February 2020

How PHP’s Labyrinth Weaponized WordPress Themes for Profit

New findings from Prevailion’s Tailored Intelligence team indicate the rapid expansion of a series of supply chain attacks that transform installations of the popular Wordpress content management system into hosts for a malicious advertising network. More than 20,000 web servers have been identified to be compromised in this campaign. WordPress has grown to become the backbone of 60% of content management systems, comprising 34% of all websites on the internet. This widespread user base and the ease in which a website can be personalized without knowledge of coding has created a fertile...

Share Post

Indicators of Compromise are Dead — Introducing Evidence of Compromise

The mission of Evidence of Compromise is simple: empower companies to audit and continuously monitor the security of their supply chains to an unprecedented degree, with the possibility of even predicting future breaches based on this real-time intelligence. Current methods of cyber risk management, incident response and risk modeling have failed to keep up with the growing sophistication and speed of cyber adversaries, which range from organized criminal groups to state-sponsored hackers. As geopolitical tensions increase around the world, they are accelerating the overall risk for the financial sector, as this industry remains...

Share Post

The Triune Threat: MasterMana Returns

Prevailion’s Tailored Intelligence team has discovered new campaigns associated with the Gorgon Group, suspected Pakistani based actors, who previously operated the MasterMana botnet. While this group relied upon an amalgamation of multiple open-source and commercially available tools, they have proven themselves to be highly capable. By utilizing various 3rd party websites and services, they are able to bypass common network defense mechanisms. Recently they have added new capabilities to evade host-based detection through encoding payloads and renaming file extensions. In some cases, they took a more audacious approach by incapacitating the Windows...

Share Post

What is Evidence of Compromise?

Evidence of Compromise (EoC) is a collection of forensic data that points to a confirmed malicious attack on a commercial, industrial or government network. ...

Share Post