Resources

STRIKE Team

Resource Library

Clear filters

Brute Force Attempts May Have Preceded Ransomware Attack on School District

Research

Brute Force Attempts May Have Preceded Ransomware Attack on School District
Executive Summary: Vice Society Ransomware Group Attack Following reports that an attack by the Vice Society ransomware group was responsible for disrupting a US school district’s operations, SecurityScorecard researchers reviewed available data from internal sources and strategic partnerships. SecurityScorecard’s platform revealed that the school district suffered from issues that our previous research found common among
Public Sector
STRIKE Team
Iran-Attributed Exploitation of Log4Shell Vulnerability

Research

Iran-Attributed Exploitation of Log4Shell Vulnerability
Executive Summary CISA and the FBI issued a joint advisory warning of ongoing exploitation of the Log4Shell vulnerability (CVE-2021-44228) on November 16. The advisory noted that an unspecified Iran-linked threat actor group had exploited the vulnerability during an intrusion into a Federal Civilian Executive Branch (FCEB) organization’s network earlier this year. SecurityScorecard STRIKE team investigated
Cyber Threat Intelligence
STRIKE Team
TTPs Associated With a New Version of the BlackCat Ransomware

Blog

TTPs Associated With a New Version of the BlackCat Ransomware
In this post, we describe a real engagement that we recently handled by giving details about the tools, techniques, and procedures (TTPs) used by this threat actor.
Cyber Threat Intelligence
STRIKE Team
Analysis of APT35 infrastructure reveals interest in Egyptian Shipping Companies

Blog

Analysis of APT35 infrastructure reveals interest in Egyptian Shipping Companies
Executive Summary SecurityScorecard has identified domains resolving to Iran-linked Advanced Persistent Threat (APT) infrastructure, likely to be used to support phishing campaigns against Egypt-based shipping and marine services companies. In at least three instances, Iran-linked APT actors may have gained unauthorized access to the DNS configuration of legitimate domains to create rogue subdomains. CNAME records
STRIKE Team
A Deep Dive Into Black Basta Ransomware

Research

A Deep Dive Into Black Basta Ransomware
Executive Summary of Black Basta Ransomware Black Basta ransomware is a recent threat that compiled its first malware samples in February 2022. The ransomware deletes all Volume Shadow Copies, creates a new JPG image set as the Desktop Wallpaper and an ICO file representing the encrypted files. Unlike other ransomware families, the malware doesn’t skip
STRIKE Team
Was the Explosion at Freeport LNG a Result of a Russian Cyber Attack?

Blog

Was the Explosion at Freeport LNG a Result of a Russian Cyber Attack?
Executive Summary On June 8, an explosion–which some commentators hypothesized was the result of a Russian cyber attack–took place at Freeport LNG’s liquefied natural gas (LNG) export facility in Quintana, Texas. SecurityScorecard’s platform revealed a number of vulnerabilities an attacker could have exploited. SecurityScorecard researchers observed some traffic involving Freeport IP space that may have
STRIKE Team
A Detailed Analysis of the RedLine Stealer

Research

A Detailed Analysis of the RedLine Stealer
Executive Summary: What is Redline Stealer? RedLine is a stealer distributed as cracked games, applications, and services. The malware steals information from web browsers, cryptocurrency wallets, and applications such as FileZilla, Discord, Steam, Telegram, and VPN clients. The binary also gathers data about the infected machine, such as the running processes, antivirus products, installed programs,
STRIKE Team
KillNet Utilizes CC-Attack: A Quick & Dirty DDoS Method

Blog

KillNet Utilizes CC-Attack: A Quick & Dirty DDoS Method
SecurityScorecard’s analysis of CC-Attack reveals the script automates the process of using open proxy servers to relay attacks.
Cyber Threat Intelligence
STRIKE Team
JBS Ransomware Attack Started in March and Much Larger in Scope than Previously Identified

Blog

JBS Ransomware Attack Started in March and Much Larger in Scope than Previously Identified
SecurityScorecard found that the JBS ransomware attack started in March and is much larger in scope than previously identified. Check out SecurityScorecard’s research.
Cyber Threat Intelligence
STRIKE Team