Threat Intelligence Brief
Curated summary with source attribution
Source: thehackernews.com
Threat Risk: High
Victim: Academic institutions and government agencies
Incident: Wide-scale data theft by the Mabna Institute and the discovery of a kernel-level EDR bypass via BTR.sys.
Impact: Theft of 31TB of intellectual property and the ability to bypass security software during system startup.
Attacker: Mabna Institute (IRGC)
Analysis: Threat actors are increasingly leveraging trusted, signed drivers to bypass endpoint security, specifically targeting the boot-time window. Simultaneously, long-term state-sponsored campaigns like the Mabna Institute demonstrate the scale of academic and intellectual property theft. These trends highlight a shift toward exploiting ‘trusted’ components to avoid signature-based detection.
Recommendations: Implement strict boot-level security and integrity checks to mitigate driver abuse.; Audit account permissions and monitor for unauthorized large-scale data exfiltration.; Ensure self-hosted tools like Gogs and n8n are patched against recent RCE vulnerabilities.
Source: The Hacker News
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source