The Good, the Bad and the Ugly in Cybersecurity – Week 25
ID: 2d4c9a53-dd96-53ae-b8e1-74bcc2f02984
STIX ID: report--2d4c9a53-dd96-53ae-b8e1-74bcc2f02984
Feed Name: SentinelOne Blog
A coordinated law-enforcement and private-sector operation dismantled the Outsider Enterprise PhaaS and removed SocGholish infections from ~15,000 WordPress sites while seizing infrastructure and cryptocurrency; separately, DragonForce actors deployed a Go-based Backdoor.Turn that abuses Microsoft Teams TURN relays for covert C2 and long dwell time, and UNC6508 (China-linked) exfiltrated medical research from exposed REDCap servers using a custom "InfiniteRed" backdoor and novel data-exfiltration via compliance rules. The bulletin describes scale (financial loss, stolen credit cards, sites compromised), key TTPs (DLL sideloading, BYOVD, TURN/QUIC abuse, credential harvesting), and recommended mitigations (patching, MFA, DBSC, IoCs/YARA).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
