Tag Mandiant

Federal Authorities Indict Five Individuals Linked to Scattered Spider Cybercrimes

FBI Indicts Five Alleged Members of Cybercrime Group Linked to Cryptocurrency Thefts The U.S. government has unveiled charges against five individuals suspected to be affiliated with a loosely organized cybercriminal group known as "Scattered Spider." These charges, unsealed on November 20, 2024, stem from allegations that the group was responsible…

Read MoreFederal Authorities Indict Five Individuals Linked to Scattered Spider Cybercrimes

OPSEC Slip Exposes North Korean Nation-State Actors Behind JumpCloud Breach

On July 25, 2023, Cyber Threat Intelligence revealed that North Korean state-sponsored hackers connected to the Reconnaissance General Bureau (RGB) were linked to the JumpCloud breach due to a significant operational security (OPSEC) error that revealed their IP address. Google’s threat intelligence firm Mandiant has identified this group as UNC4899, which overlaps with known clusters like Jade Sleet and TraderTraitor—hackers notorious for targeting the blockchain and cryptocurrency sectors. Furthermore, UNC4899 shares connections with APT43, another hacking group affiliated with North Korea, previously exposed in March for conducting intelligence-gathering campaigns and stealing cryptocurrency from various companies. Their tactics include employing Operational Relay Boxes (ORBs) using L2TP IPsec tunnels along with commercial VPN services to conceal their identity.

North Korean State-Sponsored Hackers Identified in JumpCloud Breach Due to Operational Security Oversight On July 25, 2023, cybersecurity experts revealed that the recent breach of JumpCloud, a directory-as-a-service provider, has been linked to North Korean state-sponsored hackers associated with the Reconnaissance General Bureau (RGB). The inquiry into the attack found…

Read More

OPSEC Slip Exposes North Korean Nation-State Actors Behind JumpCloud Breach

On July 25, 2023, Cyber Threat Intelligence revealed that North Korean state-sponsored hackers connected to the Reconnaissance General Bureau (RGB) were linked to the JumpCloud breach due to a significant operational security (OPSEC) error that revealed their IP address. Google’s threat intelligence firm Mandiant has identified this group as UNC4899, which overlaps with known clusters like Jade Sleet and TraderTraitor—hackers notorious for targeting the blockchain and cryptocurrency sectors. Furthermore, UNC4899 shares connections with APT43, another hacking group affiliated with North Korea, previously exposed in March for conducting intelligence-gathering campaigns and stealing cryptocurrency from various companies. Their tactics include employing Operational Relay Boxes (ORBs) using L2TP IPsec tunnels along with commercial VPN services to conceal their identity.

FBI Cautions of $40M Cryptocurrency Heist Linked to North Korean Affiliates

The FBI has issued a warning that North Korean cyber actors may seek to liquidate more than $40 million in stolen cryptocurrency. This announcement surfaced on Tuesday amid ongoing investigations into recent blockchain activities linked to a group identified by U.S. authorities as TraderTraitor, also known colloquially as Jade Sleet.…

Read MoreFBI Cautions of $40M Cryptocurrency Heist Linked to North Korean Affiliates

Urgent: FBI Issues Warning About Vulnerabilities in Barracuda Email Gateways Even After Recent Patches

The Federal Bureau of Investigation (FBI) has issued a warning regarding the ongoing risk posed to Barracuda Networks Email Security Gateway (ESG) appliances, despite recent patches deployed in response to a critical vulnerability. This advisory indicates that while Barracuda has addressed the flaw, the devices remain susceptible to exploitation by…

Read MoreUrgent: FBI Issues Warning About Vulnerabilities in Barracuda Email Gateways Even After Recent Patches

Man Arrested for Snowflake Hacking Operation Faces Extradition to the US

The recent investigation by Mandiant, a cybersecurity arm of Google, has unveiled significant insights regarding the breach incidents attributed to a hacker identified as UNC5537. Austin Larsen, a threat intelligence analyst at Mandiant, characterizes this hacker as “one of the most consequential threat actors of 2024.” The repercussions of these…

Read MoreMan Arrested for Snowflake Hacking Operation Faces Extradition to the US

Iran-Linked Imperial Kitten Cyber Group Aiming at Middle Eastern Tech Industries

Iran-Linked Cyber Group Targets Middle Eastern Transportation and Tech Sectors Amid Increased Activity In October 2023, a cyber group with connections to Iran intensified its operations, focusing on the transportation, logistics, and technology sectors across the Middle East, including Israel. This uptick in Iranian cyber activity aligns with the escalation…

Read MoreIran-Linked Imperial Kitten Cyber Group Aiming at Middle Eastern Tech Industries

UNC5820 Exploits Zero-Day Vulnerability in FortiManager (CVE-2024-47575)

In a troubling development for cybersecurity, Fortinet, in collaboration with Mandiant, has uncovered a widespread exploitation of FortiManager devices linked to CVE-2024-47575. This vulnerability has compromised over 50 systems across various sectors, with the threat group known as UNC5820 leveraging the flaw to facilitate data theft and unauthorized access. The…

Read MoreUNC5820 Exploits Zero-Day Vulnerability in FortiManager (CVE-2024-47575)