COVID-19 Chinoxy Backdoor: A Network Perspective
A prolific threat actor, active in Asia, sends documents to people in Kyrgyzstan about how the United Nations is helping to fight COVID-19. Nozomi Networks Labs examines how network traffic analysis can detect this specific threat. The post COVID-19 Chinoxy Backdoor: A Network Perspective appeared first on Nozomi Networks ... Read More
Act Now on Critical Microsoft SMB Vulnerability (CVE-2020-0796)
On March 10th, Microsoft published a security advisory of critical severity for CVE-2020-0796, which is a remote code execution vulnerability affecting the Microsoft Server Message Block 3.1.1 (SMBv3). The post Act Now on Critical Microsoft SMB Vulnerability (CVE-2020-0796) appeared first on Nozomi Networks ... Read More
New Wave of Ransomware Threatens OT Security and Reliability
The post New Wave of Ransomware Threatens OT Security and Reliability appeared first on Nozomi Networks ... Read More
Snake Ransomware is Raising Concerns for Industrial Controls Systems
A recently discovered file-encrypting ransomware is raising concerns for industrial control system (ICS) operators. Read on to learn what we now know about the Snake ransomware, and our recommendations for protecting your ICS systems. The post Snake Ransomware is Raising Concerns for Industrial Controls Systems appeared first on Nozomi Networks ... Read More
Black Hat: The Future of Securing Power Grid Intelligent Devices
Today at Black Hat USA we’re presenting an innovative power grid cyber security solution that greatly improves monitoring of intelligent electronic devices (IEDs). Using the IEC 62351 standard for monitoring industrial networks, we demonstrate how four types of hard-to-detect attacks are readily identified. The post Black Hat: The Future of ... Read More
Breaking Research: LockerGoga Ransomware Impacts Norsk Hydro
It was reported today that Norsk Hydro has temporarily stopped aluminum production at several plants following an attack by the ransomware known as LockerGoga. Nozomi Networks Labs has conducted a preliminary evaluation of LockerGoga. Read on to learn about this ransomware and our research team’s assessment of it. The post ... Read More
GreyEnergy Malware Research Paper: Maldoc to Backdoor
When the GreyEnergy Advanced Persistent Threat (APT) was unveiled last year, I decided to put my reverse engineering skills to work and study one of its infection techniques. Find out about the methods the malware’s packer stage used to conceal its true functionality, plus get access to my full Research ... Read More
Analyzing the GreyEnergy Malware: from Maldoc to Backdoor
GreyEnergy is an Advanced Persistent Threat (APT) which has been targeting industrial networks in Eastern European countries for several years. As a security analyst, I have studied the malware and provide a detailed description of how it works, from the moment that someone receives a phishing email, until the malware ... Read More
GreyEnergy Malware Targets Industrial Critical Infrastructure
Recently a new advanced threat targeting the energy sector was disclosed. Called GreyEnergy, this malware is the successor to BlackEnergy, which brought down part of the Ukraine power grid in 2015. Because of the significance of the malware, our Nozomi Networks Security Research team is evaluating it. Find out what ... Read More


