• Security researchers have uncovered a critical series of vulnerabilities in Commvault’s backup and data management software that could enable attackers to achieve remote code execution and compromise on-premises infrastructure. The flaws, discovered by Watchtowr Labs, represent a significant threat to organizations relying on Commvault’s widely-deployed backup solutions. The vulnerability chain consists of four distinct security […]

    The post Commvault Backup Suite Flaws Allow Attackers to Breach On-Premises Systems appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • DragonForce represents a sophisticated and rapidly evolving ransomware operation that has emerged as a significant threat in the cybersecurity landscape since late 2023.

    Operating under a Ransomware-as-a-Service (RaaS) model, this group has demonstrated exceptional adaptability by leveraging leaked ransomware builders from notorious families like LockBit 3.0 and Conti to create customized attack variants.

    The organization has successfully targeted high-profile victims across multiple sectors, including government entities, retail giants, and critical infrastructure, with notable attacks against the Ohio Lottery, Palau government, and major UK retailers like Marks & Spencer.

    Their operations combine advanced technical capabilities with professional business practices, offering affiliates up to 80% of ransom payments while providing comprehensive attack infrastructure and support services.

    Ransomware attack flow.
    Ransomware attack flow. (Source: cybersecuritynews.com)

    Introduction to DragonForce Ransomware

    DragonForce first appeared in December 2023 with the launch of their “DragonLeaks” dark web portal, quickly establishing themselves as a formidable player in the ransomware ecosystem.

    The group’s origins trace back to possible connections with DragonForce Malaysia, a hacktivist collective, though the current operation has evolved into a purely profit-driven enterprise.

    By 2025, DragonForce has matured into a sophisticated RaaS platform that attracts both displaced affiliates from dismantled ransomware operations and freelance threat actors seeking robust infrastructure.

    The organization operates two distinct ransomware variants based on leaked source code from established families. Their initial variant utilized the leaked LockBit 3.0 (Black) builder, allowing them to rapidly deploy effective ransomware without developing complex encryption mechanisms from scratch.

    In July 2024, DragonForce introduced a second variant based on the Conti V3 codebase, providing affiliates with enhanced customization capabilities. This dual-variant approach demonstrates the group’s technical sophistication and commitment to providing affiliates with diverse attack options.

    The group’s business model reflects modern cybercrime trends, offering a comprehensive platform that includes attack management tools, automated features, and customizable builders.

    Affiliates can tailor ransomware samples by disabling targeted security features, configuring encryption parameters, and personalizing ransom notes.

    In early 2025, DragonForce expanded its offerings by introducing a white-label ransomware service, enabling affiliates to rebrand payloads under alternative names for additional fees.

    Attack Vectors and Initial Access Techniques

    DragonForce employs multiple sophisticated vectors to achieve initial access to target networks, demonstrating the group’s understanding of diverse organizational vulnerabilities. 

    Phishing campaigns remain a primary attack vector, with operators crafting convincing spear-phishing emails containing malicious attachments or links that deploy ransomware payloads when executed by unsuspecting users.

    These campaigns often target specific individuals within organizations using social engineering techniques to increase success rates.

    Exploitation of known vulnerabilities represents another critical attack vector, with DragonForce operators actively targeting unpatched systems.

    The group has specifically been associated with exploiting several high-impact vulnerabilities, including CVE-2021-44228 (Log4Shell), CVE-2023-46805 (Ivanti Connect Secure Authentication Bypass), CVE-2024-21412 (Microsoft Windows SmartScreen Bypass), CVE-2024-21887 (Ivanti Connect Secure Command Injection), and CVE-2024-21893 (Ivanti Connect Secure Path Traversal).

    DragonForce affiliates systematically target organizations with poorly secured remote access infrastructure, leveraging stolen or weak credentials to establish a persistent network presence.

    The group also exploits trusted relationships, as demonstrated in a recent incident where attackers gained access through remote management software installed by a previous hosting company that was never properly removed.

