Wed Sep 18 21:14:48 2024



NYLXS Mailing Lists and Archives
NYLXS Members have a lot to say and share but we don't keep many secrets. Join the Hangout Mailing List and say your peice.

DATE 2024-08-01


2024-09-18 | 2024-08-18 | 2024-07-18 | 2024-06-18 | 2024-05-18 | 2024-04-18 | 2024-03-18 | 2024-02-18 | 2024-01-18 | 2023-12-18 | 2023-11-18 | 2023-10-18 | 2023-09-18 | 2023-08-18 | 2023-07-18 | 2023-06-18 | 2023-05-18 | 2023-04-18 | 2023-03-18 | 2023-02-18 | 2023-01-18 | 2022-12-18 | 2022-11-18 | 2022-10-18 | 2022-09-18 | 2022-08-18 | 2022-07-18 | 2022-06-18 | 2022-05-18 | 2022-04-18 | 2022-03-18 | 2022-02-18 | 2022-01-18 | 2021-12-18 | 2021-11-18 | 2021-10-18 | 2021-09-18 | 2021-08-18 | 2021-07-18 | 2021-06-18 | 2021-05-18 | 2021-04-18 | 2021-03-18 | 2021-02-18 | 2021-01-18 | 2020-12-18 | 2020-11-18 | 2020-10-18 | 2020-09-18 | 2020-08-18 | 2020-07-18 | 2020-06-18 | 2020-05-18 | 2020-04-18 | 2020-03-18 | 2020-02-18 | 2020-01-18 | 2019-12-18 | 2019-11-18 | 2019-10-18 | 2019-09-18 | 2019-08-18 | 2019-07-18 | 2019-06-18 | 2019-05-18 | 2019-04-18 | 2019-03-18 | 2019-02-18 | 2019-01-18 | 2018-12-18 | 2018-11-18 | 2018-10-18 | 2018-09-18 | 2018-08-18 | 2018-07-18 | 2018-06-18 | 2018-05-18 | 2018-04-18 | 2018-03-18 | 2018-02-18 | 2018-01-18 | 2017-12-18 | 2017-11-18 | 2017-10-18 | 2017-09-18 | 2017-08-18 | 2017-07-18 | 2017-06-18 | 2017-05-18 | 2017-04-18 | 2017-03-18 | 2017-02-18 | 2017-01-18 | 2016-12-18 | 2016-11-18 | 2016-10-18 | 2016-09-18 | 2016-08-18 | 2016-07-18 | 2016-06-18 | 2016-05-18 | 2016-04-18 | 2016-03-18 | 2016-02-18 | 2016-01-18 | 2015-12-18 | 2015-11-18 | 2015-10-18 | 2015-09-18 | 2015-08-18 | 2015-07-18 | 2015-06-18 | 2015-05-18 | 2015-04-18 | 2015-03-18 | 2015-02-18 | 2015-01-18 | 2014-12-18 | 2014-11-18 | 2014-10-18 | 2014-09-18 | 2014-08-18 | 2014-07-18 | 2014-06-18 | 2014-05-18 | 2014-04-18 | 2014-03-18 | 2014-02-18 | 2014-01-18 | 2013-12-18 | 2013-11-18 | 2013-10-18 | 2013-09-18 | 2013-08-18 | 2013-07-18 | 2013-06-18 | 2013-05-18 | 2013-04-18 | 2013-03-18 | 2013-02-18 | 2013-01-18 | 2012-12-18 | 2012-11-18 | 2012-10-18 | 2012-09-18 | 2012-08-18 | 2012-07-18 | 2012-06-18 | 2012-05-18 | 2012-04-18 | 2012-03-18 | 2012-02-18 | 2012-01-18 | 2011-12-18 | 2011-11-18 | 2011-10-18 | 2011-09-18 | 2011-08-18 | 2011-07-18 | 2011-06-18 | 2011-05-18 | 2011-04-18 | 2011-03-18 | 2011-02-18 | 2011-01-18 | 2010-12-18 | 2010-11-18 | 2010-10-18 | 2010-09-18 | 2010-08-18 | 2010-07-18 | 2010-06-18 | 2010-05-18 | 2010-04-18 | 2010-03-18 | 2010-02-18 | 2010-01-18 | 2009-12-18 | 2009-11-18 | 2009-10-18 | 2009-09-18 | 2009-08-18 | 2009-07-18 | 2009-06-18 | 2009-05-18 | 2009-04-18 | 2009-03-18 | 2009-02-18 | 2009-01-18 | 2008-12-18 | 2008-11-18 | 2008-10-18 | 2008-09-18 | 2008-08-18 | 2008-07-18 | 2008-06-18 | 2008-05-18 | 2008-04-18 | 2008-03-18 | 2008-02-18 | 2008-01-18 | 2007-12-18 | 2007-11-18 | 2007-10-18 | 2007-09-18 | 2007-08-18 | 2007-07-18 | 2007-06-18 | 2007-05-18 | 2007-04-18 | 2007-03-18 | 2007-02-18 | 2007-01-18 | 2006-12-18 | 2006-11-18 | 2006-10-18 | 2006-09-18 | 2006-08-18 | 2006-07-18 | 2006-06-18 | 2006-05-18 | 2006-04-18 | 2006-03-18 | 2006-02-18 | 2006-01-18 | 2005-12-18 | 2005-11-18 | 2005-10-18 | 2005-09-18 | 2005-08-18 | 2005-07-18 | 2005-06-18 | 2005-05-18 | 2005-04-18 | 2005-03-18 | 2005-02-18 | 2005-01-18 | 2004-12-18 | 2004-11-18 | 2004-10-18 | 2004-09-18 | 2004-08-18 | 2004-07-18 | 2004-06-18 | 2004-05-18 | 2004-04-18 | 2004-03-18 | 2004-02-18 | 2004-01-18 | 2003-12-18 | 2003-11-18 | 2003-10-18 | 2003-09-18 | 2003-08-18 | 2003-07-18 | 2003-06-18 | 2003-05-18 | 2003-04-18 | 2003-03-18 | 2003-02-18 | 2003-01-18 | 2002-12-18 | 2002-11-18 | 2002-10-18 | 2002-09-18 | 2002-08-18 | 2002-07-18 | 2002-06-18 | 2002-05-18 | 2002-04-18 | 2002-03-18 | 2002-02-18 | 2002-01-18 | 2001-12-18 | 2001-11-18 | 2001-10-18 | 2001-09-18 | 2001-08-18 | 2001-07-18 | 2001-06-18 | 2001-05-18 | 2001-04-18 | 2001-03-18 | 2001-02-18 | 2001-01-18 | 2000-12-18 | 2000-11-18 | 2000-10-18 | 2000-09-18 | 2000-08-18 | 2000-07-18 | 2000-06-18 | 2000-05-18 | 2000-04-18 | 2000-03-18 | 2000-02-18 | 2000-01-18 | 1999-12-18

