SELECTED BY THE TALOS SECURITY INTELLIGENCE AND RESEARCH GROUP
Title: Snake/Ekans malware adds new functionality to go after ICS
Description: The Snake ransomware (otherwise known as "Ekans") has added new capabilities aimed at going after industrial industries. Ekans first emerged in December, but now has a relationship with the MEGACORTEX ransomware that could allow it to spread quickly on ICS systems and even force some services to revert to manual operations. The malware's code now includes direct references to HMI processes and historian clients that are commonly linked to ICS.
Reference: https://dragos.com/blog/industry-news/ekans-ransomware-and-ics-operations/
Snort SIDs: 53106, 53107
Title: Carrotbat malware, Syscon backdoor team up to target federal government
Description: An American federal agency was targeted in late January with a series of phishing emails utilizing a variant of the Carrotbat malware and the Syscon backdoor. Attackers used six unique email attachments in the campaign, all relating to the ongoing strained relationship between the U.S. and North Korea. Security researchers say these attackers are still active, despite the majority of their activity taking places over the summer.
Snort SIDs: 53129 - 53145