    In some cases, DragonForce operators have gained initial access by exploiting compromised managed service provider (MSP) relationships, allowing them to move laterally across multiple client environments through trusted connections.

    This technique amplifies the impact of individual breaches by providing access to numerous organizations through a single compromise point.

    Remote Desktop Protocol (RDP) and VPN attacks constitute significant initial access methods, with operators conducting credential stuffing attacks and brute-force operations against exposed services.

    Cyber Kill Chain.
    Cyber Kill Chain. (Source: cybersecuritynews.com)

    Tactics, Techniques, and Procedures (TTPs)

    DragonForce’s operational methodology follows the MITRE ATT&CK framework across multiple tactics, demonstrating a sophisticated understanding of enterprise network compromise techniques.

    Initial AccessT1190Exploit Public-Facing ApplicationExploits CVE-2021-44228 (Log4Shell), CVE-2023-46805, CVE-2024-21412, CVE-2024-21887, CVE-2024-21893HighMedium
    Initial AccessT1078Valid AccountsUses stolen/weak RDP and VPN credentials, brute force attacks on remote access servicesHighLow
    Initial AccessT1566.001Spearphishing AttachmentDeploys ransomware through malicious email attachments targeting specific individualsHighMedium
    Initial AccessT1566.003Spearphishing via ServiceConducts vishing (voice phishing) campaigns alongside email phishingMediumHigh
    Initial AccessT1199Trusted RelationshipExploits compromised MSP relationships and previous hosting company accessMediumHigh
    ExecutionT1204.002Malicious FileSocial engineering users to execute ransomware payloads, moves files to System32HighLow
    ExecutionT1059.001PowerShellUses PowerShell for command execution, payload deployment, and system reconnaissanceHighMedium
    ExecutionT1053.005Scheduled Task/JobCreates scheduled tasks for persistence and automated executionMediumLow
    PersistenceT1574.011Services File Permissions WeaknessInstalls AnyDesk remote access tool for persistent backdoor accessHighMedium
    PersistenceT1053.005Scheduled Task/JobEstablishes scheduled tasks to maintain persistence across rebootsMediumLow
    PersistenceT1547.001Registry Run Keys / Startup FolderModifies registry Run keys to ensure malware execution at startupMediumLow
    Privilege EscalationT1134Access Token ManipulationDuplicates SYSTEM-level access tokens using DuplicateTokenEx() APIHighHigh
    Privilege EscalationT1068Exploitation for Privilege EscalationLeverages known vulnerabilities for escalation to administrator privilegesMediumMedium
    Defense EvasionT1027Obfuscated Files or InformationEmbeds Chinese text signatures, uses code obfuscation techniquesHighHigh

    Indicators of Compromise (IoCs)

    Security teams should monitor for specific indicators associated with DragonForce campaigns to enable early detection and response. 

    Network indicators include command and control server IP addresses: 2[.]147[.]68[.]96185[.]59[.]221[.]75, and 69[.]4[.]234[.]20. Notably, early campaign infrastructure was identified in Iran, suggesting international collaboration or infrastructure rental.

