logologodotlogologo
  • Home
  • Services
    • Security Operations
          • Automation Platform
          • Endpoint Security Protection
          • Log Management
          • OT Security
          • Patch Management
          • Security Management
          • Vulnerability Management
    • Service Enablement
          • Financial Management
          • IT Asset Management
          • Project Management
          • Risk Management
    • Service Design
          • Availability Management
          • Capacity Management
          • Information Security Management
          • Service Catalog Management
          • Service Level Management
    • Service Operations
          • Backup Management
          • Change Management
          • Engineering Support
          • Incident Management
          • Monitoring and Alerting
          • Problem Management
          • Release Management
          • Remote Management Solution
          • Service Desk 24×7
          • Service Request Fulfillment
    • Workplace Management Solution

          • Workplace Management

    • Hosting Platform
          • Hosting Solution
          • Networking
          • Storage and Backup Platform
          • Virtual Desktop Infrastructure
  • Company
    • About us
          • Our Story
          • Global Reach
          • Leadership Team
          • Vision
          • Mission
    • Resources
          • Brochures
    • Blog & Events
          • Blog
          • Events
    • Careers
  • Contact Us
✕
Two-Thirds of Financial Services Firms Suffered Cyber-Attack in the Past Year
November 9, 2020
TomCat Orange to Exhibit at Business Revival 2023
January 26, 2023
Published by Thomas at November 9, 2020
Categories
  • Cloud security
Tags
Firestarter Android Malware Abuses Google Firebase Cloud Messaging

The DoNot APT threat group is leveraging the legitimate Google Firebase Cloud Messaging server as a command-and-control (C2) communication mechanism.

An APT group is starting fires with a new Android malware loader, which uses a legitimate Google messaging service to bypass detection.

The malware, dubbed “Firestarter,” is used by an APT threat group called “DoNot.” DoNot uses Firebase Cloud Messaging (FCM), which is a cross-platform cloud solution for messages and notifications for Android, iOS and web applications. The service is provided by Firebase, a subsidiary of Google, and has been previously leveraged by cybercriminals.

In this case, the loader uses it as a communication mechanism to connect with DoNot’s command-and-control (C2) servers, helping the group’s activities avoid detection.

“Our research revealed that DoNot has been experimenting with new techniques to keep a foothold on their victim machines,” according to researchers with Cisco Talos in a Thursday analysis. “These experiments, substantiated in the Firestarter loader, are a sign of how determined they are to keep their operations despite being exposed, which makes them a particularly dangerous actor operating in the espionage area.”

The DoNot team continues to focus on India and Pakistan, and is known for targeting Pakistani government officials and Kashmiri non-profit organizations (Kashmiris are a Dardic ethnic group native to the disputed Kashmir Valley).Article’s intro is courtesy of Threatpost

Continue reading…

Share
0
Thomas
Thomas

Related posts

October 20, 2019

Wormable Apple iCloud Bug Allows Automatic Photo Theft


Read more

Comments are closed.


Contact us

UK – EU +44 1279 927082

USA +1 813-422-5109

Global Reach

Learn more about our Globl Reach

© 2023 Tomcat Orange