{"id":4962,"date":"2020-08-26T09:41:27","date_gmt":"2020-08-25T21:41:27","guid":{"rendered":"https:\/\/kinetics.co.nz\/?p=4962"},"modified":"2020-08-26T09:41:27","modified_gmt":"2020-08-25T21:41:27","slug":"is-deathstalker-coming-for-you","status":"publish","type":"post","link":"https:\/\/new.kinetics.co.nz\/?p=4962","title":{"rendered":"Is &#8220;Deathstalker&#8221; coming for you?"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; admin_label=&#8221;section&#8221; _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_row admin_label=&#8221;row&#8221; _builder_version=&#8221;4.16&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221; theme_builder_area=&#8221;post_content&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.16.1&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; theme_builder_area=&#8221;post_content&#8221; sticky_enabled=&#8221;0&#8243;]<a href=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2020\/08\/deathstalker-scorpion_1_orig.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-4967\" src=\"http:\/\/kinetics.co.nz\/wp-content\/uploads\/2020\/08\/deathstalker-scorpion_1_orig-300x300.jpg\" alt=\"\" width=\"200\" height=\"199\" \/><\/a>Cyber-Crime is big business.\u00a0 The criminals are organised and sophisticated.\u00a0 Imagine if they put their ingenuity to things that are good?\u00a0 But alas, that&#8217;s not reality.\u00a0 Instead we have to brace ourselves to deal with another wave of crime.<\/p>\n<p>Deathstalker is a such a great name, inspiring fear.\u00a0 In fact, <a href=\"https:\/\/www.scorpionworlds.com\/deathstalker-scorpion\/\" target=\"_blank\" rel=\"noopener\">Deathstalkers are a type of scorpion<\/a>.\u00a0 I desperately wanted to find out that they were misnamed and quite pleasant but actually they seem like quite nasty, cannibalistic little characters.<\/p>\n<p>Most of the information we can find on this threat comes from Kaspersky and we haven&#8217;t been able to verify this with other sources.\u00a0 However it is sufficiently worrying that we wanted to bring it to your attention.<\/p>\n<h2>These hackers are targeting LEGAL and FINANCIAL services firms<\/h2>\n<p>They want to steal information to sell, or they will act as mercenaries and attack on demand.<\/p>\n<p>They start by using a <a href=\"http:\/\/kinetics.co.nz\/spearphishing-aka-whaling\/\" target=\"_blank\" rel=\"noopener\">phishing attack<\/a> (targeting the victim with a hand-crafted email that tempts you to open it) to entice the victim to open an apparently innocent file that is actually a hidden powershell script (LNK) . Of course, the victim doesn&#8217;t know that &#8211; they think its something they need to read &#8211; a candidate CV, remittance advice, or a purchase order, or a letter of some sort.<\/p>\n<p><strong>Introducing the Dead-Drop-Resolver<\/strong><\/p>\n<p>The malicious code points to a public, trusted site.\u00a0 These appear to be legitimate, like pointing to a seemingly innocent YouTube video that has a comment which happens to include some weird sequence of characters that is actually the code that instructs or triggers the malicious code.\u00a0 \u00a0 This code is enough to tell the malware what to do, including launching further malware on the victim&#8217;s PC.<\/p>\n<p><strong>So, what can you do to reduce your risk?\u00a0<\/strong><\/p>\n<ul>\n<li>Phishing training<\/li>\n<li>Security Awareness briefings.<\/li>\n<li>Use of ATP tools to scan emails<\/li>\n<li>Advanced endpoint protection<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p>All of these are part of our<a href=\"http:\/\/kinetics.co.nz\/kare-for-security-s1\/\" target=\"_blank\" rel=\"noopener\">\u00a0KARE for Security service<\/a>, which <strong>we have begun to realise is now a minimum level of protection.<\/strong>\u00a0\u00a0We are working through offering a SOC and SEIM to complement this service, and we&#8217;re just trying to find a solution that meets NZ budgets.<\/p>\n<p>The other action we recommend is ensuring your IT engineer audits user rights and makes sure that no one has any excess access rights &#8211;<strong> the least access each user has, the least harm that can occur should they become infected.<\/strong><\/p>\n<p>&nbsp;<\/p>\n<h3>References<\/h3>\n<p><a href=\"https:\/\/www.fintechdirect.net\/2020\/08\/25\/deathstalker-cyberspy-group-menaces-fintech-sme\" target=\"_blank\" rel=\"noopener\">https:\/\/www.fintechdirect.net\/2020\/08\/25\/deathstalker-cyberspy-group-menaces-fintech-sme<\/a><\/p>\n<p><a href=\"https:\/\/cyberdailyreport.com\/news\/a0f10bb3dedea21466d7f51ea38eb83f\" target=\"_blank\" rel=\"noopener\">https:\/\/cyberdailyreport.com\/news\/a0f10bb3dedea21466d7f51ea38eb83f<\/a>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cyber-Crime is big business.\u00a0 The criminals are organised and sophisticated.\u00a0 Imagine if they put their ingenuity to things that are good?\u00a0 But alas, that&#8217;s not reality.