When Intrusions Don’t Align: A New Water Watering Hole and Oldsmar
ID: 5edbb0aa-bf88-53b0-86ff-b0791e66b95d
STIX ID: report--5edbb0aa-bf88-53b0-86ff-b0791e66b95d
Feed Name: Dragos Blog
Dragos analyzed a 58-day watering-hole compromise of a Florida water-construction company website that hosted advanced JavaScript to enumerate and fingerprint visiting browsers. The script harvested detailed client telemetry (OS, browser, hardware, plugins, time zone, screen metrics) and TLS cipher fingerprints (JA3) and exfiltrated data to a Heroku host. Dragos linked the activity to a Tofsee botnet variant named “Tesseract,” observed over 1,000 profiled clients (concentrated in the U.S./Florida), recovered three JA3 hashes, multiple "Tesseract/1.0" user-agent artifacts, and two malware SHA256s, and concluded the actor likely sought to improve botnet browser impersonation rather than directly delivering ICS exploits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
