# Weekly Community Review - March 10, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-march-10-2023/356>\
**Category:** Announcements\
**Created:** [March 11, 2023, 2:36am UTC](https://community.emergingthreats.net/t/weekly-community-review-march-10-2023/356 "2023-03-11T02:36:38Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [March 11, 2023, 2:36am UTC](https://community.emergingthreats.net/t/weekly-community-review-march-10-2023/356/1 "2023-03-11T02:36:38Z")

</div>

It’s (almost) the weekend. Thanks to the suricata IDS infosec community we had 131 signatures added to ET Open in the last 5 days–and they’re there for you to use with thousands more! Take a look here, [https://rules.emergingthreatspro.com/open/](https://t.co/j7Vc3tNy6L), and lets go over a few…

First I want to shout-out the researchers who work so hard to share their good work on [#Gamaredon](https://twitter.com/hashtag/Gamaredon?src=hashtag_click)–particularly [@StopMalvertisin](https://twitter.com/StopMalvertisin),[@Cyber0verload](https://twitter.com/Cyber0verload),[@500mk500](https://twitter.com/500mk500), and [@malPileDiver](https://twitter.com/malPileDiver).

First up is[@Cyber0verload](https://twitter.com/Cyber0verload) (2044523) - with a hash and a sample that allowed us to model detection logic after content in the user agent field.

> <https://twitter.com/Cyber0verload/status/1633122380171051009>

They also tipped up multiple [#Gamaredon](https://twitter.com/hashtag/Gamaredon?src=hashtag_click) domains that we sig’d up to provide notification of DNS queries - potential indicators querying hosts may be compromised. SIDs 2044441-2044445 will let you know.

> <https://twitter.com/Cyber0verload/status/1632479604945428484>

Next, thanks to [@malPileDiver](https://twitter.com/malPileDiver) for the shout-out to identify a couple more [#Gamaredon](https://twitter.com/hashtag/Gamaredon?src=hashtag_click)-involved domains - these are SIDs 2044439 and 2044440.

> <https://twitter.com/malPileDiver/status/1632447537767501826>

Remember, there are many ways to reach out to us with a tip-up on an interesting hash, article, or even detection logic you’ve created: [Twitter](https://twitter.com/et_labs), here on [https://community.emergingthreats.net](https://t.co/vCn6PWHiB7), on our mailing list via support[at]emergingthreats[dot]net or on our Discord (DM for an invite!).

Back to the week - from [@h2jazi](https://twitter.com/h2jazi), with a hash and analysis that allowed us to model the network traffic of a backdoor exfiltrating data! SIDs 2044437 (DNS lookup for malicious domain) and 2044438 (Data exfil!)

> <https://twitter.com/h2jazi/status/1630983583727747085>

More data exfil via Telegram from [@suyog42](https://twitter.com/suyog42), [#LucaStealer](https://twitter.com/hashtag/LucaStealer?src=hashtag_click) Sending System Information (SID 2044524):

> <https://twitter.com/suyog41/status/1631189160093425664>

From [@James\_inthe\_box](https://twitter.com/James_inthe_box), still more Telegram exfil: SID 2044527 for [#vectorstealer](https://twitter.com/hashtag/vectorstealer?src=hashtag_click) - thanks for the tweet!

> <https://twitter.com/James_inthe_box/status/1633503622381322242>

Industry time - here’s a few blogs and such that tipped us up to techniques and detection logic.[@uptycs](https://twitter.com/uptycs), thanks for SIDs 2044449 and 2044450 - call and response alerts for Parallax RAT from here:

> **[Cryptocurrency Entities at Risk: Threat Actor Uses Parallax RAT for Infiltration](https://t.co/YxhcJ03L6c)**
>
> The Uptycs Threat Research team has recently detected active samples of the Parallax remote access Trojan (RAT) targeting cryptocurrency organizations.

From [@morphisec](https://twitter.com/morphisec), C2 traffic and malicious domain information that led us to 2044505-2044515. Sourced from:

> **[SYS01 Stealer Will Steal Your Facebook Info](https://t.co/zzckhxOg7B)**
>
> A new, highly evasive info stealer Morphisec has dubbed SYS01stealer targets personal and business Facebook accounts.

Hiatus RAT c2 coverage (SID 2044503), thanks to [@BlackLotusLabs](https://twitter.com/BlackLotusLabs) and this blog:

> **[New HiatusRAT router malware covertly spies on victims - Lumen](https://t.co/Xn09w1KJHD)**
>
> Lumen Black Lotus Labs identified a new campaign involving compromised routers. HiatusRAT allows threat actors to remotely interact with the system.

An inbound C2 GET alert modeled from this [@bridewellsec](https://twitter.com/bridewellsec) blog content, thanks for 2044535!

> **[Threat Advisory: Bridewell Sounds the Alarm on New 'I'm Better' Malware...](https://t.co/DnbzgRK4iN)**
>
> Bridewell Cyber Threat Intelligence has identified a previously unreported infostealer, named "I'm Better", that targets valuable information such as cryptocurrency wallets, browser credentials, and session cookies.

And lastly, from [@_CPResearch_](https://twitter.com/_CPResearch_), a sig alerting on [#SharpPanda](https://twitter.com/hashtag/SharpPanda?src=hashtag_click) Soul Framework activity, SID 2044564. Thanks for sharing!

> **[Pandas with a Soul: Chinese Espionage Attacks Against Southeast Asian...](https://t.co/irkFVE5IH0)**
>
> Executive summary In 2021, Check Point Research published a report on a previously undisclosed toolset used by Sharp Panda, a long-running Chinese cyber-espionage operation targeting Southeast Asian government entities. Since then, we...

That’s all for this week everyone - be well and enjoy the weekend.
