News

Latest news about B2B cyber security >>> PR agencies: add us to your mailing list - see contact! >>> Book an exclusive PartnerChannel for your news!

Microsoft 365 targeted by Russian hacker group APT29

New Mandiant research into the Russian hacker group APT29 behind the 2021 SolarWinds attack shows the attackers are adopting new tactics and continue to actively target Microsoft 365. APT29 has also been observed re-targeting previous victims - particularly those with influence or close ties to NATO countries. This shows that the cyber criminals are persistent, aggressive and with a lot of dedication to further develop their technical skills. Focus on Operational Security APT29 continues to demonstrate exceptional operational security and evasive tactics. In addition to using proxies in homes to provide their last access to victim environments…

Read more

Chinese disinformation campaign with HaiEnergy

New research from Mandiant reveals a Chinese disinformation campaign. Mandiant has christened this "HaiEnergy". The campaign distributes content on fake news sites. In addition to the websites in North America, Europe, the Middle East and Asia, the campaign also uses many social media that are strategically aligned with the political interests of the People's Republic of China. The HaiEnergy campaign uses 72 websites posing as independent news channels and publishing content in 11 languages. Mandiant analysts believe these websites are linked to Chinese PR firm Shanghai Haixun Technology Co. HaiEnergy:…

Read more

Mandiant expands XDR platform
Mandiant expands XDR platform

The new XDR solution, based on threat intelligence, helps companies to defend their digital assets, their supply chains and their brand against persistent cyber attacks. It also extends Mandiant Advantage's cross-vendor XDR platform. Mandiant, the leader in dynamic cyber defense and incident response, launches a new digital risk protection solution. This leverages Mandiant Advantage's cross-vendor XDR platform to provide a threat-intelligence-driven view of an organization's global attack surface and business-related activities across the deep web and dark web. The solution combines multiple modules from Mandiant...

Read more

Insights into the global cyber threat landscape
Insights into the global cyber threat landscape

Mandiant, the leader in dynamic cyber defense and incident response, releases the 2022 M-Trends findings on the cyber threat landscape. This is an annual report that provides up-to-date data and insights from the cyber frontline. The 2022 report covers the study period from October 1, 2020 to December 31, 2021. It shows that significant advances have been made in threat detection and response. But attackers are innovating and adapting to achieve their goals. Dwell time of attackers drops to three weeks According to the report M-Trends…

Read more

Hacker group FIN7 - still elusive

New research from Mandiant reveals that the financially motivated hacking group FIN7 has evolved its operations and is increasingly focusing on ransomware attacks believed to include MAZE, RYUK, DARKSIDE and ALPHV ransomware. Mandiant has now been able to link previous activities by other threat clusters to FIN7. These show that FIN7 has evolved to increase the speed of its operations, broaden the scope of its targets, and possibly even expand its relationships with other ransomware operations in the cybercriminal underground. Key Findings About FIN7 Since 2020, a total of eight previously classified groups of…

Read more

Bureau 325: North Korea and its state hacking
B2B Cyber ​​Security ShortNews

State-led hacker attacks are usually assigned to one of the "Big Four": Russia, China, Iran or North Korea. North Korea's early attacks were primarily directed at South Korea, but in recent years Western countries have also become targets of their financially motivated and espionage-related operations. Based on current research, Mandiant has compiled an overview of North Korean hacking groups and provides information about their connection to the North Korean government. Historically, most North Korean cyberattacks have been attributed to the notorious Lazarus group. New research suggests North Korea's government has various...

Read more

Trending Evil Q1 2022: 30 attack campaigns against the Log4j vulnerability

Trending Evil provides insights into the latest threats observed by Mandiant Managed Defense. The Trending Evil Q1 2022 report focuses on the ongoing impact of the Log4j /Log4Shell vulnerability and the proliferation of financially motivated attacks. 30 attack campaigns exploiting the Log4j vulnerability (CVE-2021-44228) are currently under surveillance, including activities by state attacker groups allegedly controlled by China and Iran. During the reporting period, Mandiant Managed Defense detected eleven different malware families used to exploit the Log4j / Log4Shell vulnerability. Trending Evil Q1 2022: The findings at a glance In addition, Managed Defense observed numerous financially…

Read more

Chinese hackers APT41 active unchecked

Mandiant Threat Intelligence monitors the Chinese hacker group APT41 and its activities. It is currently targeting US authorities, actively exploiting the Log4j vulnerability and vigorously distributing ransomware. In addition, Mandiant has gleaned new insights from an ongoing investigation into APT41, the Chinese hacker group conducting cyberespionage on behalf of MSS, China's civilian intelligence agency. APT41 targets US government agencies and Log4j vulnerability At least six US government agencies were compromised by exploiting vulnerabilities in internet-based web applications. Exploiting the infamous Log4j vulnerability just two days after the Apache Foundation disclosed it. Adaptation of the malware to…

Read more

Mandiant module assesses ransomware resilience

Mandiant helps organizations assess their ability to defend against ransomware attacks. The new Mandiant Advantage Ransomware Defense Validation offering provides security professionals with ongoing, secure, and measurable insight into their ability to defend against specific ransomware families. Mandiant, the leader in dynamic cyber defense and incident response, releases the Ransomware Defense Validation module within the Mandiant Advantage platform. It examines how well companies can fend off ransomware attacks. This includes answers to the question in which attack phase the security measures failed or were successful. Ransomware attack: Tool checks the ability to defend yourself Ransomware attacks have…

Read more

Analysis of DDoS attacks on Ukrainian facilities

Developments in Ukraine are putting concerns of serious cyberattacks in the spotlight of IT security professionals and businesses around the world. Mandiant shares first insights into recent DDoS attacks. A commentary by John Hultquist, VP, Intelligence Analysis at Mandiant. “It seems that DDOS attacks are being carried out against Ukrainian government and financial sector websites. There are indications that other financial systems, such as point-of-sale terminals, could be affected by disruptions. In another related incident, Ukraine Cyber ​​Police have stated that Ukrainian citizens have received fraudulent SMS messages claiming that…

Read more