Hackers Modified Cobalt Strike Capabilities to Attack macOS Users

0
[ad_1]
Cobalt Strike Modified to Attack macOS Users

Geacon, a Cobalt Strike implementation written in Golang, is likely to attract the attention of threat actors looking for vulnerable macOS devices.

Threat actors have been employing Cobalt Strike to breach Windows PCs for years, despite the infosec industry’s ongoing efforts to stop it.

SentinelOne’s results confirm this after it saw an increase in the number of Geacon payloads that have been detected on VirusTotal lately.

“While some of these are likely red-team operations, others bear the characteristics of genuine malicious attacks,” SentinelOne reports.

Fortra created Cobalt Strike, a well-known red teaming and adversary simulation tool. Due to their many capabilities, threat actors have long misused illegally cracked versions of the software.

While Cobalt Strike’s post-exploitation activity has mostly targeted Windows, assaults against macOS are rather uncommon.

Geacon was a promising Cobalt Strike port that first surfaced on GitHub, but it didn’t seem like many hackers were interested in it.

SentinelOne notes that this changed in April as a result of two Geacon forks—Geacon Plus, a free and publicly accessible version, and Geacon Pro, a private, paid version—being uploaded on GitHub by unidentified Chinese developers.

Mach-O payloads for the free version of the fork have reportedly been in development since November 2022, according to historical data from Virus Total.

The Geacon fork has been added to the ‘404 Starlink project,’ a public GitHub repository dedicated to red-team pen-testing tools that have been maintained by the Zhizhi Chuangyu Laboratory since 2020.

This addition contributed to the Geacon fork’s rise in popularity and appears to have attracted users with malicious intent.

Malicious Geacon Deployment

Two VirusTotal submissions from the dates of April 5 and April 11 contained two instances of malicious Geacon deployment, according to SentinelOne.

The first one is an AppleScript applet file with the name “Xu Yiqing’s Resume_20230320.app,” which checks to see if a macOS system is supported before downloading one unsigned “Geacon Plus” payload from a command and control (C2) server with a Chinese IP address.

The user is shown a two-page decoy document that is integrated into the Geacon binary before it starts its beaconing activity. An individual named “Xu Yiqing”‘s resume is visible in an opened PDF document. 

Geacon Decoy PDF

“The compiled Geacon binary has a multitude of functions for tasks such as network communications, encryption, decryption, downloading further payloads, and exfiltrating data”, researchers explain.

The second payload is a trojanized version of the SecureLink application used for secure remote support called SecureLink.app and SecureLink_Client, including a copy of “Geacon Pro.”

The binary in this instance only supports Mac OS X 10.9 (Mavericks) and subsequent versions, which are Intel-based systems.

File details

The app asks for access to the computer’s microphone, camera, contacts, images, reminders, and administrator rights upon launch, even though these features are typically covered by Apple’s Transparency, Consent, and Control (TCC) privacy framework.

Although these are exceedingly hazardous permissions, the kind of fake application allows for the user’s suspicion to be allayed, which deceives them into approving the app’s request.

Access permission details

Final Words

Researchers say enterprise security teams can benefit from attack simulation tools such as Cobalt Strike and its macOS Go adaption, Geacon.

“It is quite likely that some of the activity we are observing around this tool is legitimate red team use, but it is also likely that genuine threat actors will make use of the public and possibly even the private forks of Geacon now available to them,” researchers.

Struggling to Apply The Security Patch in Your System? – 
Try All-in-One Patch Manager Plus


[ad_2]
Source link

Google Fiber 20-gig Internet speeds in now open for testers

0
[ad_1]

Google Fiber has launched its 20-gig internet plan for at least eight organizations that want to test it, CNET reports.

Having a 20-gig internet service at home might seem like a daydream for most Internet users worldwide. But Google is working to make this dream come true by launching a test program for its 20-gig product. The company has already launched 5-gig and 8-gig tiers, but a 20-gig service would certainly be a hallmark of the technology.

According to the company’s announcement, the service is currently under testing in the School of Science and Engineering at the University of Missouri-Kansas City. Google is now asking eight more organizations to join the program to stretch the service to its full extent.

Google Fiber is looking for eight organizations to test its 20-gig internet service

The tech giant further explains that these organizations could be businesses, non-profits, and educational institutions. Additionally, they should be located in Austin, Huntsville, Raleigh-Durham, and Salt Lake City. Google currently doesn’t charge selected organizations and puts them in its Trusted Tester program.