    IoC TypeIndicatorDescriptionThreat LevelDetection Method
    IP Address (C&C)2.147.68.96Command and Control serverHighNetwork monitoring, firewall logs
    IP Address (C&C)185.59.221.75Command and Control serverHighNetwork monitoring, firewall logs
    IP Address (C&C)69.4.234.20Command and Control serverHighNetwork monitoring, firewall logs
    File Hash (SHA256)b9bba02d18bacc4bc8d9e4f70657d381568075590cc9d0e7590327d854224b32DragonForce ransomware executable hashCriticalFile integrity monitoring, antivirus
    File Hash (SHA256)ba1be94550898eedb10eb73cb5383a2d1050e96ec4df8e0bf680d3e76a9e2429DragonForce payload hashCriticalFile integrity monitoring, antivirus
    File Hash (SHA256)d626eb0565fac677fdc13fb0555967dc31e600c74fbbd110b744f8e3a59dd3f9DragonForce variant hashCriticalFile integrity monitoring, antivirus
    File PathC:\Users\Public\Documents\Winupdate.exeExfiltration tool locationHighFile system monitoring, EDR
    File PathC:\Windows\System32\Winupdate.exeAlternative exfiltration tool pathHighFile system monitoring, EDR
    File PathC:\Users\Public\log.logSystem information log fileMediumFile system monitoring
    File PathC:\Windows\System32\Common payload deployment directoryMediumDirectory monitoring
    FilenameWinupdate.exeData exfiltration utility (GoLang)HighProcess monitoring, EDR
    FilenameFileSeek.exeFile discovery reconnaissance toolMediumProcess monitoring
    FilenameREADME.txtRansom note filenameLowFile system monitoring
    FilenameSystemBCSOCKS5 backdoor for persistenceHighNetwork monitoring, process monitoring
    File Extension.dragonforce_encryptedEncrypted file extensionMediumFile system monitoring
    Domain (.onion)z3wqggtxft7id3ibr7srivv5gjof5fwg76slewnzwwakjuf3nlhukdid.onionDragonLeaks leak siteHighNetwork monitoring, DNS logs
    Domain (.onion)3pktcrcbmssvrnwe5skburdwe2h3v6ibdnn5kbjqihsg6eu6s6b7ryqd.onionAlternative leak site domainHighNetwork monitoring, DNS logs

    The Marks & Spencer incident in April 2025 caused estimated losses of £300 million and months-long operational disruption, with attackers sending direct emails to the CEO demanding ransom payments.

    These cases illustrate DragonForce’s capability to target both government infrastructure and private sector organizations with devastating effectiveness, emphasizing the critical need for comprehensive cybersecurity measures and incident response planning.

    Find this Story Interesting! Follow us on LinkedIn and X to Get More Instant Updates.

    The post DragonForce Ransomware Attack Analysis – Targets, TTPs and IoCs appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • The financially motivated threat group UNC5518 has been infiltrating trustworthy websites to install ClickFix lures, which are misleading phony CAPTCHA pages, as part of a complex cyber campaign that has been monitored since June 2024. These malicious pages trick users into executing downloader scripts that initiate infection chains, often leading to malware deployment by affiliated […]

    The post UNC5518 Group Hacks Legitimate Sites with Fake Captcha to Deliver Malware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers have disclosed details of a new malware loader called QuirkyLoader that’s being used to deliver via email spam campaigns an array of next-stage payloads ranging from information stealers to remote access trojans since November 2024. Some of the notable malware families distributed using QuirkyLoader include Agent Tesla, AsyncRAT, Formbook, Masslogger, Remcos RAT,

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • As security professionals, it’s easy to get caught up in a race to counter the latest advanced adversary techniques. Yet the most impactful attacks often aren’t from cutting-edge exploits, but from cracked credentials and compromised accounts. Despite widespread awareness of this threat vector, Picus Security’s Blue Report 2025 shows that organizations continue to struggle with preventing

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Cybersecurity researchers are highlighting a dangerous attack technique that combines rogue IPv6 configuration with NTLM credential relay to achieve complete Active Directory domain compromise, exploiting default Windows configurations that most organizations leave unchanged. Attack Leverages Default Windows IPv6 Behavior The MITM6 + NTLM Relay attack exploits Windows systems’ automatic DHCPv6 requests, even in networks that […]

    The post MITM6 + NTLM Relay Attack Enables Full Domain Compromise appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • CISA issued four comprehensive Industrial Control Systems (ICS) advisories on August 19, 2025, highlighting serious vulnerabilities affecting critical infrastructure sectors including energy and manufacturing.

    These advisories detail exploitable vulnerabilities with CVSS scores ranging from 5.8 to 9.8, requiring immediate attention from system administrators and security professionals.