Key: Value:

Key: Value:

DATE 2024-08-10
FROM shulie
SUBJECT Subject: [Hangout - NYLXS] Chinese backdoors

Linux Threat Report: Earth Lusca Deploys Novel SprySOCKS Backdoor in
Attacks on Government Entities

by Jamieson Davis
on September 19, 2023

The threat actor Earth Lusca, linked to Chinese state-sponsored hacking
groups, has been observed utilizing a new Linux backdoor dubbed
SprySOCKS to target government organizations globally. 

As initially reported in January 2022 by Trend Micro, Earth Lusca has
been active since at least 2021 conducting cyber espionage campaigns
against public and private sector targets in Asia, Australia, Europe,
and North America. Their tactics include spear-phishing and watering
hole attacks to gain initial access. Some of Earth Lusca's activities
overlap with another Chinese threat cluster known as RedHotel.

In new research, Trend Micro reveals Earth Lusca remains highly active,
even expanding operations in the first half of 2023. Primary victims are
government departments focused on foreign affairs, technology, and
telecommunications. Attacks concentrate in Southeast Asia, Central Asia,
and the Balkans regions. 

After breaching internet-facing systems by exploiting flaws in Fortinet,
GitLab, Microsoft Exchange, Telerik UI, and Zimbra software, Earth Lusca
uses web shells and Cobalt Strike to move laterally. Their goal is
exfiltrating documents and credentials, while also installing additional
backdoors like ShadowPad and Winnti for long-term spying.

The Command and Control server delivering Cobalt Strike was also found
hosting SprySOCKS - an advanced backdoor not previously publicly
reported. With roots in the Windows malware Trochilus, SprySOCKS
contains reconnaissance, remote shell, proxy, and file operation
capabilities. It communicates over TCP mimicking patterns used by a
Windows trojan called RedLeaves, itself built on Trochilus.

At least two SprySOCKS versions have been identified, indicating ongoing
development. This novel Linux backdoor deployed by Earth Lusca
highlights the increasing sophistication of Chinese state-sponsored
threats. Robust patching, access controls, monitoring for unusual
activities, and other proactive defenses remain essential to counter
this advanced malware.

The Trend Micro researchers emphasize that organizations must minimize
attack surfaces, regularly update systems, and ensure robust security
hygiene to interrupt the tactics, techniques, and procedures of
relentless threat groups like Earth Lusca.