The organizations willing to participate in the program can fill out an form. Of course, they should meet certain qualifications like downloading or uploading massive datasets, conducting research that really needs significantly more bandwidth, and working on developing a tech that needs enormous bandwidth.

Google Fiber is rapidly growing in the United States and even managed to become a rival for AT&T and Verizon tiers. Google’s fiber internet will also arrive in Logan, Utah, in 2024 after the company signed a license agreement with the city. More cities are expected to join the program in the coming years.

The race for offering high-speed internet is going to a whole new level, and Google wants to stay caught up with rivals. China, the biggest internet market in the world, has recently tested a 6G network with a data speed of 100Gbps. This was also the first successful wireless transmission in the world at the terahertz (THz) frequency level.


[ad_2]
Source link

Google Bard is now better at summarizing and sourcing

0
[ad_1]

Google’s chatbot Bard is steadily improving as time goes on. During Google I/O, Google unveiled several new additions to Bard that really make it a compelling chatbot. The improvements don’t stop there, as a recent update gives Bard improved summarizing and sourcing abilities, according to 9To5Google.

Right now, Google Bard is catching up to ChatGPT in the AI chatbot race. In some respects, it actually lapped OpenAI’s chatbot. If you want a rundown of things that Google Bard can do that ChatGPT can’t, click here.

Google Bard is better at sourcing and summarizing content

Most modern AI chatbots have the ability to give a summary of articles. This is something that ChatGPT can do, but it’s limited and its ability. If you still want to give it a try, click here. The thing about ChatGPT is that it’s limited to events that happen before 2021.

This is where Bart has a leg up on ChatGPT. Since Bard is powered by Google, and since Google is basically the internet, it has a live feed of up-to-date information. Thus, it’s able to summarize articles more proficiently.

If you ask Barb to summarize an article and paste the link, you’ll get a response back with a few parts to it. Firstly, you’ll get a rough overview of the article. Next, you’ll get several bullet points that highlight the main points in the article. After that, you’ll get a short closing paragraph.

So far, just know that the company is still working on this feature. There’s a chance that Bard will not properly summarize the article and give you inaccurate information.

Sourcing

Next, Bard will improve its sourcing capabilities. Microsoft’s Bing AI lists the sources of where it got its information at the bottom of the response. Each Source is hyperlinked, so you can go straight to the source if you want.

This is something that Bart does, but it doesn’t do this quite as often as Bing AI. Hopefully, we will see it doing this more in the future.


[ad_2]
Source link

Instagram will now allow you to respond to posts with a GIF and further edit your Reels

0
[ad_1]
Instagram has recently rolled out a highly anticipated feature that allows users to express themselves through GIFs in the comments section. This move comes after years of user requests for the platform to integrate this popular form of communication.
The new feature was announced via the Instagram channel of Adam Mosseri, who currently heads the company. The announcement was shared with a voice note accompanied by an image showcasing how a GIF has been inserted into a comment by using GIPHY. It was also included in a post today on Meta’s Newsroom.

In the voice note, Mosseri expressed some regret for not bringing this feature to Instagram users sooner and called this a “finally feature.” He acknowledged that this should have been available a long time ago, but they were just now able to launch.

The feature will be available globally for both Android and iOS effective immediately, although it might be a staged rollout so don’t despair if you don’t have it yet. You’ll know the feature is available to you if you see a GIF icon on the bottom right of the “Add a comment” field when commenting on a post.

Additionally, Instagram will be beefing up the Reels editor so that you can split a single clip into two clips, speed up or slow down your clips, or swap clips out without affecting the timing. These particular improvements to Reels will be rolling out globally in the next few weeks.

Incorporating GIFs into your comments can be an excellent method of infusing a touch of personality and humor in posts as well as a very imaginative way to engage with your social circle. Meanwhile, Instagram continues to build new features into its platform that are very TikTok-esque, further proving that it is serious about competing and establishing itself as the go-to social network for media sharing.


[ad_2]
Source link

VirusTotal AI code Analysis Expanded to Spot Malicious Files

0
[ad_1]
VirusTotal AI code Analysis

In April 2023, Google announced VirusTotal Code Insight to improve the capacity of its malware detection and analysis platform. This week, Google released an enhanced version of VirusTotal Code Insight, including support for more scripting languages.

Code Insight is an AI-based code analysis feature powered by the Google Cloud Security AI Workbench that uses the Sec-PaLM large language model (LLM) tailored for security use cases.

