Category: Security Operations

Providing Solutions

Rapid Response: The Squirrelwaffle Incident Guide

Squirrelwaffle is a malicious dropper or loader used to deliver other malware onto target systems. This guide shows Security Operations Centers (SOCs) and Incident Response Teams how to detect and respond to the presence of Squirrelwaffle on the network

Log4Shell: How the Attackers’ Faces Have Changed Over Time

Following an article on January 24, 2022 of Log4Shell scanning and attack detections since the bug was reported, Sophos addresses reader questions about who’s behind it all

Log4Shell: No Mass Abuse, But No Respite, What Happened?

Sophos reviews the scanning and attack detections for Log4Shell to see what’s really going on

Zloader Installs Remote Access Backdoors and Delivers Cobalt Strike

Zloader is a banking trojan with historical ties to the Zeus malware.  Recently, Egregor and Ryuk ransomware affiliates used Zloader for the initial point of entry. Zloader featured VNC remote access capabilities and was offered on the infamous Russian-speaking cybercrime forum exploit[.]in. Zloader infects users by leveraging malicious web advertising to redirect users into downloading…
Read more