malware Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/malware/ Breaking news about the market for products, systems and services for the U.S. intelligence community Sun, 22 Mar 2026 23:34:54 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg malware Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/malware/ 32 32 59882712 CISA issues cyberattack alert, recommendations https://intelligencecommunitynews.com/cisa-issues-cyberattack-alert-recommendations/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-issues-cyberattack-alert-recommendations Sun, 22 Mar 2026 23:34:54 +0000 https://intelligencecommunitynews.com/?p=44133 On March 18, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it is aware of malicious cyber activity targeting...

The post CISA issues cyberattack alert, recommendations appeared first on Intelligence Community News.

]]>
On March 18, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it is aware of malicious cyber activity targeting endpoint management systems of U.S. organizations based on the March 11, 2026 cyberattack against U.S.-based medical technology firm Stryker Corporation, which affected their Microsoft environment.

To defend against similar malicious cyber activity, CISA urges organizations to harden endpoint management system configurations using the recommendations and resources provided in this alert. CISA is conducting enhanced coordination with federal partners, including the Federal Bureau of Investigation (FBI), to identify additional threats and determine mitigation actions.

To defend against similar malicious activity that misuses legitimate endpoint management software, CISA urges organizations to implement Microsoft’s newly released best practices for securing Microsoft Intune; the principles of these recommendations can be applied to Intune and more broadly to other endpoint management software:

  • Use principles of least privilege when designing administrative roles.
  • Enforce phishing-resistant multi-factor authentication (MFA) and privileged access hygiene.
  • Configure access policies to require Multi Admin Approval in Microsoft Intune.

 

Source: CISA

If you enjoyed this article, please consider becoming a paid subscriber. Your support helps keep our site ad-free.

The post CISA issues cyberattack alert, recommendations appeared first on Intelligence Community News.

]]>
44133
Booz Allen unveils Vellox Reverser https://intelligencecommunitynews.com/booz-allen-unveils-vellox-reverser/?utm_source=rss&utm_medium=rss&utm_campaign=booz-allen-unveils-vellox-reverser Wed, 28 Jan 2026 14:55:09 +0000 https://intelligencecommunitynews.com/?p=43711 On January 26, Booz Allen Hamilton announced the general availability of Vellox Reverser, a malware reverse engineering and threat intelligence product designed...

The post Booz Allen unveils Vellox Reverser appeared first on Intelligence Community News.

]]>
On January 26, Booz Allen Hamilton announced the general availability of Vellox Reverser, a malware reverse engineering and threat intelligence product designed to radically accelerate cyber defense. Built with a resilient agentic AI architecture, Vellox Reverser rapidly automates time-intensive in-depth malware analysis of the most complex and evasive threats. The product delivers actionable intelligence and comprehensive countermeasures at machine speed that integrate seamlessly into existing security workflows, according to the company.

The product is now widely available to help both federal and commercial customers accelerate wide-scale deployment, increase resiliency, speed and confidence, and immediately strengthen their cyber defenses.

“As AI-driven cyberattacks become one of the primary security concerns in 2026, we’re proud to deliver a mission-grade malware analysis product that helps our customers address the most complex threats at speed,” said Mujtaba Hamid, executive vice president of product at Booz Allen. “Vellox Reverser will serve as a force multiplier for security teams, embedding decades of Booz Allen cyber defense tradecraft into AI agents designed to replicate world-class malware analysts so our customers can analyze threats at a depth unmatched by other tools and solutions.”

A limited preview of Vellox Reverser, introduced in 2025, drove product refinements and new features including Binary and Function Similarity Matching. By comparing new analyzed samples against a database of previously analyzed sets of malware, this upgrade dramatically reduces investigation time and reveals links to broader adversarial cyber campaigns. These added features enable teams to build stronger, more scalable detection and threat hunting strategies by revealing how attack behaviors evolve over time, turning historical insights into proactive defense.

In a recent evaluation of a single, sophisticated malware sample, Vellox Reverser completed analysis in minutes, evaluating more than 120 functions and flagging 39 as malicious. It then generated a comprehensive report with indicators of compromise mapped to the MITRE ATT&CK framework, along with deployable defensive measures for rapid response.

Source: Booz Allen

Start 2026 ahead of the competition with a paid subscription to IC News. You’ll get full access to our searchable archive of 15,000+ articles, plus new articles each weekday.

