← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Miscellaneous Sectors Cyber Threat Intel - Key Insights (February 2022)
In February, a ransomware attack was abusing Microsoft Exchange vulnerabilities for gaining initial access. The ransomware group was identified as UNC2596 and malware was detected as COLDDRAW (commonly known as Cuba).
Other Major Incidents
TA402 threat actor was found using a NimbleMamba implant. The Dridex bot was found spreading the Entropy ransomware. Gamaredon was using spear-phishing emails aimed at Ukrainian organizations. One of the flaws in Apple iOS was used by a surveillance firm, QuaDream. Attacks were observed delivering the Micropsia malware developed by the Arid Viper APT. The National Math and Science Initiative had a security breach. The Internet Society blamed the exposure of personal data on a third-party vendor. The News Corp. was hacked and data was stolen from journalists and employees. A cyber attack had targeted the Oiltanking GmbH Group.
Indicators of Compromise (10 / 303 total)
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| URL | http://deangelomcnay.news/qWIlIdKf2buIH0k/GbrHoIfRqtE69hH/ZCgbo9EVhYMA8PX | — | 2022-03-14 | |
| URL | http://deangelomcnay.news/qWIlIdKf2buIH0k/GbrHoIfRqtE69hH/bu5EmpJE7DUfzZD | d5a89e26beae0bc03ad18a0b0d1d3d75f87c32047879d25da11970cb5c4662a3 | 2022-03-14 | |
| URL | http://dorothymambrose.live/hx3FByTR5o3zNZYD/sYkaiHz0Mse13C79dy1I/ | — | 2022-03-14 | |
| URL | http://earlahenry.com/Ct2azbEP57LtWgmK/lWaPwemAJ3LPFmDH/ | — | 2022-03-14 | |
| URL | http://juliansturgill.info/um2NxySaF4L5mSYE/KY1hNeVvrE1XCrKP/ | — | 2022-03-14 | |
| URL | http://nicholasuhl.website/X2EYSWlzSZgSUME210Zv/YPPV6kFl2PwwF0TEVHMy/ | — | 2022-03-14 | |
| URL | https://cooperron.me/qWIlIdKf2buIH0k/GbrHoIfRqtE69hH/ | — | 2022-03-14 | |
| URL | https://dorothymambrose.live/hx3FByTR5o3zNZYD/sYkaiHz0Mse13C79dy1I/ | — | 2022-03-14 | |
| URL | https://earlahenry.com/Ct2azbEP57LtWgmK/lWaPwemAJ3LPFmDH/ | — | 2022-03-14 | |
| URL | https://nicholasuhl.website/X2EYSWlzSZgSUME210Zv/YPPV6kFl2PwwF0TEVHMy/ | — | 2022-03-14 |