Tim Brown

Results 258 issues of Tim Brown

Might be worth considering if we can merge these two concepts? I'm the author of the paper and patches referenced in that blog post... PS I'm aware that the SSL...

### Area Defensive tools ### Parent threat Command and Control ### Finding https://twitter.com/timb_machine/status/1523253031382687744 ### Industry reference uses:BPF attack:T1205:Traffic Signaling ### Malware reference BPFDoor Tricephalic Hellkeeper Unix.Backdoor.RedMenshen JustForFun https://github.com/timb-machine/linux-malware/issues/420 ### Actor...

confirmed

### Area Supply chain attacks ### Parent threat Impact ### Finding https://blog.sonatype.com/pypi-package-secretslib-drops-fileless-linux-malware-to-mine-monero ### Industry reference delivery:PyPI uses:Python attack:T1620:Reflective Code Loading attack:T1070.004:File Deletion attack:T1195.001:Compromise Software Dependencies and Development Tools ### Malware...

new

### Area Supply chain attacks ### Parent threat Impact ### Finding https://blog.sonatype.com/newly-found-npm-malware-mines-cryptocurrency-on-windows-linux-macos-devices ### Industry reference delivery:NPM uses:JavaScript attack:T1195.001:Compromise Software Dependencies and Development Tools ### Malware reference wltm ### Actor reference...

new

### Area Malware reports ### Parent threat Impact ### Finding https://blog.reversinglabs.com/blog/gwisinlocker-ransomware-targets-south-korean-industrial-and-pharmaceutical-companies ### Industry reference attack:T1486:Data Encrypted for Impact region:South Korea vertical:Pharmaceutical ### Malware reference Gwisin wltm ### Actor reference _No...

new

### Area Defensive techniques ### Parent threat Lateral Movement, Command and Control, Exfiltration ### Finding https://redcanary.com/blog/process-streams/ ### Industry reference uses:bash uses:ksh93 attack:T1059:Command and Scripting Interpreter attack:T1095:Non-Application Layer Protocol ### Malware...

confirmed

### Area Malware reports ### Parent threat _No response_ ### Finding https://www.intezer.com/blog/research/a-storm-is-brewing-ipstorm-now-has-linux-malware/ ### Industry reference _No response_ ### Malware reference IPStorm [/malware/binaries/Unix.Trojan.Ipstorm](../tree/main/malware/binaries/Unix.Trojan.Ipstorm) ### Actor reference _No response_ ### Component _No...

new

### Area Malware reports ### Parent threat Persistence, Command and Control ### Finding https://www.bitdefender.com/files/News/CaseStudies/study/376/Bitdefender-Whitepaper-IPStorm.pdf ### Industry reference uses:Go ### Malware reference IPStorm [/malware/binaries/Unix.Trojan.Ipstorm](../tree/main/malware/binaries/Unix.Trojan.Ipstorm) ### Actor reference _No response_ ### Component...

confirmed

### Area Malware reports ### Parent threat _No response_ ### Finding https://twitter.com/avastthreatlabs/status/1430527767855058949 ### Industry reference _No response_ ### Malware reference HCRootkit https://github.com/timb-machine/linux-malware/issues/491 ### Actor reference _No response_ ### Component Linux...

new
missing:tactics
missing:tag:T1005
missing:tag:T1048
missing:tag:T1071.001
missing:tag:T1567
missing:tag:T1573
missing:tag:T1027.002
missing:tag:T1560

### Area Malware PoCs ### Parent threat Persistence, Defense Evasion ### Finding https://github.com/mncoppola/suterusu ### Industry reference _No response_ ### Malware reference wltm ### Actor reference _No response_ ### Component Linux...

new