OSINT collection playbooks updated with new threats: Nighthawk, Rhadamanthys, etc. 🦠

Each month SEKOIA.IO updates the configuration of its collection playbooks to automatically gather Indicators of Compromise (IoCs) of new threats. Our collection playbooks are aggregating, enriching and contextualising IoCs from community threat intelligence feeds (URLhaus, ThreatFox, and others) and analysis of Hatching Triage sandbox. This time, we have added:

  • Recent commodity malware sold as a Malware-as-a-Service: PureLogs, Rhadamanthys, Gomorrah stealer;
  • And other malware families: Nighthawk, Chaos botnet, Rafel RAT.

SEKOIA proactively monitors new malware advertised on underground forums or Telegram channels, as well as the threat groups operating them. If you want to know more about these malware families, read the associated malware object in the SEKOIA.IO Intelligence Center.

What do you think about this update?