• Trend Micro
  • About TrendLabs Security Intelligence Blog
Search:
  • Home
  • Categories
    • Ransomware
    • Vulnerabilities
    • Exploits
    • Targeted Attacks
    • Deep Web
    • Mobile
    • Internet of Things
    • Malware
    • Bad Sites
    • Spam
    • Botnets
    • Social
    • Open source
Home   »   sandworm

Timeline of Sandworm Attacks

  • Posted on:November 10, 2014 at 1:12 pm
  • Posted in:Exploits
  • Author:
    William Gamazo Sanchez (Vulnerability Research)
0

The Sandworm vulnerability, also known as CVE-2014-4114, is an interesting vulnerability for two reasons. For one, it is related to the timing of the vulnerability life cycle.  In this blog post, we will tackle vulnerability analysis, and user awareness on what actions to take when they are under attack.  Note that all dates and times discussed here…

Read More
Tags: sandwormtimeline

New CVE-2014-4114 Attacks Seen One Week After Fix

  • Posted on:October 22, 2014 at 2:23 pm
  • Posted in:Malware, Targeted Attacks, Vulnerabilities
  • Author:
    Ronnie Giagone (Threats Analyst)
1

Despite the availability of fixes related to the Sandworm vulnerability (CVE-2014-4114), we are still seeing new attacks related to this flaw. These attacks contain a new routine that could prevent detection. A New Evasion Technique In our analysis of the vulnerability, we noted this detail: “…[T]he vulnerability exists in PACKAGER.DLL, which is a part of…

Read More
Tags: CVE-2014-4114ExploitsandwormTargeted Attackvulnerability

Sandworm to Blacken: The SCADA Connection

  • Posted on:October 16, 2014 at 4:15 pm
  • Posted in:Internet of Things, Malware, Targeted Attacks
  • Author:
    Kyle Wilhoit and Jim Gogolinski (Senior Threat Researcher)
2

On October 14th, a report was publicly released regarding the Sandworm team.  After beginning an investigation into the affiliated malware samples and domains, we quickly came to realization that this group is very likely targeting SCADA-centric victims who are using GE Intelligent Platform’s CIMPLICITY HMI solution suite.   We have observed this team utilizing .cim and .bcl…

Read More
Tags: CIMPLICITYsandwormSCADAzero day

MS Zero-Day Used in Attacks Against European Sectors, Industries

  • Posted on:October 14, 2014 at 6:24 am
  • Posted in:Targeted Attacks, Vulnerabilities
  • Author:
    Trend Micro
0

Microsoft has announced the discovery of a zero-day vulnerability affecting all supported versions of Microsoft Windows and Windows Server 2008 and 2012. Reports are also coming in that this specific vulnerability has been exploited and used in attacks against the North Atlantic Treaty Organization (NATO) and several European industries and sectors. According to reports, this…

Read More
Tags: MicrosoftsandwormTargeted Attackzero dayzero-day vulnerability

Security Predictions for 2020

  • Cybersecurity in 2020 will be viewed through many lenses — from differing attacker motivations and cybercriminal arsenal to technological developments and global threat intelligence — only so defenders can keep up with the broad range of threats.
    Read our security predictions for 2020.

Business Process Compromise

  • Attackers are starting to invest in long-term operations that target specific processes enterprises rely on. They scout for vulnerable practices, susceptible systems and operational loopholes that they can leverage or abuse. To learn more, read our Security 101: Business Process Compromise.

Popular Posts

Sorry. No data so far.

Stay Updated

  • Home and Home Office
  • |
  • For Business
  • |
  • Security Intelligence
  • |
  • About Trend Micro
  • Asia Pacific Region (APAC): Australia / New Zealand, 中国, 日本, 대한민국, 台灣
  • Latin America Region (LAR): Brasil, México
  • North America Region (NABU): United States, Canada
  • Europe, Middle East, & Africa Region (EMEA): France, Deutschland / Österreich / Schweiz, Italia, Россия, España, United Kingdom / Ireland
  • Privacy Statement
  • Legal Policies
  • Copyright © Trend Micro Incorporated. All rights reserved.