The post Booz Allen unveils Vellox Reverser appeared first on Intelligence Community News.

]]>
43711
NSA advises how to detect BRICKSTORM backdoor activity https://intelligencecommunitynews.com/nsa-advises-how-to-detect-brickstorm-backdoor-activity/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-advises-how-to-detect-brickstorm-backdoor-activity Fri, 05 Dec 2025 14:30:03 +0000 https://intelligencecommunitynews.com/?p=43328 On December 4, the National Security Agency (NSA) joined the Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre...

The post NSA advises how to detect BRICKSTORM backdoor activity appeared first on Intelligence Community News.

]]>
On December 4, the National Security Agency (NSA) joined the Cybersecurity and Infrastructure Security Agency (CISA) and the Canadian Centre for Cyber Security to detail the broad campaign of China state-sponsored cyber actors using the BRICKSTORM malware for long-term persistence on victim systems.

BRICKSTORM malware is a sophisticated backdoor that provides capabilities for secure command and control, remote system control, and long-term persistence.

Organizations—especially those within critical infrastructure, government services and facilities, and the Information Technology sector—are encouraged to use the indicators of compromise (IOCs) and detection signatures outlined in the report to detect BRICKSTORM backdoor activity. If BRICKSTORM, similar malware, or potentially related activity is detected, promptly report the compromise.

Read the full report here.

Source: NSA

Time is running out — become a paid subscriber to IC News today, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post NSA advises how to detect BRICKSTORM backdoor activity appeared first on Intelligence Community News.

]]>
43328
Russian malware targeting Ukrainian military, US says https://intelligencecommunitynews.com/russian-malware-targeting-ukrainian-military-us-says/?utm_source=rss&utm_medium=rss&utm_campaign=russian-malware-targeting-ukrainian-military-us-says Tue, 05 Sep 2023 13:01:51 +0000 https://intelligencecommunitynews.com/?p=36512 U.S. federal agencies and international partners published a report warning of a new malware campaign from Russian military cyber actors known publicly...

The post Russian malware targeting Ukrainian military, US says appeared first on Intelligence Community News.

]]>
U.S. federal agencies and international partners published a report warning of a new malware campaign from Russian military cyber actors known publicly as Sandworm.

The joint guidance is intended to promote discovery and mitigation of this new malware from an actor known to target U.S. government and Defense Industrial Base (DIB) networks.

“Russia continues to leverage the cyber domain to advance its war against Ukraine,” said Rob Joyce, NSA’s Cybersecurity Director. “Our analysis offers guidance to help find and eradicate this threat, and raises awareness of this threat targeted by Sandworm malicious cyber activity. We will continue to collaborate across the U.S. government and with our international allies to eradicate cyber threats.”

The report is being released now because of the targeting involved, the fact this is new malware, and the actor group having targeted U.S. government and Defense Industrial Base in the past. The information in the publication will help National Security System, Department of Defense, and Defense Industrial Base network defenders defend against malicious cyber actors.

The malware analysis report was jointly issued by the United Kingdom’s National Cyber Security Centre (NCSC-UK), the U.S. National Security Agency (NSA), the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the U.S. Federal Bureau of Investigation (FBI), New Zealand’s National Cyber Security Centre (NCSC-NZ), Canada’s Communications Security Establishment (CSE) and Australian Signals Directorate (ASD).

The Security Service of Ukraine (SBU) publicly uncovered the Infamous Chisel malware campaign in early August 2023 and associated it with the Sandworm threat actor. NSA, CISA, FBI, and NCSC-UK previously attributed the Sandworm actor to the Russian GRU Main Centre for Special Technologies (GTsST).

Read the full report here.

Source: NSA

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post Russian malware targeting Ukrainian military, US says appeared first on Intelligence Community News.

]]>
36512
NSA releases BlackLotus Guide https://intelligencecommunitynews.com/nsa-releases-blacklotus-guide/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-releases-blacklotus-guide Fri, 23 Jun 2023 14:01:41 +0000 https://intelligencecommunitynews.com/?p=35906 Malicious cyber actors could take advantage of a known vulnerability in the Microsoft Windows secure startup process to bypass Secure...

The post NSA releases BlackLotus Guide appeared first on Intelligence Community News.

]]>
Malicious cyber actors could take advantage of a known vulnerability in the Microsoft Windows secure startup process to bypass Secure Boot protection and execute BlackLotus malware.

