Microcin is here
#1
Bug 
Quote:
[Image: sl_microcin_02.png]

With asynchronous sockets, steganography, GitLab ban and a sock In February 2020, we observed a Trojan injected into the system process memory on a particular host. The target turned out to be a diplomatic entity. What initially attracted our attention was the enterprise-grade API-like (application programming interface) programming style. Such an approach is not that common in the malware world and is mostly used by top-notch actors.

Due to control server reuse (Choopa VPS service), target profiling techniques and code similarities, we attribute this campaign with high confidence to the SixLittleMonkeys (aka Microcin) threat actor. Having said that, we should note that they haven’t previously applied the aforementioned coding style and software architecture. During our analysis we didn’t observe any similar open source tools, and we consider this to be the actor’s own custom code.

SixLittleMonkeys’ sphere of interest remains the same – espionage against diplomatic entities. The actor is still also using steganography to deliver configuration data and additional modules, this time from the legitimate public image hosting service cloudinary.com. The images include one related to the notorious GitLab hiring ban on Russian and Chinese citizens. In programming terms, the API-like architecture and asynchronous work with sockets is a step forward for the actor.
...
Continue Reading
Reply


Messages In This Thread
Microcin is here - by harlan4096 - 23 June 20, 06:51

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.6.0 Added Conn...Kool — 13:39
AMD Radeon RX 9070 GRE launches June 1st...
AMD Radeon RX 9070...harlan4096 — 10:19
uBOLite 2026.529.1448 (already available...
uBOLite 2026.529.1...harlan4096 — 08:05
Microsoft Edge 148.0.3967.96
Version 148.0.3967...harlan4096 — 08:02
Brave 1.90.128 (Chromium 148.0.7778.217)
Release v1.90.128 ...harlan4096 — 08:01

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (42)tapedDow
avatar (48)BrantgoG
avatar (50)eapedDow
avatar (47)Carlosskake
avatar (49)rapedDow
avatar (44)Johnsonsyday
avatar (49)Groktus
avatar (41)efodo
avatar (39)Tedscolo
avatar (46)brakasig
avatar (51)smudloquask
avatar (46)benchJem
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (42)zacforat
avatar (47)NemrokReks
avatar (50)Jasoncedia
avatar (38)Barrackleve
avatar (40)Julioagopy
avatar (50)aolaupitt2558
avatar (48)vadimTob
avatar (38)leannauu4
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (51)nteriageda
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>