# Weekly Community Review - March 17, 2023

**URL:** <https://community.emergingthreats.net/t/weekly-community-review-march-17-2023/366>\
**Category:** Announcements\
**Created:** [March 17, 2023, 10:22pm UTC](https://community.emergingthreats.net/t/weekly-community-review-march-17-2023/366 "2023-03-17T22:22:47Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rgonzalez](https://avatars.discourse-cdn.com/v4/letter/r/bc79bd/32.png) [@rgonzalez](https://community.emergingthreats.net/u/rgonzalez)\
**Post date:** [March 17, 2023, 10:22pm UTC](https://community.emergingthreats.net/t/weekly-community-review-march-17-2023/366/1 "2023-03-17T22:22:47Z")

</div>

Happy St. Patrick’s Day all - greetings on another Friday. Big week for us in the Suricata IDS community with over 100 (113!) signatures added to ET Open! Check them out [here](https://rules.emergingthreatspro.com/open/) and lets chat on a few.

From [@Gi7w0rm](https://twitter.com/Gi7w0rm), a tip-up and a [@hatching\_io](https://twitter.com/hatching_io) run allowing us to sig on Amadey bot POSTs in 2044597 and 2044623 - thanks!

> <https://twitter.com/Gi7w0rm/status/1633851568482054146>

Coverage for exfils viaTelegram, a couple sigs from this [@suyog41](https://twitter.com/suyog41) tweet on a Rust stealer. SIDs 2044598 and 2044599.

> <https://twitter.com/suyog41/status/1635640558273146880>

Friend of ET [@malwareforme](https://twitter.com/malwareforme) contributes towards SID 2044625 - bolstering our sidecopy APT coverage with this alert on system info being sent outward for recon and data leakage. Thanks and hope you’re well!

> <https://twitter.com/malwareforme/status/1636005291849396224>

On sidecopy APT POST activity, we’ve also got 2044645 from [@fmc\_nan](https://twitter.com/fmc_nan). Thanks for the tweet!

> <https://twitter.com/fmc_nan/status/1634096201577660416>

Old home week continues with good friend contributing on our Emerging Threats Discord 2044600 for a sideshow outbound CnC Auth. DM for an invite and thank you [@travisbgreen](https://twitter.com/travisbgreen)!

Tip-ups and feedback can help us see where existing coverage can be tuned. For [@0xrb](https://twitter.com/0xrb), their tweet let us tidy up Android/SOVA sigs (2033940, 2033941, 2033942, 2033943, 2033944) that were FN due to some user-agent filtering. Thanks for the tag!

> <https://twitter.com/0xrb/status/1633034670815469569>

Both [@StopMalvertisin](https://twitter.com/StopMalvertisin) and [@t3ft3lb](https://twitter.com/t3ft3lb) taking it to MustangPanda APT - alerts on both inbound and outbound activity. Thanks for your work that led to SIDs 2044640-2044642.

> <https://twitter.com/StopMalvertisin/status/1635620870214352901>

and

> <https://twitter.com/t3ft3lb/status/1635597523434762240>

The industry helped contribute tips to ET Open this week as well - here’s [@Mandiant](https://twitter.com/Mandiant) with their Lightshow blog writeup giving us domains for these DNS query SIDs: 2044601-2044613 from here:

> **[Stealing the LIGHTSHOW (Part One) — North Korea's UNC2970 | Mandiant](https://www.mandiant.com/resources/blog/lightshow-north-korea-unc2970)**
>
> A campaign from a suspected North Korean espionage group.

From [@SentinelOne](https://twitter.com/SentinelOne), more than a few DNS sigs on Winter Vivern APT (SIDs 2044656-2044661) as well as C2 Check-in (2044662) and payload retrieval (2044663-2044664) - all from here:

> **[Winter Vivern | Uncovering a Wave of Global Espionage](https://www.sentinelone.com/labs/winter-vivern-uncovering-a-wave-of-global-espionage/)**
>
> SentinelLabs uncover a previously unknown set of espionage campaigns conducted by Winter Vivern advanced persistent threat (APT) group.

Lastly, unfortunately as with any crisis threat actors seek to capitalize on misery for their own gain - we’ve released SIDs 2044674-2044676 to help protect against those that would phish targets based on the recent collapse of SVB.

That’s all for this week - enjoy the weekend and be careful out there!
