Author Archives: CSIRT

Ransomware hits helicopter maker Kopter

Data from Kopter’s internal network has been published on the LockBit gang’s blog, hosted on the dark web. Helicopter maker Kopter has fallen victim to a ransomware attack after hackers breached its internal network and encrypted the company’s files. After Kopter refused to engage with the hackers, the ransomware gang has published on Friday some of the […]

Iranian Hackers Access Unprotected ICS at Israeli Water Facility

A group of Iranian hackers recently posted a video showing how they managed to access an industrial control system (ICS) at a water facility in Israel. According to industrial cybersecurity firm OTORIO, the hackers accessed a human-machine interface (HMI) system that was directly connected to the internet without any authentication or other type of protection. […]

xHunt Campaign: Newly Discovered Backdoors Using Deleted Email Drafts and DNS Tunneling for Command and Control

Executive Summary The xHunt campaign has been active since at least July 2018 and we have seen this group target Kuwait government and shipping and transportation organizations. Recently, we observed evidence that the threat actors compromised a Microsoft Exchange Server at an organization in Kuwait. We do not have visibility into how the actors gained […]