To guide system administrators and network defenders on how to mitigate this threat, the National Security Agency (NSA) is publicly releasing the “BlackLotus Mitigation Guide” Cybersecurity Information Sheet (CSI). The guide provides an overview of recommended actions to detect and prevent malicious activities associated with BlackLotus, NSA announced June 22.

“Protecting systems against BlackLotus is not a simple fix, “said Zachary Blum, NSA’s Platform Security Analyst. “Patching is a good first step, but we also recommend hardening actions, dependent on your system’s configurations and security software used.”

BlackLotus exploits a known vulnerability called “Baton Drop,” CVE-2022-21894, which bypasses security features during the device’s startup process, also known as Secure Boot. The malware targets Secure Boot by exploiting vulnerable boot loaders not added into the Secure Boot Deny List Database (DBX).

The Secure Boot DBX prevents execution of unauthorized boot loaders. According to the CSI, boot loaders vulnerable to Baton Drop have not been added into the Secure Boot DBX revocation list and are still trusted during Secure Boot process. A malicious cyber actor, therefore, could successfully exploit the Baton Drop vulnerability, bypass Secure Boot, and compromise the device.

NSA recommends system administrators and network defenders take action by implementing the mitigations listed in this report.

Read the full report here.

Source: NSA

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post NSA releases BlackLotus Guide appeared first on Intelligence Community News.

]]>
35906
NSA, partners identify Russian Snake malware infrastructure https://intelligencecommunitynews.com/nsa-partners-identify-russian-snake-malware-infrastructure/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-partners-identify-russian-snake-malware-infrastructure Wed, 10 May 2023 12:12:32 +0000 https://intelligencecommunitynews.com/?p=35515 The National Security Agency (NSA) and several partner agencies have identified infrastructure for Snake malware—a sophisticated Russian cyberespionage tool—in over...

The post NSA, partners identify Russian Snake malware infrastructure appeared first on Intelligence Community News.

]]>
The National Security Agency (NSA) and several partner agencies have identified infrastructure for Snake malware—a sophisticated Russian cyberespionage tool—in over 50 countries worldwide, the NSA announced May 9.

To assist network defenders in detecting Snake and any associated activity, the agencies are publicly releasing the joint Cybersecurity Advisory (CSA), “Hunting Russian Intelligence “Snake” Malware” today.

The agencies, which include the NSA, Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Cyber National Mission Force (CNMF), Canadian Cyber Security Centre (CCCS), United Kingdom National Cyber Security Centre (NCSC-UK), Australian Cyber Security Centre (ACSC), and New Zealand National Cyber Security Centre (NCSC-NZ) attribute Snake operations to a known unit within Center 16 of Russia’s Federal Security Service (FSB). The international coalition has identified Snake malware infrastructure across North America, South America, Europe, Africa, Asia, and Australia, including the United States and Russia.

“Russian government actors have used this tool for years for intelligence collection,” said Rob Joyce, NSA Director of Cybersecurity. “Snake infrastructure has spread around the world. The technical details will help many organizations find and shut down the malware globally.”

Malicious cyber actors used Snake to access and exfiltrate sensitive international relations documents, as well as other diplomatic communications, through a victim in a North Atlantic Treaty Organization (NATO) country.

In the U.S., the FSB has victimized industries including education institutions, small businesses, and media organizations. Critical infrastructure sectors, such as local government, finance, manufacturing, and telecommunications, have also been impacted.

Typically, Snake malware is deployed to external-facing infrastructure nodes on a network. From there, it uses other tools, and techniques, tactics, and procedures (TTPs) on the internal network to conduct additional exploitation operations.

This CSA focuses on one of the more recent variants of Snake. It provides background on Snake’s attribution to the FSB and detailed technical information and mitigation recommendations to assist network defenders in protecting against Snake-associated malicious activity.

Read the full report here.

Source: NSA

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

 

The post NSA, partners identify Russian Snake malware infrastructure appeared first on Intelligence Community News.

]]>
35515
Conceal partners with Carahsoft https://intelligencecommunitynews.com/conceal-partners-with-carahsoft/?utm_source=rss&utm_medium=rss&utm_campaign=conceal-partners-with-carahsoft Thu, 21 Jul 2022 12:44:49 +0000 https://intelligencecommunitynews.com/?p=32946 On July 19, Augusta, GA-based Conceal announced a partnership with Carahsoft Technology Corp. to protect government agencies from ransomware using the...

