View Topics

Research
13 minutes
HiddenWasp Malware Stings Targeted Linux Systems
Intezer has discovered a new, sophisticated malware named HiddenWasp, targeting Linux systems. Unlike common Linux malware, HiddenWasp is not focused on crypto-mining or DDoS activity, but rather it is a trojan purely used for targeted remote control.

Research
6 minutes
Technical Analysis: Pacha Group Competing against Rocke Group for Cryptocurrency Mining Foothold on the Cloud
The Pacha Group is disabling previously installed cryptominers from other threat groups on the cloud, most notably Rocke Group, in order to obtain the largest foothold of computing power on the cloud for conducting malicious crypto-mining activities.

Research
3 minutes
War on the Cloud: Cybercriminals Competing for Cryptocurrency Mining Foothold
The Pacha Group is disabling previously installed cryptominers from other threat groups on the cloud, most notably the Rocke Group, in order to obtain the largest foothold of computing power on the cloud for conducting malicious crypto-mining activities.

Malware Analysis
7 minutes
Meet the Team: Shaul Holtzman
Get to know Intezer Analyze community manager Shaul Holtzman. Shaul is a former cybersecurity analyst helping organizations detect and classify advanced cyber threats.

Incident Response
6 minutes
Fileless Malware: Scanning Endpoint Memory with Genetic Analysis
Memory forensics are crucial for detecting fileless malware. The new Intezer endpoint analysis solution analyzes code in memory to detect advanced threats.

Research
9 minutes
Technical Analysis: Pacha Group Deploying Undetected Cryptojacking Campaigns on Linux Servers
A technical analysis of Linux.Greedy.Antd, a cryptominer employed by Pacha Group to compromise third party Linux servers. The malware was undetected by all leading engines, demonstrating the sophistication of this threat.

Alert Triage
4 minutes
New! API for the Intezer Analyze Community
Announcing the release of an API for the Intezer Analyze community edition. Members of the free community can now create automation scripts to analyze files without manual intervention. Highlighted in this blog are some of the ways in which community users can utilize the API.

Malware Analysis
4 minutes
What is Genetic Malware Analysis?
Software is evolutionary. Intezer has introduced a new innovative approach to automate malware analysis and provide clear insights into any suspicious file. The company's Genetic Malware Analysis technology empowers security teams to improve and accelerate all stages of their incident response, from the initial alert to the final step of remediation.

Research
14 minutes
ChinaZ Revelations: Revealing ChinaZ Relationships with other Chinese Threat Actor Groups
Distributed denial-of-service (DDoS) attacks were on the rise in 2018. Chinese threat actors in particular have predominantly deployed DDoS attacks in their cyber campaigns, and China has emerged has having one of the highest rates of DDoS attacks. This blog provides a technical analysis highlighting connections between ChinaZ and other notable Chinese threat actor groups in the current DDoS landscape.

Research
8 minutes
Muhstik Botnet Reloaded: New Variants Targeting phpMyAdmin Servers
The Muhstik botnet was first exposed by Netlab360 researchers in May 2018. This botnet targeted mainly GPON routers. At Intezer we found that Muhstik is extending its spectrum of compromised devices by targeting web servers hosting phpMyAdmin.

Research
3 minutes
Paleontology: The Unknown Origins of Lazarus Malware
As seen by security researchers across the world and proven in a joint research by McAfee and Intezer, Lazarus, one of the groups operating from North Korea, has consistently reused code in their malware toolset.

Research
2 minutes
APT37: Final1stspy Reaping the FreeMilk
Researchers at Palo Alto Networks recently published a report regarding the NOKKI malware, which has shared code with KONNI and, although not in the report by Palo Alto, KimJongRAT (discovered by Paul Rascagnères of Cisco Talos in 2013), and another report on how there is evidence of the NOKKI malware connecting...

Research
2 minutes
Intezer Analyze™ ELF Support Release: Hakai Variant Case Study
We would like to proudly announce that Intezer Analyze™ now supports genetic malware analysis for ELF binaries! You may now upload ELF files to our system and find code reuse. We have already indexed the genes of millions of different files into our ELF genome database, classified into both malicious, trusted, and...

Research
5 minutes
Prince of Persia: The Sands of Foudre
Foudre is a remote access tool and has the ability to remotely execute commands, steal information about the infected target (such as keystrokes, process information, etc), and auto-update itself. Most of the code and functionality from the previous versions of Foudre and Infy was reused and can be read about in the reports by Palo Alto linked above, so we are only going to focus on the new, unique, interesting features and the linkage of code reuse from previous versions.