Hangout mailing list

  1. 2024-08-02 Ruben Safir <> Subject: [Hangout - NYLXS] Spyware you pay for..
  2. 2024-08-02 Ruben Safir <> Subject: [Hangout - NYLXS] [ Upcoming student debt
  3. 2024-08-02 Ruben Safir <> Subject: [Hangout - NYLXS] [ Shortcut to a Lucrative
  4. 2024-08-02 Ruben Safir <> Subject: [Hangout - NYLXS] Exactly what IS political corruption?
  5. 2024-08-02 Ruben Safir <> Re: [Hangout - NYLXS] Exactly what IS political corruption?
  6. 2024-08-02 Ruben Safir <> Re: [Hangout - NYLXS] Exactly what IS political corruption?
  7. 2024-08-05 Ruben Safir <> Subject: [Hangout - NYLXS] Rape as a weapon in detail in the Arab war
  8. 2024-08-06 From: "Professional Career Services" <> Subject: [Hangout - NYLXS] Open House tonight! Masters in Accounting
  9. 2024-08-06 Ruben Safir <> Subject: [Hangout - NYLXS] In a day loaded with news,
  10. 2024-08-08 Mithun Bhattacharya <> Re: [Hangout - NYLXS] reasons for modperl declines?
  11. 2024-08-08 Jeff Pang <> Re: [Hangout - NYLXS] reasons for modperl declines?
  12. 2024-08-08 Jeff Pang <> Re: [Hangout - NYLXS] reasons for modperl declines?
  13. 2024-08-07 Jeff Pang <> Subject: [Hangout - NYLXS] reasons for modperl declines?
  14. 2024-08-08 Guido Brugnara <> Re: [Hangout - NYLXS] reasons for modperl declines? ... pagination
  15. 2024-08-08 Guido Brugnara <> Re: [Hangout - NYLXS] reasons for modperl declines?
  16. 2024-08-08 Vincent Veyron <> Re: [Hangout - NYLXS] *** SPAM *** Re: reasons for modperl declines?
  17. 2024-08-08 Guido Brugnara <> Re: [Hangout - NYLXS] reasons for modperl declines?
  18. 2024-08-07 Jan Kasprzak <> Re: [Hangout - NYLXS] reasons for modperl declines?
  19. 2024-08-08 Ruben Safir <> Subject: [Hangout - NYLXS] [ Re: cross-site scripting
  20. 2024-08-09 Ruben Safir <> Subject: [Hangout - NYLXS] Fwd: What the Cori Bush defeat and the Tim Walz
  21. 2024-08-09 Ruben Safir <> Subject: [Hangout - NYLXS] More Red Paint
  22. 2024-08-09 Ruben Safir <> Subject: [Hangout - NYLXS] Jew hating Bigots and Journalist went to arrested
  23. 2024-08-10 Ruben Safir <> Subject: [Hangout - NYLXS] Ancient Calender
  24. 2024-08-10 shulie <> Subject: [Hangout - NYLXS] Chinese backdoors
  25. 2024-08-11 Ruben Safir <> Subject: [Hangout - NYLXS] linux adim texts
  26. 2024-08-13 Ruben Safir <> Subject: [Hangout - NYLXS] the rage to destroy -
  27. 2024-08-13 Ruben Safir <> Subject: [Hangout - NYLXS] The kids are alright..
  28. 2024-08-14 Ruben Safir <> Subject: [Hangout - NYLXS] DRM is theft
  29. 2024-08-15 Ruben Safir <> Subject: [Hangout - NYLXS] Drug Price Controlls Bullshit
  30. 2024-08-16 Ruben Safir <> Subject: [Hangout - NYLXS] Iran - New Zealand - all the same
  31. 2024-08-17 Ruben Safir <> Subject: [Hangout - NYLXS] online privacy
  32. 2024-08-17 Ruben Safir <> Subject: [Hangout - NYLXS] Frontline on Israel
  33. 2024-08-18 Ruben Safir <> Subject: [Hangout - NYLXS] Gaza Abductions live video
  34. 2024-08-18 Ruben Safir <> Re: [Hangout - NYLXS] Gaza Abductions live video
  35. 2024-08-25 Ruben Safir <> Subject: [Hangout - NYLXS] Just before Shabbat my phone and email lit up
  36. 2024-08-25 Ruben Safir <> Subject: [Hangout - NYLXS] Parental Alienation is a mess..
  37. 2024-08-25 Ruben Safir <> Subject: [Hangout - NYLXS] 3000 missles a day..
  38. 2024-08-26 Ruben Safir <> Subject: [Hangout - NYLXS] Say what?
  39. 2024-08-26 Ruben Safir <> Re: [Hangout - NYLXS] Say what?
  40. 2024-08-28 Ruben Safir <> Subject: [Hangout - NYLXS] Get off the train

NYLXS are Do'ers and the first step of Doing is Joining! Join NYLXS and make a difference in your community today!