<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>MooBot &#8211; DEVOQ Technology</title>
	<atom:link href="https://www.devoq.gr/tag/moobot/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.devoq.gr</link>
	<description></description>
	<lastBuildDate>Sat, 21 Jun 2025 12:17:37 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://i0.wp.com/www.devoq.gr/wp-content/uploads/2018/07/cropped-logo_ico.png?fit=32%2C32&#038;ssl=1</url>
	<title>MooBot &#8211; DEVOQ Technology</title>
	<link>https://www.devoq.gr</link>
	<width>32</width>
	<height>32</height>
</image> 
<site xmlns="com-wordpress:feed-additions:1">192885280</site>	<item>
		<title>Threat Advisory – September 1 &#8211; 7</title>
		<link>https://www.devoq.gr/2022/09/07/threat-advisory-september-1-7/</link>
					<comments>https://www.devoq.gr/2022/09/07/threat-advisory-september-1-7/#respond</comments>
		
		<dc:creator><![CDATA[DEVOQ Technology]]></dc:creator>
		<pubDate>Wed, 07 Sep 2022 10:19:42 +0000</pubDate>
				<category><![CDATA[News]]></category>
		<category><![CDATA[D-Link devices]]></category>
		<category><![CDATA[Mirai botnet]]></category>
		<category><![CDATA[MooBot]]></category>
		<guid isPermaLink="false">https://devoq.gr/?p=11114952</guid>

					<description><![CDATA[A variant of the Mirai botnet known as MooBot is co-opting vulnerable D-Link devices into an army of denial-of-service bots by taking advantage of multiple exploits.]]></description>
										<content:encoded><![CDATA[
	<div id="text-2214043253" class="text">
		

