The Deep Purple Sec – April 2025
A monthly round-up of interesting articles, reports and tools for tech experts, covering both offensive and defensive topics.
🔴 Red Team
📝 Goodbye HTA, Hello MSI: New TTPs and Clusters of an APT driven by multi-platform attacks
Seqrite Labs details the evolving tactics of the Pakistan-linked SideCopy APT group, which has expanded its targets to include the ministries of railways, oil and gas, and foreign affairs. The group has moved from HTML Application (HTA) files to Microsoft Installer (MSI) packages to evade detection, using advanced techniques such as DLL side-loading and AES decryption via PowerShell.
SideCopy APT has introduced new payloads, including a custom version of Xeno RAT and CurlBack, which registers victims with the C2 server. The campaigns employ sophisticated phishing tactics, including compromised domains and fake government personas, targeting both Windows and Linux environments with customised tools such as Spark RAT.
The investigation reveals credential phishing and open directories used to host payloads, targeting critical sectors in India. The APT’s infrastructure includes compromised domains and fake e-governance websites, which enhance persistence and evasion. The article provides insights into the TTPs employed by SideCopy, including reflective loading and custom RATs, along with IOCs and MITRE ATT&CK techniques associated with these campaigns.
📝 Blacklock Ransomware: A belated festive gift, with an intrusion into the threat actor’s infrastructure
Resecurity’s article details an operation targeting the BlackLock ransomware group, which has been active since March 2024. They exploited a vulnerability in BlackLock’s Data Leak Site (DLS) on the TOR network, gathering intelligence on the group’s activities and planned attacks.
The DLS breach revealed critical information about the group’s operations, enabling Resecurity to predict and prevent future attacks and disrupt their activities, highlighting a proactive approach to combating ransomware.
Resecurity identified 46 victims from various sectors, noting BlackLock’s aggressive recruitment and a 1,425% increase in data leak posts in Q4 2024, highlighting the effectiveness of proactive cybersecurity measures.
📝 TROX Stealer: An in-depth look at a new Malware-as-a-Service (MaaS) attack campaign
The article from Sublime Security discusses TROX Stealer, a data-stealing malware offered as Malware-as-a-Service (MaaS). First observed in December 2024, it may have been released as early as April 2024. It is marketed for the rapid deployment of large-scale attack campaigns and is typically licensed on a weekly basis.
TROX Stealer targets consumers, stealing credit card details and sensitive data from browsers and chat clients such as Discord and Telegram. It uses urgent-sounding lures to trick victims into opening malicious emails that execute the payload.
The TROX Stealer’s infrastructure comprises various domains and IP addresses, with certificate management to ensure persistence. It uses WebAssembly (Wasm) code encoded in Base64 and junk code to obscure its functions. Sublime Security’s AI detection engine has been instrumental in preventing these attacks at the email delivery stage, highlighting the need for advanced threat detection.
🔵 Blue Team
📝 ATT&CK v17: New Platform (ESXi), Collection Optimisation, & Further Countermeasures
The ATT&CK v17 update introduces new features to help defenders keep pace with adversary trends. The update includes the ESXi platform, reflecting the rise in attacks on virtualisation infrastructure, and renames the ‘Network’ platform to ‘Network Devices’. Data components have been enhanced to provide platform-specific guidance on data collection. The update also includes new techniques and tools for mobile environments, as well as updates on groups, campaigns and software used by adversaries.
In addition, the mitreattack-python library has been updated to work with ATT&CK v17 STIX content, and Workbench has adopted semantic versioning to provide a preview of upcoming changes.
Note: These changes have already been incorporated into the BlackNoise application.
📌 Source: https://medium.com/mitre-attack/attack-v17-dfb59eae2204
📝 CISA extends Mitre’s CVE contract at the last minute
The US Cybersecurity and Infrastructure Security Agency (CISA) has extended its contract with MITRE for the Common Vulnerabilities and Exposures (CVE) Programme at the last minute. The agreement was reached late on Tuesday, 15 April 2025, ensuring the continuity of the vital CVE Programme, which is crucial for the global cybersecurity community.
The 11-month extension was implemented to prevent any interruption to the service, underscoring CISA’s commitment to maintaining this essential resource for vulnerability management. The decision was taken against a backdrop of concerns within the cybersecurity community about the potential consequences of any disruption to the CVE Programme, which is widely relied upon for tracking and managing security vulnerabilities.
📌 Source: https://www.computerweekly.com/news/366622896/CISA-extends-MITRE-CVE-contract-at-last-moment
🛠️ Cloud Incident Readiness: Key logs for cloud incidents
The Invictus article highlights the importance of logging in cloud incident preparedness, discussing key logs for major providers such as Microsoft, AWS and Google Workspace. It categorises logs into «Must-Have» for critical response and «Nice-to-Have» for deeper analysis, emphasising their role in addressing investigative questions during incidents. It also offers advice on prioritising logs in light of potential budget constraints.
📌 Source: https://www.invictus-ir.com/news/cloud-incident-readiness-key-logs-for-cloud-incidents