“Code Insight has broadened its support for script formats, moving beyond PowerShell to offer analysis for various scripting languages,” VirusTotal founder Bernardo Quintero said.

Updates to VT Code Insight

Code Insight, which was once limited to analyzing a subset of PowerShell files, can currently detect malicious Batch (BAT), Command Prompt (CMD), Shell (SH), and VBScript (VBS) scripts.

The maximum file size limit for files handled by Code Insight has been doubled, allowing for an analysis of larger files.

Further, the model provides more brief and concentrated high-level explanations, emphasizing code behavior.

The user interface has been modified to display only the initial sentences of the report by default, with the option for users to expand the report as needed, preventing lengthy reports from overpowering the default view.

ESXiArgs sample analysis by VirusTotal Code Insight

The functionality is currently in active development and should be regarded as beta. In the upcoming months, VirusTotal intends to enhance it by supporting more file formats, bigger file sizes, and the analysis of executable file types like.exe.

For example, the team intends to provide the study with more context by granting the AI access to “any metadata related to the URLs and files linked in the code snippet.”

Security researchers and other users can utilize Code Insight to analyze the behavior of scripts, making it an intriguing feature. Its use will increase when the service is expanded to support more file types, particularly executable files.

Struggling to Apply The Security Patch in Your System? – 
Try All-in-One Patch Manager Plus


[ad_2]
Source link

Google may let you use your Pixel phone as a dashcam

0
[ad_1]

Smartphones have already replaced tons of devices in our lives like our clocks, video game consoles, cameras, microphones, Etc. Well, according to an APK deep dive by 9To5Google, it seems like Google wants your Pixel phone to replace your dashcam as well.

Since this was an APK Deep dive, you’ll want to take this news with a grain of salt. Essentially, early code for a feature was hidden within the current version of an app. Since it’s hidden within the app, Google can silently take it away if need be. So, there’s a chance that we may never see this feature.

Google might let you use your Pixel phone as a dashcam

Sometimes, you want to keep a record of what you witnessed while driving. Maybe you see an accident, or you yourself were in an accident. Having video proof of what happened during a traffic incident can turn the tide in a legal battle.

So, having one is important, but they can be rather expensive. However, if you have a Pixel device, then you might be in luck. According to 9To5Google, Google may have accidentally launched a dog food version of the personal safety app. Basically, it’s a version of the app that’s used for internal testing amongst the developers.

This version has the version number 2023.04.27.532191641.8-dogfood, and it wasn’t really meant for public use. However, they were able to crack into the app and discover some strings for and enable this potential feature.

The function is pretty self-explanatory. If you have the proper rig, you can attach your device to your dashboard and consistently record video of the traffic ahead of you.

Functions

The app is built to be very conservative with your storage. On average, the recorded video is about 30MB per minute, and the recordings are deleted three days after being recorded. However, you can save those recordings to preserve them.

Using a feature like this could definitely drain your battery, but the app lets you lock your screen while using it. If you need to have your screen on for apps like Google Maps, you can move the personal safety app to the background and use other apps over it.

Along with recording video, the dashcam can also record audio. Aside from that, you’ll be able to launch the dashcam using a home screen shortcut. There’s also a set-it-and-forget-it mentality behind this feature, as you can set the dashcam to start immediately when connected to certain Bluetooth devices.

At this point, there’s no telling if Google will actually launch this feature. We will have to wait and see. The next feature drop for Pixel phones isn’t too far away, so there’s a chance that we might see that feature drop then.


[ad_2]
Source link

New Galaxy Buds 2 Pro update enhances Ambient Sound

0
[ad_1]

Samsung has announced a new update for the Galaxy Buds 2 Pro. Scheduled to roll out in the coming weeks, it will bring enhancements to the Ambient Sound feature. The company plans to add new customization and fine-tuning options that will be particularly beneficial to people who are hard of hearing.

The Galaxy Buds 2 Pro are Samsung’s latest TWS earbuds, and one of the best out there currently. The company launched this pair in August last year alongside the Galaxy Watch 5 series and new foldables. These buds came with three levels of customization for the Ambient Sound feature out of the box. Depending on your need and preference, you could customize the feature to let in an optimal amount of surrounding sound when listening to music or other audio content.

The upcoming update will add two more levels of Ambient Sound customization, giving you a total of five options. The additional levels will allow people with hearing loss to better communicate with their surrounding by letting in more surround sound.