    Key Takeaways
    1. CISA issued four ICS advisories for Siemens, Tigo Energy, and EG4 systems affecting critical infrastructure.
    2. Critical vulnerabilities (CVSS up to 9.8) enable remote attacks and system compromise.
    3. Update immediately - Apply vendor patches and implement network segmentation.

    Critical Siemens Vulnerabilities 

    Two significant Siemens advisories were released addressing distinct attack vectors. Advisory ICSA-25-231-01 covers the Desigo CC Product Family and SENTRON Powermanager, identifying a least privilege violation (CWE-272) vulnerability tracked as CVE-2025-47809 with a CVSS v3.1 score of 8.2. 

    This vulnerability affects Wibu CodeMeter components across multiple product versions (V5.0 through V8), enabling privilege escalation through the CodeMeter Control Center component immediately after installation.

    The second Siemens advisory, ICSA-25-231-02, addresses the Mendix SAML Module with a more severe improper verification of cryptographic signature (CWE-347) vulnerability. 

    CVE-2025-40758 carries a CVSS v3.1 score of 8.7 and enables unauthenticated remote attackers to hijack accounts in specific Single Sign-On (SSO) configurations.

    The vulnerability affects multiple Mendix versions, with patches available requiring updates to V3.6.21, V4.0.3, or V4.1.2 depending on the deployment.

    Tigo and EG4 Infrastructure Vulnerabilities

    The energy sector faces particularly severe threats with two advisories targeting solar energy infrastructure. 

    ICSA-25-217-02 addresses Tigo Energy’s Cloud Connect Advanced devices with three critical vulnerabilities: hard-coded credentials (CWE-798), command injection (CWE-77), and predictable PRNG seeds (CWE-337). 

    CVE-2025-7768 received the highest CVSS v4 score of 9.3, while CVE-2025-7769 and CVE-2025-7770 both scored 8.7.

    EG4 Electronics inverters, covered in advisory ICSA-25-219-07, present four distinct vulnerabilities including cleartext transmission (CWE-319), firmware integrity issues (CWE-494), observable discrepancies (CWE-203), and authentication bypass (CWE-307). 

    The most critical, CVE-2025-46414, achieved a CVSS v4 score of 9.2, though EG4 deployed server-side fixes for some vulnerabilities in April 2025.

    Mitigations

    Siemens requires CodeMeter updates to version 8.30a and enables UseEncryption configurations for SAML modules. 

    Tigo Energy is developing comprehensive fixes, while EG4 has implemented server-side patches and plans new hardware releases by October 15, 2025.

    CISA emphasizes implementing defense-in-depth strategies, including network segmentation, VPN-secured remote access, and firewall isolation. 

    Organizations should prioritize impact analysis and risk assessment before deploying defensive measures, while monitoring for suspicious activity and reporting incidents to CISA for correlation analysis. 

    No public exploitation has been reported for these specific vulnerabilities, providing a critical window for remediation efforts.

    Safely detonate suspicious files to uncover threats, enrich your investigations, and cut incident response time. Start with an ANYRUN sandbox trial → 

    The post CISA Releases Four ICS Advisories Surrounding Vulnerabilities, and Exploits appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Researchers at Push Security have discovered a new phishing campaign that targets Microsoft 365 (M365) systems and uses Active Directory Federation Services (ADFS) to enable credential theft. This attack vector exploits Microsoft’s authentication redirect mechanisms, effectively turning a legitimate service into a conduit for phishing operations. Sophisticated Phishing Infrastructure The campaign begins with malvertising lures […]

    The post New Campaign Uses Active Directory Federation Services to Steal M365 Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • Security researchers at Imperva have disclosed a critical pre-handshake memory exhaustion vulnerability in the widely-used LSQUIC QUIC implementation that enables remote attackers to crash servers through denial-of-service attacks. The flaw, designated CVE-2025-54939 and dubbed “QUIC-LEAK,” bypasses standard QUIC connection-level protections by triggering before any handshake is established, leaving servers vulnerable to unbounded memory growth and […]

    The post QUIC-LEAK Vulnerability Allows Attackers to Drain Server Memory and Cause DoS appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

  • A sophisticated attack chain that combines MITM6 with NTLM relay techniques to achieve full Active Directory domain compromise. 

