privacysavvy

privacysavvy

Tuesday, August 1, 2023

[New post] Recent highlights of the week’s cyber attacks – A summary

Site logo image The Art of Cyber-Space posted: " In today's technologically driven era, the cyber landscape is a dynamic and relentless battlefield. As we traverse the digital realm, the threats posed by cyber attacks continue to mutate and adapt, challenging our ability to stay ahead of the curve. Fro" The Art Of Cyber-Space

Recent highlights of the week's cyber attacks – A summary

The Art of Cyber-Space

Aug 1

In today's technologically driven era, the cyber landscape is a dynamic and relentless battlefield. As we traverse the digital realm, the threats posed by cyber attacks continue to mutate and adapt, challenging our ability to stay ahead of the curve. From nation-state hacking to sophisticated ransomware campaigns and social engineering exploits, the arsenal of cyber adversaries seems boundless. In the past week, quite a few notable attacks have come to limelight, the most prominent one being Israel's largest oil refineries, APT 31 attacking air gapped systems in Eastern Europe and some interesting insights around Space Pirates Cyber campaign across Russia. This post highlights the attack details with the associated TTPs

According to Bleeping Computer, Website of Israel's largest oil refinery operator, BAZAN Group is inaccessible from most parts of the world as threat actors claim to have hacked the Group's cyber systems. A backdrop about BAZANgroup: located in the Haifa Bay area and is one of the most complex and largest energy groups in Israel. It operates a refinery and is a petrochemical conglomerate. Approximately 70% of the Company's products are distributed in the Israeli market and the remainder in international markets (with an emphasis on countries in the eastern Mediterranean. In terms of the attack, during the weekend, BAZAN Group's websites, namely bazan.co.il and eng.bazan.co.il, experienced significant issues with incoming traffic. Many visitors encountered timeouts and HTTP 502 errors, while others were denied access by the company's servers. Bleeping computer has suggested that " BAZAN may have implemented a geo-block as a defensive measure against an ongoing cyber attack." Interestingly, on a telegram channel, Cyber Avengers aka Cybe3rAv3ngers (Iranian hacktivists) claimed that it had breached BAZAN's network over the weekend. Additionally, it had also leaked images of the SCADA systems including diagrams of "Flare Gas Recovery Unit," "Amine Regeneration" system, a petrochemical "Splitter Section," [Source]

APT 31 is a sophisticated Chinese state-sponsored cyber espionage group, also known as Zirconium or Judgment Panda has been known to conduct targeted attacks on governments, organizations, and tech companies, focusing on intellectual property theft and information gathering for strategic advantages. This time around, they are suspected of being behind a series of attacks against industrial organizations in Eastern Europe that took place last year to siphon data stored on air-gapped systems. There have been resembelennces with respect to their tactics in the past. (Refer to this link here: APT31)

Kaspersky attributes the intrusions to APT31 (Bronze Vinewood, Judgement Panda, Violet Typhoon). The attacks involved more than 15 distinct implants, categorized by their abilities to establish remote access, gather sensitive data, and send it to the attackers' infrastructure. The attackers used a set of backdoors, including a malware family named FourteenHi with versatile features for file manipulation, command execution, reverse shell, and self-erasure from compromised hosts. Furthermore, discovered three first-stage backdoors used in cyber attacks by APT31. The backdoors are named MeatBall, with capabilities for process listing and file operations, and a third implant that uses Yandex Cloud for command-and-control. (Source)

Over the past year, the threat actor Space Pirates has targeted 16 organizations in Russia and Serbia, displaying innovative tactics and expanding its cyber arsenal. The group's primary objectives remain espionage and stealing confidential data, but it has diversified its interests and extended the scope of its attacks. The targets include government agencies, educational institutions, private security companies, aerospace manufacturers, agricultural producers, defense, energy, and healthcare firms in both countries. Space Pirates first came to light in May 2022, with a focus on the aerospace sector in Russia. It has been active since at least late 2019 and has ties to another adversary known as Webworm, as tracked by Symantec. Positive Technologies' analysis of the attack infrastructure has revealed the threat actor's interest in harvesting PST email archives as well as making use of Deed RAT, a malware artifact exclusively attributed to the adversarial collective.

These attacks attribute to an emerging trend of threat actors exploiting cloud services to evade detection. Kaspersky researchers also highlight the challenge of detecting and analyzing threats, as malicious code is concealed in encrypted form within separate binary data files and legitimate applications' memory. The necessity to exercise extreme precautions while managing cyber attacks has never been more critical. With ever-evolving cyber threats, advanced and persistent adversaries, and the increasing reliance on digital infrastructure, organizations must prioritize robust cybersecurity measures. Implementing proactive defense strategies, continuous monitoring, and employee training are essential to safeguard sensitive data, prevent financial losses, and protect reputation in the face of relentless cyber threats.

Comment
Like
Tip icon image You can also reply to this email to leave a comment.

Unsubscribe to no longer receive posts from The Art Of Cyber-Space.
Change your email settings at manage subscriptions.

Trouble clicking? Copy and paste this URL into your browser:
https://theartofcyberspace.wordpress.com/2023/08/01/recent-highlights-of-the-weeks-cyber-attacks-a-summary/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at August 01, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

Why do we overeat?

Exploring this question can go a long way towards improving your health. ͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏     ­͏   ...

  • [New post] Norwegian Black Metal Bands – Satanic or Psychotic?
    Dawn ...
  • [New post] After Announcing a New CEO, is Lordstown Motors Worth Buying?
    Editorial Team posted: "To improve its market reputation and streamline its operations, on Aug. 26 electric vehicle (EV) ma...
  • [New post] Estrazioni Lotto di oggi martedì 30 novembre 2021
    Redazione News posted: "Seguite su Cyberludus.com la diretta delle estrazioni di Lotto, 10eLotto e Superenalotto di martedì...

Search This Blog

  • Home

About Me

privacysavvy
View my complete profile

Report Abuse

Blog Archive

  • October 2025 (67)
  • September 2025 (79)
  • August 2025 (71)
  • July 2025 (89)
  • June 2025 (78)
  • May 2025 (95)
  • April 2025 (85)
  • March 2025 (78)
  • February 2025 (31)
  • January 2025 (50)
  • December 2024 (39)
  • November 2024 (42)
  • October 2024 (54)
  • September 2024 (83)
  • August 2024 (2665)
  • July 2024 (3210)
  • June 2024 (2908)
  • May 2024 (3025)
  • April 2024 (3132)
  • March 2024 (3115)
  • February 2024 (2893)
  • January 2024 (3169)
  • December 2023 (3031)
  • November 2023 (3021)
  • October 2023 (2352)
  • September 2023 (1900)
  • August 2023 (2009)
  • July 2023 (1878)
  • June 2023 (1594)
  • May 2023 (1716)
  • April 2023 (1657)
  • March 2023 (1737)
  • February 2023 (1597)
  • January 2023 (1574)
  • December 2022 (1543)
  • November 2022 (1684)
  • October 2022 (1617)
  • September 2022 (1310)
  • August 2022 (1676)
  • July 2022 (1375)
  • June 2022 (1458)
  • May 2022 (1297)
  • April 2022 (1464)
  • March 2022 (1491)
  • February 2022 (1249)
  • January 2022 (1282)
  • December 2021 (1663)
  • November 2021 (3139)
  • October 2021 (3253)
  • September 2021 (3136)
  • August 2021 (732)
Powered by Blogger.