A clinical trial by the University of Iowa’s Hearing Aid and Aging Research Laboratory concluded that the Galaxy Buds 2 Pro “significantly improved speech perception in those with mild-to-moderate hearing loss”. A similar trial conducted by Samsung Medical Center concluded the same.

Following this addition, Galaxy Buds 2 Pro users will have more options when fine-tuning their left and right audio preferences. That’s thanks to Samsung letting you customize the Ambient Sound volume for each bud separately. You can also define the Ambient Sound tone by selecting one of the five stages ranging from Soft to Clear. The Galaxy Buds 2 Pro has an adaptive ambient sound feature as well.

This update for the Galaxy Buds 2 Pro will arrive soon

Samsung announced the latest update for the Galaxy Buds 2 Pro to mark the occasion of Global Accessibility Awareness Day 2023, which falls on Thursday, May 18 (observed on the third Thursday of May every year since 2012).

It is an awareness day focusing on digital access and inclusion for people with disabilities or impairments. In its press release, the company said that the new features will help those who are hard of hearing “better enjoy the sounds of the world around them.”

As said earlier, this update will roll out to Galaxy Buds 2 Pro users globally in the coming weeks. Once the update is available for you, the Galaxy Wearable app on your connected smartphone will send a notification prompting you to download it. Install the update to access the new features, which will be available in the Laboratory menu under Earbuds settings.

Note that updates are usually released in batches and may take a while to reach everyone around the world. We will let you know if Samsung pushes this update to other Galaxy Buds models.

Samsung Galaxy Buds 2 Pro new update Ambient Sound


[ad_2]
Source link

TikTok creators will soon dip their toes into a $6 million fund, awarding AR effects

0
[ad_1]

Back in February, TikTok announced its new Creativity Program, aimed at motivating creators to… well, create. The thing was in beta back then, and the first incentive ironically tried to encourage creators to make longer videos (while other platforms have been trying to copy TikTok’s short format for years).

Now there’s yet another way for TikTok creators to try and pay the rent, and it’s called Effect Creator Rewards. Basically, if you create an effect that makes it into half a million unique videos, you get some cash from a huge $6 million dollar pool.“The $6 million dollar fund, available to creators in select regions, will offer payments to creators based on the community’s engagement with their effects. At launch, for every effect that’s used in 500K unique videos within 90 days of being published, a creator will collect $700 USD. For every 100K videos published thereafter within the same 90 days, creators will collect an additional $140,” explained the company in a blog post.
Looking at the paragraph above, it’s clear that this $6 million fund will be distributed very carefully, and you can’t expect to buy that dream Malibu house while making TikTok effects. Nevertheless, it’s another instrument encouraging TikTok creators to get serious on the platform. The new program is available through Creativity Beta and currently live in the US, France and Brazil.

Two months ago, at the beginning of March, TikTok launched another incentive called Series, enabling creators to offer premium content to fans for a fee. All these efforts came after many popular TikTokers voiced their concern with the income they’re making from the platform. What do you think about it? Are we going to get rich by flooding TikTok with effects?


[ad_2]
Source link

APT Hackers Using Custom Backdoor to Attack Government Orgs

0
[ad_1]
Lancefly APT Hackers

The cybersecurity researchers at Symantec Threat Labs recently discovered APT hacking group has been utilizing the specialized ‘Merdoor’ backdoor malware to conduct precise and prolonged attacks on the following sectors in South and Southeast Asia since 2018:-

  • Government
  • Aviation
  • Telecommunication

While apart from this, since 2018, Lancefly has been using the Merdoor backdoor malware in specific attacks.

Symantec researchers have observed the usage of this backdoor malware in multiple campaigns, spanning from 2020 to the first quarter of 2023, with the primary aim of spying and gathering intelligence reports.

Lancefly APT Hackers Attack Chain

Although Symantec has not identified the precise initial infection method employed by Lancefly, evidence suggests that the group has utilized techniques such as phishing emails, SSH credential brute forcing, and exploiting vulnerabilities in public-facing servers to gain unauthorized access.

The attackers inject the Merdoor backdoor through DLL side-loading into legitimate Windows processes, such as “perfhost.exe” or “svchost.exe,” to help the malware evade detection once it gains a foothold on the target system.

The Merdoor dropper contains three files, and it is a self-extracting RAR (SFX):-

  • A legitimate and signed binary vulnerable to DLL search-order hijacking
  • A malicious loader (Merdoor loader)
  • An encrypted file (.pak) containing the final payload (Merdoor backdoor)

The Merdoor dropper, upon execution, extracts embedded files and leverages older versions of five legitimate applications to facilitate DLL sideloading for loading the Merdoor loader.

