file contains an obfuscated URL to a remote template which...

View Article

Image may be NSFW.
Clik here to view.

Pay2Kitten – Fox Kitten 2

During the past four months a wave of cyber-attacks has been targeting Israeli companies. The attacks are conducted by different means and target a range of sectors. We estimate with medium to high...

View Article


Image may be NSFW.
Clik here to view.

Operation Quicksand

During September 2020, we identified a new campaign targeting many prominent Israeli organizations. The campaign was attributed to the Iranian threat actor ‘MuddyWater’ (also known as TEMP.Zagros,...

View Article

Image may be NSFW.
Clik here to view.

The Kittens Are Back in Town 3

During 2017-2019, Clearsky had published several reports about the Iranian APT group “Charming Kitten”. One of the group’s most common attack vectors is impersonating journalists, particularly those...

View Article


Image may be NSFW.
Clik here to view.

Operation ‘Dream Job’ Widespread North Korean Espionage Campaign

During June-August of 2020, ClearSky’s analysis team had investigated an offensive campaign attributed with high probability to North Korea, which we call “Dream Job”. This campaign has been active...

View Article

Image may be NSFW.
Clik here to view.

CryptoCore Group

A Threat Actor Targeting Cryptocurrency Exchanges In this research, we present a hidden and persistent group, that has been targeting crypto-exchanges, mainly in the US and Japan since as early as...

View Article

ClearSky Q1 summary report

We have published our quarterly report for the first quarter of 2020. We mark the outbreak of the COVID-19 virus as a systematic change for most businesses around the world. The immense pressure felt...

View Article
Browsing index pages (59 articles)


Latest Images