    The attack exploits Windows’ default IPv6 auto-configuration behavior, allowing attackers to escalate from network access to Domain Admin privileges in minutes. 

    Key Takeaways
    1. Abuses Windows IPv6 auto-config and AD's 10-machine account quota for domain compromise.
    2. Uses mitm6 + ntlmrelayx to create malicious accounts with RBCD to reach Domain Admin quickly.
    3. Fix: Disable IPv6, set ms-DS-MachineAccountQuota = 0, enable signing, deploy DHCPv6 Guard.

    This technique poses significant risks to organizations running standard Windows environments, as it leverages built-in protocols rather than requiring malware or zero-day exploits.

    IPv6 Auto-Configuration Attack

    Resecurity reports that the MITM6 attack targets a fundamental Windows behavior: automatic DHCPv6 requests sent when systems boot or connect to networks. 

    Even in organizations not actively using IPv6, Windows machines prioritize IPv6 configuration over IPv4, creating an exploitable attack surface.

    Attackers deploy the mitm6 tool to act as a rogue DHCPv6 server, responding to these requests and assigning malicious DNS server addresses to victim machines. 

    The command sudo mitm6 -d target.local –no-ra establishes the attacker as the authoritative DNS server for the target domain.

    Attack chain
    Attack chain

    The attack chain continues with ntlmrelayx from the Impacket toolkit, which intercepts NTLM authentication attempts through WPAD (Web Proxy Auto-Discovery Protocol) spoofing. 

    The tool executes: sudo impacket-ntlmrelayx -ts -6 -t ldaps://target.local -wh fakewpad –add-computer –delegate-access, creating malicious computer accounts and configuring Resource-Based Constrained Delegation (RBCD).

    Active Directory’s default ms-DS-MachineAccountQuota setting allows any authenticated user to add up to 10 machine accounts, enabling attackers to create controlled computer objects, reads the report.

    These accounts can then modify their msDS-AllowedToActOnBehalfOfOtherIdentity attribute, allowing impersonation of privileged accounts, including Domain Administrators.

    Recommendations

    The attack’s impact extends far beyond initial network compromise. Once successful, attackers can extract NTLM hashes using secretsdump.py “target.local/User:Password@target.local” and conduct lateral movement with tools like CrackMapExec: crackmapexec smb 10.0.0.1/8 -u administrator -H 1f937b21e2e0ada0d3d3f7cf58c8aade –share.

    Take Control of Compromised Machines
    Take Control of Compromised Machines

    Organizations face severe consequences, including full domain compromise, credential theft, service disruption, and potential data exfiltration. 

    The attack’s stealthy nature makes detection challenging, as it abuses legitimate Windows protocols.

    Critical mitigation strategies include disabling IPv6 when not required, setting ms-DS-MachineAccountQuota = 0 to prevent unauthorized computer account creation, and enforcing SMB and LDAP signing to prevent relay attacks. 

    Network-level defenses should implement DHCPv6 Guard on switches and routers to block unauthorized IPv6 advertisements.

    This attack demonstrates how default configurations can create significant security vulnerabilities, emphasizing the need for proactive hardening of Active Directory environments and continuous monitoring for rogue network services.

    Safely detonate suspicious files to uncover threats, enrich your investigations, and cut incident response time. Start with an ANYRUN sandbox trial → 

    The post New MITM6 + NTLM Relay Attack Let Attackers Escalate Privileges and Compromise Entire Domain appeared first on Cyber Security News.

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶

    ¶¶¶¶¶