<h1><span style="color: #282828;">CySec News</span></h1>
<p><span style="color: #282828;">A variant of the Mirai botnet known as MooBot is co-opting vulnerable D-Link devices into an army of denial-of-service bots by taking advantage of multiple exploits.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://thehackernews.com/2022/09/mirai-variant-moobot-botnet-exploiting.html</span></p>
<p> </p>
<p><span style="color: #282828;">Networking equipment maker Zyxel has released patches for a critical security flaw impacting its network-attached storage (NAS) devices. Tracked as <a style="color: #282828;" href="https://nvd.nist.gov/vuln/detail/CVE-2022-34747" target="_blank" rel="noopener">CVE-2022-34747</a> (CVSS score: 9.8), the issue relates to a &#8220;format string vulnerability&#8221; affecting NAS326, NAS540, and NAS542 models. Zyxel credited researcher Shaposhnikov Ilya for reporting the flaw.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://thehackernews.com/2022/09/critical-rce-vulnerability-affects.html</span></p>
<p> </p>
<p><span style="color: #282828;">QNAP has issued a new advisory urging users of its network-attached storage (NAS) devices to upgrade to the latest version of <a style="color: #282828;" href="https://www.qnap.com/en/software/photo-station" target="_blank" rel="noopener">Photo Station</a> following yet another wave of <a style="color: #282828;" href="https://thehackernews.com/2022/06/critical-php-vulnerability-exposes-qnap.html" target="_blank" rel="noopener">DeadBolt ransomware attacks</a> in the wild by exploiting a zero-day flaw in the software.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://thehackernews.com/2022/09/qnap-warns-of-new-deadbolt-ransomware.html</span></p>
<p> </p>
<p><span style="color: #282828;">A new stealthy Linux malware known as Shikitega has been discovered infecting computers and IoT devices with additional payloads. The malware exploits vulnerabilities to elevate its privileges, adds persistence on the host via crontab, and eventually launches a cryptocurrency miner on infected devices.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://www.bleepingcomputer.com/news/security/new-linux-malware-evades-detection-using-multi-stage-deployment/</span></p>
<p> </p>
<p><span style="color: #282828;">Resecurity has identified a new underground service that allows cybercriminals to bypass 2FA authentication (MFA) authentication mechanisms on a large scale without the need to hack upstream services or the supply chain. EvilProxy actors are using Reverse Proxy and Cookie Injection methods to bypass 2FA authentication – proxyfying victim’s session.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://otx.alienvault.com/pulse/63175332703dcba6367c4087</span></p>
<p> </p>
<p><span style="color: #282828;">Bitdefender analyzed a recent industrial espionage operation targeting a small (under 200 employees) technology company based in the United States. The attack was focused on information exfiltration and spans several months. A vast network of several hundred IP addresses (most of them originated from China) was used as part of this attack.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://otx.alienvault.com/pulse/6310c8b1ae9f85af2d64d77d</span></p>
<p> </p>
<p><span style="color: #282828;">The Securonix Threat research team has recently identified a unique sample of a persistent Golang-based attack campaign tracked by Securonix as GO#WEBBFUSCATOR. The new campaign incorporates an equally interesting strategy by leveraging the infamous deep field image taken from the James Webb telescope and obfuscated Golang programming language payloads to infect the target system with the malware.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://otx.alienvault.com/pulse/630f67c49a28f85f26b91f5a</span></p>
<p> </p>
<p><span style="color: #282828;">Microsoft warned customers today that it will finally disable basic authentication in random tenants worldwide to improve Exchange Online security starting October 1, 2022.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://www.bleepingcomputer.com/news/microsoft/microsoft-will-disable-exchange-online-basic-auth-next-month/</span></p>
<p> </p>
<p><span style="color: #282828;">South Korean chaebol Samsung on Friday said it experienced a cybersecurity incident that resulted in the unauthorized access of some customer information, the second time this year it has reported such a breach. &#8220;In late July 2022, an unauthorized third-party acquired information from some of Samsung&#8217;s U.S. systems,&#8221; the company <a style="color: #282828;" href="https://www.samsung.com/us/support/securityresponsecenter/" target="_blank" rel="noopener">disclosed</a> in a notice. &#8220;On or around August 4, 2022, we determined through our ongoing investigation that personal information of certain customers was affected.&#8221;</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://thehackernews.com/2022/09/samsung-admits-data-breach-that-exposed.html</span></p>
<p> </p>
<p><span style="color: #282828;">A bad Microsoft Defender signature update mistakenly detects Google Chrome, Microsoft Edge, Discord, and other Electron apps as &#8216;Win32/Hive.ZY&#8217; each time the apps are opened in Windows. The issue started Sunday morning when Microsoft pushed out Defender <a style="color: #282828;" href="https://www.microsoft.com/en-us/wdsi/definitions/antimalware-definition-release-notes?requestVersion=1.373.1508.0" target="_blank" rel="nofollow noopener">signature update 1.373.1508.0</a> to include two new threat detections, including <a style="color: #282828;" href="https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Behavior:Win32/Hive.ZY&amp;ThreatID=2147830806" target="_blank" rel="nofollow noopener">Behavior:Win32/Hive.ZY</a>. Microsoft issued an update to fix the issue.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-falsely-detects-win32-hivezy-in-google-chrome-electron-apps/</span></p>
<p> </p>
<p><span style="color: #282828;">Chile&#8217;s national computer security and incident response team (CSIRT) has announced that a ransomware attack has impacted operations and online services of a government agency in the country. The attack started on Thursday, August 25, targeting Microsoft and VMware ESXi servers operated by the agency. The hackers stopped all running virtual machines and encrypted their files, appending the &#8220;.crypt&#8221; filename extension.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://www.bleepingcomputer.com/news/security/new-ransomware-hits-windows-linux-servers-of-chile-govt-agency/</span></p>
<p> </p>
<p><span style="color: #282828;">The government of Montenegro has provided more information about the attack on its critical infrastructure saying that ransomware is responsible for the damage and disruptions. Public Administration Minister Maras Dukaj stated on local television yesterday that behind the attack is an organized cybercrime group. The effects of the incindet continue for the tenth day. The minister added that a &#8220;special virus&#8221; is used in this attack and there is a ransom demand of $10 million.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://www.bleepingcomputer.com/news/security/montenegro-hit-by-ransomware-attack-hackers-demand-10-million/</span></p>
<p> </p>
<p><span style="color: #282828;">A new Instagram phishing campaign is underway, attempting to scam users of the popular social media platform by luring them with a blue-badge offer. Blue badges are highly coveted as Instagram provides them to accounts it verified to be authentic, representing a public figure, celebrity, or brand. The spear emails in the recently observed phishing campaign inform recipients that they Instagram reviewed their accounts and deemed them eligible for a blue badge.</span></p>
<p><span style="color: #282828;"><strong>Reference:</strong> https://www.bleepingcomputer.com/news/security/thousands-lured-with-blue-badges-in-instagram-phishing-attack/</span></p>
		
<style>
#text-2214043253 {
  text-align: center;
  color: rgb(0,0,0);
}
#text-2214043253 > * {
  color: rgb(0,0,0);
}
</style>
	</div>
	

]]></content:encoded>
					
					<wfw:commentRss>https://www.devoq.gr/2022/09/07/threat-advisory-september-1-7/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">11114952</post-id>	</item>
	</channel>
</rss>
