logo
Kaspersky discovered cyberattacks that sourced information from GitHub, Quora, and social networks to target organizations

Kaspersky discovered cyberattacks that sourced information from GitHub, Quora, and social networks to target organizations

Biz Bahrain02-08-2025
Kaspersky detected a complex attack sequence that involved retrieving information from legitimate services such as GitHub, Microsoft Learn Challenge, Quora, and social networks. The attackers did this to avoid detection and run an execution chain to launch Cobalt Strike Beacon, a tool to remotely control computers, execute commands, steal data, and maintain persistent access within a network. The attacks were detected in the second half of 2024 in organizations across China, Japan, Malaysia, Peru and Russia, and persisted into 2025. The majority of victims were large to medium-sized businesses. To infiltrate victims' devices, the attackers sent spear phishing emails which were disguised as legitimate communications from major state-owned companies, particularly within the oil and gas sector. The text was phrased to look like there was interest in products and services of the victim organization to convince the recipient to open the malicious attachment. The attachment was an archive with what looked like PDF files containing requirements for the requested products and services – but in fact some of these PDFs were executable EXE and DLL files containing malware.
The attackers leveraged DLL highjacking techniques and exploited the legitimate Crash reporting Send Utility which is originally designed to help developers get detailed, real-time crash reports for their applications. To function, the malware also retrieved and downloaded a code that was stored in public profiles on popular legitimate platforms to avoid detection. Kaspersky found this code encrypted inside profiles on GitHub, and links to it (also encrypted) – on other GitHub profiles, Microsoft Learn Challenge, Q&A websites, and even Russian social media platforms. All of these profiles and pages were created specifically for this attack. After the malicious code was executed on victims' machines, Cobalt Strike Beacon was launched, and the victims' systems were compromised.
'While we didn't find any evidence of the attackers using real people's social media profiles, as all the accounts were created specifically for this attack, there's nothing stopping the threat actor from abusing various mechanisms these platforms provide. For instance, malicious content strings could be posted in comments on legitimate users' posts. Threat actors are using increasingly complex methods to conceal long-known tools, and it's important to stay up to date with the latest threat intelligence to be protected from such attacks,' comments Maxim Starodubov, Malware Analyst Team Lead at Kaspersky. The method used to retrieve the download address for the malicious code is similar to what was observed in the EastWind campaign linked to Chinese-speaking actors. Kaspersky recommends that organizations follow these security guidelines to stay safe: • Track the status of digital infrastructure and continuously monitor the perimeter. • Use proven security solutions to detect and block malware embedded within bulk email. • Train staff to increase cybersecurity awareness.
• Secure corporate devices with a comprehensive system, such as Kaspersky Next, that detects and blocks attacks in the early stages.
Orange background

Try Our AI Features

Explore what Daily8 AI can do for you:

Comments

No comments yet...

Related Articles

UN to boost air parcel security a year after DHL depot explosions
UN to boost air parcel security a year after DHL depot explosions

Daily Tribune

time05-08-2025

  • Daily Tribune

UN to boost air parcel security a year after DHL depot explosions

AFP | Montreal The United Nations yesterday announced plans to enhance air mail security, one year after parcels exploded at DHL depots in Germany and Britain, in a plot blamed on Russia. The strategy announced by the International Civil Aviation Organization (ICAO) and Universal Postal Union -- two specialized UN agencies -- aims to improve threat detection, officials told AFP. European intelligence services believe Russia was behind the explosions last July at DHL depots in Leipzig, Germany and Birmingham in Britain. Several people implicated in the operation were believed to be 'disposable' agents with no official position in the Russian intelligence services, according to German media reports. Such low-level agents were typically recruited via messaging apps to carry out tasks for money, the reports said. German intelligence officials have said the planes carrying the parcels would have crashed had they exploded mid-flight. Canada-based ICAO's head of aviation security, Sonia Hifdi, did not directly name Russia when laying out the plan, but said: 'In the last 12 months, we have seen more sophisticated actors aiming to cause disruptions in the supply chain.' The joint 'multi-year action plan' strives to train all personnel who handle air mail, and will work towards increased data sharing between postal and aviation authorities.

