[ << ALL_FEED ]

Like a hammer of thunder disrupted the claws of silence.

More in General

How the Hammer of Thunder Disrupted the Claws of Silence 🦀

During an incident investigation, the Incident Response team, with support from the Threat Intelligence department, discovered traces of the KrustyLoader malware.

This malware was first described in January 2024 by experts from Volexity and Mandiant: they found it being used in attacks targeting the exploitation of zero-day RCE vulnerabilities in Ivanti Connect Secure. At that time, it was noted that KrustyLoader was written for Linux, but later versions for Windows appeared. Notably, at the time of the research, the loader was used by only one group, which we call QuietCrabs.

Further investigation revealed the activity of another group within the victim’s infrastructure. Interestingly, the actions of the second group likely disrupted QuietCrabs’ ability to carry out the attack and were the reason this attack drew attention.

We believe the second group is Thor. Based on an analysis of the attackers’ network infrastructure and telemetry data, we concluded that they were conducting mass attacks against Russian companies. To gain initial access to the infrastructure, the group exploited a number of RCE (Remote Code Execution) vulnerabilities, such as CVE-2025-53770 and CVE-2021-27065.

😠 In the article, we will show the attack chains we discovered during the investigation and discuss the tools used by the attackers. Read the material in our blog.

#IR #TI #APT
@ptescalator

More from oUth0R

More from oUth0R

More in General