Rewterz

Rewterz Threat Alert – Ryuk Ransomware – Active IOCs

August 19, 2022
Rewterz

Rewterz Threat Alert – STOP/DJVU Ransomware – Active IOCs

August 19, 2022

Rewterz Threat Alert – APT29 Cozy Bear – Active IOCs

Severity

High

Analysis Summary

APT29 aka Nobelium and Cozy Bear are the group which were behind the infamous Solar Wind attacks in 2020. APT29 threat group has previously targeted commercial entities and government organizations in Germany, Uzbekistan, South Korea and the US, including the US State Department and the White House in 2014. They have also targeted several vaccine manufacturers in attempt to sabotage the process to combat the Coronavirus pandemic. This time they’ve come up with a current campaign to target government organizations in attempt to steal sensitive information.

Impact

  • Information Theft and Espionage
  • Exposure of Sensitive Data

Indicators of Compromise

MD5

  • 6cacf38b2ce739e47127bc358b98ba42

SHA-256

  • 8160224ed2c53adc691f64ce3613ac2adcce5416c0128a08f1265eb68be8143b

SHA-1

  • 85dbec5d23649267cdf15e67c5f4b67436b42aa4

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.