The post Conceal partners with Carahsoft appeared first on Intelligence Community News.

]]>
On July 19, Augusta, GA-based Conceal announced a partnership with Carahsoft Technology Corp. to protect government agencies from ransomware using the Conceal Platform which incorporates intelligence-grade, Zero Trust technology.

“Conceal has developed a powerful new approach to ransomware protection that uses isolation to prevent malware from targeting an organization’s users and infrastructure, and executing on endpoints,” said Craig Abod, Carahsoft president. “This partnership allows Carahsoft and our reseller partners to provide our government customers with unprecedented security for their end users, network and data.”

“Government agencies rely on Carahsoft to recommend and provide the most advanced security technology available to protect their infrastructure and assets from ransomware and other threats,” said Gordon Lawson, CEO of Conceal. “This partnership enables government customers to access the Conceal Platform to detect, defend and isolate their networks, users and data from today’s most insidious threats using intelligence-grade technology.”

The Conceal Platform provides detection of cyber threats before they can infiltrate the network by processing all code to determine whether or not it is malicious and placing suspicious content in isolation so malware cannot execute. It is comprised of three integrated products:

  • ConcealBrowse which secures users by protecting every endpoint from malicious threats
  • ConcealSearch which shields the network from reconnaissance and attacks by fortifying online activity without attribution to your enterprise
  • ConcealCloud which safeguards cloud resources through isolation by regularly churning the underlying network infrastructure

Source: Conceal

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post Conceal partners with Carahsoft appeared first on Intelligence Community News.

]]>
32946
CISA identifies SUPERNOVA malware https://intelligencecommunitynews.com/cisa-identifies-supernova-malware/?utm_source=rss&utm_medium=rss&utm_campaign=cisa-identifies-supernova-malware Sun, 25 Apr 2021 16:04:00 +0000 https://intelligencecommunitynews.com/?p=29236 On April 22, the Cybersecurity and Infrastructure Security Agency (CISA) released information about a newly discovered malware. CISA recently responded...

The post CISA identifies SUPERNOVA malware appeared first on Intelligence Community News.

]]>
On April 22, the Cybersecurity and Infrastructure Security Agency (CISA) released information about a newly discovered malware. CISA recently responded to an advanced persistent threat (APT) actor’s long-term compromise of an entity’s enterprise network, which began in at least March 2020. The threat actor connected to the entity’s network via a Pulse Secure virtual private network (VPN) appliance, moved laterally to its SolarWinds Orion server, installed malware referred to by security researchers as SUPERNOVA (a .NET webshell), and collected credentials.

SUPERNOVA is a malicious webshell backdoor that allows a remote operator to dynamically inject C# source code into a web portal to subsequently inject code. APT actors use SUPERNOVA to perform reconnaissance, conduct domain mapping, and steal sensitive information and credentials. (Note: for more information on SUPERNOVA, refer to Malware Analysis Report MAR-10319053-1.v1 – SUPERNOVA.) According to a SolarWinds advisory, SUPERNOVA is not embedded within the Orion platform as a supply chain attack; rather, an attacker places it directly on a system that hosts SolarWinds Orion, and it is designed to appear as part of the SolarWinds product.[1] CISA assesses this is a separate actor than the APT actor responsible for the SolarWinds supply chain compromise described in Alert AA20-352A: Advanced Persistent Threat Compromise of Government Agencies, Critical Infrastructure, and Private Sector Organizations. Organizations that find SUPERNOVA on their SolarWinds installations should treat this incident as a separate attack.

This report provides tactics, techniques, and procedures (TTPs) CISA observed during an incident response engagement. (Note: this threat actor targeted multiple entities in the same period; some information in this Analysis Report is informed by other related incident response engagements and CISA’s public and private sector partners.) This APT actor has used opportunistic tradecraft, and much is still unknown about its TTPs.

For a downloadable copy of indicators of compromise (IOCs) associated with this malware, see AR21-112A.stix and Malware Analysis Report MAR-10319053-1.v1.stix.

Source: CISA

 

The post CISA identifies SUPERNOVA malware appeared first on Intelligence Community News.