\u00a0 Instead we have to brace ourselves to deal with another wave of crime. Deathstalker is a such a great name, inspiring fear.\u00a0 In fact, Deathstalkers are a type of [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":4967,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"<a href=\"http:\/\/mattp49.sg-host.com\/wp-content\/uploads\/2020\/08\/deathstalker-scorpion_1_orig.jpg\"><img class=\"alignright wp-image-4967\" src=\"http:\/\/mattp49.sg-host.com\/wp-content\/uploads\/2020\/08\/deathstalker-scorpion_1_orig-300x300.jpg\" alt=\"\" width=\"200\" height=\"199\" \/><\/a>Cyber-Crime is big business.\u00a0 The criminals are organised and sophisticated.\u00a0 Imagine if they put their ingenuity to things that are good?\u00a0 But alas, that's not reality.\u00a0 Instead we have to brace ourselves to deal with another wave of crime.\n\nDeathstalker is a such a great name, inspiring fear.\u00a0 In fact,[wow_colorme]\u00a0<a href=\"https:\/\/www.scorpionworlds.com\/deathstalker-scorpion\/\" target=\"_blank\" rel=\"noopener\">Deathstalkers are a type of scorpion<\/a>.[\/wow_colorme]\u00a0 I desperately wanted to find out that they were misnamed and quite pleasant but actually they seem like quite nasty, cannibalistic little characters.\n\nMost of the information we can find on this threat comes from Kaspersky and we haven't been able to verify this with other sources.\u00a0 However it is sufficiently worrying that we wanted to bring it to your attention.\n\n[header2 text=\"These hackers are targeting LEGAL and FINANCIAL services firms\" align=\"left\" color=\"#3ec940\" margintop=\"\"]\n\nThey want to steal information to sell, or they will act as mercenaries and attack on demand.\n\nThey start by using a[wow_colorme] <a href=\"http:\/\/kinetics.co.nz\/spearphishing-aka-whaling\/\" target=\"_blank\" rel=\"noopener\">phishing attack<\/a> [\/wow_colorme](targeting the victim with a hand-crafted email that tempts you to open it) to entice the victim to open an apparently innocent file that is actually a hidden powershell script (LNK) . Of course, the victim doesn't know that - they think its something they need to read - a candidate CV, remittance advice, or a purchase order, or a letter of some sort.\n\n<strong>[wow_colorme]Introducing the Dead-Drop-Resolver[\/wow_colorme]<\/strong>\n\nThe malicious code points to a public, trusted site.\u00a0 These appear to be legitimate, like pointing to a seemingly innocent YouTube video that has a comment which happens to include some weird sequence of characters that is actually the code that instructs or triggers the malicious code.\u00a0 \u00a0 This code is enough to tell the malware what to do, including launching further malware on the victim's PC.\n\n<strong>[wow_colorme]So, what can you do to reduce your risk?\u00a0[\/wow_colorme]<\/strong>\n<ul>\n \t<li>Phishing training<\/li>\n \t<li>Security Awareness briefings.<\/li>\n \t<li>Use of ATP tools to scan emails<\/li>\n \t<li>Advanced endpoint protection<\/li>\n<\/ul>\n[wow_spacing size=\"20px\"]\n\nAll of these are part of our[wow_colorme]<a href=\"http:\/\/kinetics.co.nz\/kare-for-security\/\" target=\"_blank\" rel=\"noopener\"> KARE for Security service<\/a>,[\/wow_colorme]\u00a0which <strong>we have begun to realise is now a minimum level of protection.<\/strong>\u00a0\u00a0We are working through offering a SOC and SEIM to complement this service, and we're just trying to find a solution that meets NZ budgets.\n\nThe other action we recommend is ensuring your IT engineer audits user rights and makes sure that no one has any excess access rights -<strong> the least access each user has, the least harm that can occur should they become infected.<\/strong>\n\n&nbsp;\n<h3>References<\/h3>\n[wow_colorme]\n\n<a href=\"https:\/\/www.fintechdirect.net\/2020\/08\/25\/deathstalker-cyberspy-group-menaces-fintech-sme\" target=\"_blank\" rel=\"noopener\">https:\/\/www.fintechdirect.net\/2020\/08\/25\/deathstalker-cyberspy-group-menaces-fintech-sme<\/a>\n\n<a href=\"https:\/\/cyberdailyreport.com\/news\/a0f10bb3dedea21466d7f51ea38eb83f\" target=\"_blank\" rel=\"noopener\">https:\/\/cyberdailyreport.com\/news\/a0f10bb3dedea21466d7f51ea38eb83f<\/a>\n\n&nbsp;\n\n[\/wow_colorme]\n\n&nbsp;\n\n&nbsp;","_et_gb_content_width":"","footnotes":""},"categories":[4,5],"tags":[],"class_list":["post-4962","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-security"],"_links":{"self":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/4962","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4962"}],"version-history":[{"count":0,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/wp\/v2\/posts\/4962\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=\/"}],"wp:attachment":[{"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4962"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4962"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/new.kinetics.co.nz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4962"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}