After installing itself as a service that persists between reboots, the Merdoor backdoor establishes communication with the C2 server via several supported protocols. It awaits further instructions, enabling Lancefly to maintain access and a foothold on the victim’s system.

Here below, we have mentioned all the supported communication protocols:-

Merdoor functions as a backdoor that can receive commands through local ports and records keystrokes to gather potentially useful information.

To swiftly execute scheduled tasks on remote systems through SMB, Lancefly utilizes Impacket’s ‘Atexec’ feature. At the same time, it does so as a means to propagate through the network or eliminate output files generated by previous commands.

The attackers employ memory dumping, stealing registry hives, and encrypting files with a disguised WinRAR tool, followed by likely exfiltration using Merdoor to steal credentials and extract sensitive data.

Attack Chain Tools and TTPs

Here below, we have mentioned all the attack chain tools and TTPs:-

  • Impacket Atexec
  • Suspicious SMB activity
  • WinRAR
  • LSSAS Dumper
  • NBTScan
  • Blackloader
  • Prcloader

ZXShell Rootkit

Lancefly attacks incorporate an upgraded ZXShell rootkit, leveraging its advanced capabilities through the “FormDII.dll” loader, which enables the deployment of tailored payloads, execution of shellcode, termination of processes, and additional functionalities based on the host’s system architecture.

Lancefly uses a shared codebase for their tools, as evidenced by the common code between the rootkit’s installation and updating utility and the Merdoor loader, with the former also capable of:-

  • Creating services
  • Modifying the registry
  • Compressing its executable to evade detection

Possible Links

Although the ZXShell rootkit has been used by multiple Chinese APT groups, including APT17 and APT41, the connection to Lancefly is tenuous due to the rootkit’s public availability for years.

The rootkit loader name “formdll.dll” used by Lancefly has been observed in a previous APT27 campaign, but it remains uncertain if this choice intentionally confuses analysts and hinders attribution efforts.

The utilization of commonly employed PlugX and ShadowPad remote access trojans (RATs), shared by multiple Chinese APT groups, provides additional support for the proposition that Lancefly has Chinese origins.

Struggling to Apply The Security Patch in Your System? – 
Try All-in-One Patch Manager Plus


[ad_2]
Source link

OnePlus V Fold & OPPO Find N3 to feature the same design

0
[ad_1]

According to a new report, the OnePlus V Fold and OPPO Find N3 will feature the same design. This information comes from 91mobiles, in collaboration with Yogesh Brar. One thing to note is that this tipster has a mixed track record, so take this info with a grain of salt.

The OnePlus V Fold & OPPO Find N3 tipped to feature the same design

Having said that, the OnePlus V Fold will become the company’s first foldable smartphone. OnePlus trademarked both the OnePlus V Fold and OnePlus V Flip names earlier this year. The ‘Flip’ name is presumably reserved for its clamshell foldable.

The tipster also says that the two devices will have the same cameras as the OPPO Find X6. That device includes a 50-megapixel main camera (Sony’s IMX890 sensor), a 48-megapixel ultrawide unit (Sony’s IMX581 sensor), and a 32-megapixel periscope camera. Hasselblad will also be a part of the picture.

Now, the OPPO Find N and Find N2 are quite compact when folded, and they unfold to a 7.1-inch form factor. Those two devices were rather unique in the book-style foldable market, though unfortunately neither made its way to global markets.

The OPPO Find N3 will be larger than its predecessors, based on rumors

The OPPO Find N3 is rumored to be larger, for better or worse. It’ll lose some of its appeal because of that, but that’s what the rumors are claiming. The same goes for the OnePlus V Fold, of course, if they end up being the same design-wise.

The rumors claim that the two devices will feature an 8-inch 120HZ display when they unfold. 20 and 32-megapixel selfie cameras were also mentioned in previous rumors. The same goes for a 4,805mAh battery.

If these rumors end up being true, the OPPO Find N3 and OnePlus V Fold could end up featuring the Google Pixel Fold-like form factor. If OPPO doesn’t change things around entirely, and doesn’t go for a vertically-oriented foldable, like the Galaxy Z Fold 4. We’ll see.

The OnePlus V Fold is expected to launch in Q3 this year, while the OPPO Find N3 will likely arrive in Q4.


[ad_2]
Source link