Freight Train Crashes Into Tourist Bus Near St. Petersburg, Leaving One Dead
Freight Train Crashes Into Tourist Bus Near St. Petersburg, Leaving One Dead

Daily Tribune

time04-08-2025

  • Daily Tribune

Freight Train Crashes Into Tourist Bus Near St. Petersburg, Leaving One Dead

A tragic accident occurred early Monday near the Russian city of St. Petersburg when a freight train collided with a tourist bus at a level crossing. Officials confirmed that one person was killed and 11 others were injured. The crash happened at around 3:00 a.m. GMT in northwestern Russia. Authorities said the bus was on the tracks when the train struck it at full speed. According to the railway company, the train driver attempted to brake but could not stop in time to avoid the collision. Emergency responders rushed to the scene, and the injured passengers were taken to nearby hospitals. Investigations are underway to determine why the bus was on the tracks. Traffic violations remain a frequent cause of deadly accidents in Russia.

US Imposes Sweeping New Sanctions On Iranian Shipping Network
US Imposes Sweeping New Sanctions On Iranian Shipping Network

Gulf Insider

time02-08-2025

  • Gulf Insider

US Imposes Sweeping New Sanctions On Iranian Shipping Network

The US Treasury Department has announced new sanctions targeting the global shipping interests reportedly controlled by Mohammad Hossein Shamkhani, son of senior Iranian official Ali Shamkhani, in what it described as the most significant Iran-related action since 2018. The sanctions aim to dismantle what Treasury officials called a 'vast network' used to sell Iranian and Russian oil through container ships and tankers operated by front companies and intermediaries. The network, they said, generated tens of billions of dollars used to support the Iranian government. 'These profits have helped prop up the Iranian regime,' the Treasury stated, accusing Shamkhani of leveraging corruption and personal connections in Tehran to evade existing restrictions. In total, the action designates 15 shipping firms, 52 vessels, 12 individuals, and 53 entities involved in sanctions evasion, with operations spanning 17 countries, including Panama, Italy, Hong Kong, the UAE, and the UK. A US official said the measure was 'tailored' to avoid disrupting global oil markets while striking specific targets. 'From our perspective, given where this individual fits, given his connection to the supreme leader and his father's previous sanctions activities, given the Iran-related authorities, it's critically important to emphasize that this is an Iran action that is meaningful and very impactful,' the official said. The EU sanctioned Shamkhani earlier in July for his role in the Russian oil trade, and his father, Ali Shamkhani, was sanctioned by the US in 2020. Tehran condemned the decision as a hostile move, with Foreign Ministry spokesperson Esmail Baghaei calling it a 'blatant assault on the Iranian people and their national dignity,' adding that it reflected 'the hostility of American policymakers towards the Iranian people.' He accused Washington of seeking to 'cripple Iran's development, sow internal discord, and erode the rights and livelihoods of ordinary citizens.' 'The Iranian people, fully aware of the malicious intent of the aggressive sanctioning party …, will stand firm with all their might to safeguard their dignity and interests,' Baghaei said. He criticized the US's 'addiction' to unilateralism and said its measures repeatedly violated 'international law, human rights, and freedom of sovereign trade.' He called for international accountability and reaffirmed Iran's 'unshakeable resolve' to defend its sovereignty and continue its development goals. Sanctioned entities include Sepehr Energy Jahan Nama Pars Company, linked to Iran's Armed Forces General Staff. Among the targeted vessels are Bendigo, Carnatic, Luna Prime, Goodwin, Davina, and Spirit of Casper.

DOWNLOAD THE APP

Get Started Now: Download the App

Ready to dive into a world of global content with local flavor? Download Daily8 app today from your preferred app store and start exploring.
app-storeplay-store