- Gone Phishing
- Posts
- Fake reporters from APT42 harvest credentials
Fake reporters from APT42 harvest credentials

Welcome to Gone Phishing, your daily cybersecurity newsletter thatโs gotta catch โem all! ๐ฃ๐ฒ๐พ
Todayโs hottest cybersecurity news stories:
๐ฐ Jour-no, thanks! Fake reporters from APT42 harvest credentials ๐จโ๐พ
๐ฎ Can you guess who it is yet? Tonight, Matthew, I am Dmitry Khoroshev ๐ต๐ปโโ๏ธ
๐ Bleepy Hollowโฆ Hijack loader employs process โhollowingโ, UAC bypass ๐ง

Hackers: Iโm in the APT, yeah you know me! ๐ค๐๐ฅ
๐จ Iranian Hackers Targeting NGOs and Media Outlets! ๐ต๏ธโโ๏ธ
In a recent report by Mandiant, it's been revealed that APT42, a notorious Iranian hacking group, is up to their old tricks again. This time, they're using advanced social engineering schemes to breach target networks and cloud environments. ๐ฑ
Who's in the Crosshairs? ๐ฏ
Targets of these cyberattacks include Western and Middle Eastern NGOs, media organisations, academia, legal services, and activists. APT42 is cleverly posing as journalists and event organisers to build trust with their victims, delivering invitations to conferences or legit documents in the process. ๐ฐโ๏ธ
What's the Game Plan? ๐ค
Once they've gained a victim's trust, APT42 harvests credentials to sneak into cloud environments. From there, they covertly snatch sensitive data and exfiltrate it back to Iran. ๐ But here's the kicker: they're doing it all while flying under the radar using built-in features and open-source tools. ๐ต๏ธโโ๏ธ๐
APT42 Unmasked! ๐ญ
First identified in September 2022, APT42 is affiliated with Iran's Islamic Revolutionary Guard Corps (IRGC). They're a subset of another notorious group, APT35. While APT35 focuses on long-term, malware-heavy operations, APT42 zeroes in on specific individuals and organisations to serve Iran's domestic and foreign interests. ๐๐
Stay Vigilant, Stay Safe! ๐ก๏ธ
As APT42's cyber espionage campaigns evolve, it's crucial to stay one step ahead. Watch out for phishing emails and suspicious links, and always beef up your cybersecurity defences. Together, we can keep our networks secure! ๐ช

They done him Dmitry ๐๐๐ Tbf, he was chomping at the LockBit ๐ฌ
๐จ UK NCA Busts LockBit Ransomware Mastermind! ๐ฃ
In a stunning turn of events, the UK National Crime Agency (NCA) has unveiled the face behind the notorious LockBit ransomware operation. Meet Dmitry Yuryevich Khoroshev, a 31-year-old Russian national who's been wreaking havoc in the digital realm. ๐ฑ๐ต๏ธโโ๏ธ
The Man, The Myth ๐ญ
Khoroshev, also known as LockBitSupp and putinkrab, has been slapped with sanctions from the U.K., U.S., and Australia for his nefarious deeds. With over 2,500 decryption keys in hand, authorities are reaching out to LockBit victims to offer support and bring justice to those affected. ๐๐ฐ
Charges Galore! โ๏ธ
The Department of Justice (DoJ) has dropped a whopping 26 charges on Khoroshev, including conspiracy to commit fraud, extortion, and intentional damage to protected computers. If convicted, he could be staring down the barrel of a 185-year prison sentence. ๐ฑ๐ผ
The LockBit Legacy ๐
LockBit, once a titan in the ransomware underworld, has been dismantled thanks to a coordinated operation dubbed Cronos. Despite attempts to resurface, their global threat has been significantly diminished, with only 69 active affiliates remaining. Victory for cyber defenders everywhere! ๐ก๏ธ๐

๐ฃ Catch of the Day!! ๐๐๐ฆ
Stay ahead of the curve with Presspool.ai! ๐ Subscribe to their newsletter for the latest buzz in the information technology space, with a special focus on AI. Their slogan says it all: "Actionable marketing insights for the visionary AI executive." ๐ค๐ก Thatโs us, alright! ๐คต How about you? Visionary AI executive, much? ๐
And if the newsletter gets your motor running then you can take a butchers at their cool AI marketing product too which is sure to help you make the most of our new artificial overlords and put them to work for your business ๐ค๐ฉโ๐ป๐
Rest assured, the process is very straightforward.
You simply:
๐ Sign Up & Create Campaign
๐ Define your audience, budget, and message to captivate your audience.
๐ Launch your campaign, as Presspoolโs AI matches it with ideal newsletter audiences for optimal reach and conversions. ๐ฏ
๐ต๏ธ Finally, you leverage real-time analytics to track performance and refine future strategies. ๐ Elevate your marketing game and stay informed with Presspool.ai! ๐ Simples! ๐ฆฆ
Presspool.ai ๐ฐ๐๐ค may just have what you need to succeed. And if the product isnโt for you, the newsletter alone is a gamechanger. And we know newsletters ๐

Hijack? Bye Jack! ๐
๐จ Hijack Loader Malware Evolves with Stealthier Tactics! ๐ก๏ธ
A revamped version of the notorious malware loader, Hijack Loader, is making waves with its upgraded stealth capabilities. According to Zscaler ThreatLabz researcher Muhammed Irfan V A, this latest iteration boasts enhanced anti-analysis tricks to slip past detection systems unnoticed. ๐ต๏ธโโ๏ธ๐
A Closer Look at Hijack Loader: ๐ฆ
Originally dubbed IDAT Loader, Hijack Loader first emerged on the cyber scene back in September 2023. Since then, it's been the go-to conduit for various malware families, including Amadey, Lumma Stealer, and Remcos RAT, among others. ๐ฑ๐ป
PNG Decryption Technique Unveiled! ๐ผ๏ธ
What sets this new version apart is its ingenious use of a PNG image to decrypt and load the next-stage payload. This technique, pioneered by Morphisec, adds another layer of complexity to the malware's operation, making it even trickier to detect. ๐จ๐
The Arms Race Continues! ๐ฅ
As cyber threats evolve, so too must our defences. With malware campaigns on the rise, it's crucial to stay vigilant against emerging threats like Hijack Loader. But fear not! Together, we can outsmart even the most cunning cyber adversaries. ๐ก๏ธ๐
Stay tuned for more updates as the cybersecurity saga unfolds! ๐ป๐

๐๏ธ Extra, Extra! Read all about it! ๐๏ธ
Every few weeks, we carefully select three hot newsletters to show you. Reputation is everything, so any links we share come from personal recommendation or carefully researched businesses at the time of posting. Enjoy!
๐ก๏ธ Tl;dr sec: Join 30,000+ security professionals getting the best tools, blog posts, talks, and resources right in their inbox for free every Thursday ๐
๐ต Crypto Pragmatist: Crypto made simple. Actionable alpha in 5 minutes, 3x a week. Join 47,000+ investors and insiders, for ๐
๐ Bitcoin Breakdown: The best in Bitcoin, carefully curated by an alien from the future ๐พ
Let us know what you think.
So long and thanks for reading all the phish!
Give us a rating? |