]]>
29236
NSA, FBI warn of previously undisclosed Russian malware https://intelligencecommunitynews.com/nsa-fbi-warn-of-previously-undisclosed-russian-malware/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-fbi-warn-of-previously-undisclosed-russian-malware Mon, 17 Aug 2020 13:13:54 +0000 https://intelligencecommunitynews.com/?p=27267 On August 13, the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI) released a new Cybersecurity Advisory about previously...

The post NSA, FBI warn of previously undisclosed Russian malware appeared first on Intelligence Community News.

]]>
On August 13, the National Security Agency (NSA) and the Federal Bureau of Investigation (FBI) released a new Cybersecurity Advisory about previously undisclosed Russian malware.

The Russian General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165, whose activity is sometimes identified by the private sector as Fancy Bear, Strontium, or APT 28, is deploying malware called Drovorub, designed for Linux systems as part of its cyber espionage operations. Further details on Drovorub, to include detection techniques and mitigations, can be found in the joint NSA and FBI Cybersecurity Advisory.

“This Cybersecurity Advisory represents an important dimension of our cybersecurity mission, the release of extensive, technical analysis on specific threats,” NSA Cybersecurity Director Anne Neuberger said. “By deconstructing this capability and providing attribution, analysis, and mitigations, we hope to empower our customers, partners, and allies to take action. Our deep partnership with FBI is reflected in our releasing this comprehensive guidance together.”

“For the FBI, one of our priorities in cyberspace is not only to impose risk and consequences on cyber adversaries but also to empower our private sector, governmental, and international partners through the timely, proactive sharing of information,” said FBI Assistant Director Matt Gorham. “This joint advisory with our partners at NSA is an outstanding example of just that type of sharing. We remain committed to sharing information that helps businesses and the public protect themselves from malicious cyber actors.”

Drovorub is a Linux malware toolset consisting of an implant coupled with a kernel module rootkit, a file transfer and port forwarding tool, and a command and control (C2) server. When deployed on a victim machine, Drovorub provides the capability for direct communications with actor-controlled C2 infrastructure; file download and upload capabilities; execution of arbitrary commands; port forwarding of network traffic to other hosts on the network; and implements hiding techniques to evade detection.

Drovorub represents a threat to National Security Systems, Department of Defense, and Defense Industrial Base customers that use Linux systems. Network defenders and system administrators can find detection strategies, mitigation techniques, and configuration recommendations in the advisory to reduce the risk of compromise.

Read the Fact Sheet and FAQ here.

Source: NSA

The post NSA, FBI warn of previously undisclosed Russian malware appeared first on Intelligence Community News.

]]>
27267
NSA warns of attacks through web shell malware https://intelligencecommunitynews.com/nsa-warns-of-attacks-through-web-shell-malware/?utm_source=rss&utm_medium=rss&utm_campaign=nsa-warns-of-attacks-through-web-shell-malware Fri, 24 Apr 2020 13:09:57 +0000 https://intelligencecommunitynews.com/?p=26328 Malicious cyber actors have increasingly leveraged web shells to gain or maintain access on victim networks. Web shell malware is...

The post NSA warns of attacks through web shell malware appeared first on Intelligence Community News.

]]>
Malicious cyber actors have increasingly leveraged web shells to gain or maintain access on victim networks. Web shell malware is software deployed by a hacker, usually on a victim’s web server, that can execute arbitrary system commands, commonly sent over HTTPS. To harden and defend web servers against this threat, NSA and the Australian Signals Directorate have issued a dual-seal Cybersecurity Information Sheet (CSI), NSA announced April 22.

This product contains valuable information on how to detect and prevent web shell malware from affecting Department of Defense and other government web servers, though the guidance would likely also be useful for any network defenders responsible for maintaining web servers.

Web shell malware has been a threat for years and continues to evade detection from most security tools. Malicious cyber actors are increasingly leveraging this type of malware to get consistent access to compromised networks while using communications that blend in well with legitimate traffic. This means attackers might send system commands over HTTPS or route commands to other systems, including to your internal networks, which may appear as normal network traffic.

This CSI contains detection techniques, along with links to signatures and lists maintained on GitHub. This report also highlights prevention techniques and recovery guidance. NSA encourages network defenders who maintain web servers to review this technical guidance and apply the mitigations as appropriate.

NSA’s Cybersecurity Advisories and Technical Guidance are available here.

 

The post NSA warns of attacks through web shell malware appeared first on Intelligence Community News.

]]>
26328