Top attack vectors: November 2021
ID: 431a73f9-9224-5dd5-9c79-69b9ba8e66a8
STIX ID: report--431a73f9-9224-5dd5-9c79-69b9ba8e66a8
Feed Name: Expel Blog
**November 2021 SOC monthly report:** The SOC observed a 10% rise in commodity malware incidents driven by phishing emails linking to macro-enabled Office documents—SquirrelWaffle accounted for ~25% of commodity malware attempts and commonly delivered Qakbot or CobaltStrike—and ongoing cryptojacking operations (XMRig, TNT Worm, and malicious npm packages) exploiting exposed cloud resources; the report provides detection rules (e.g., monitor Excel -> regsvr32 activity, network traffic to mining pools) and mitigation advice (disable macros, patch public-facing servers, secure S3 and cloud credentials).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
