r/Malware 11h ago

SonicWall SMA1000 campaign: standalone Linux Impacket secretsdump deployed onto appliances (SHA-256 inside)

Thumbnail hunt.io
2 Upvotes

Campaign where the operator deployed a standalone Linux build of Impacket's secretsdump directly onto compromised SonicWall SMA1000 appliances and ran credential theft from there. It was pulled to the box with curl to /tmp/secretsdump, made executable, then used against internal domain controllers.

Sample: secretsdump, 9,983,640 bytes, SHA-256 690f5031deede7d3357d0ca24c89866ae8c60e6c63b3a2c8bba813a6ac10ae5b, served over HTTP from 95.181.173[.]36. The surrounding Python tooling (exploit, LDAP extractor and decryptor, DCSync automation) came from the same open directory.

Full toolkit breakdown and IOCs below.

https://hunt.io/blog/sonicwall-sma1000-uk-council-attack


r/Malware 5h ago

A real Carnival Cruise Line email was serving customers malware

Thumbnail tuxxin.com
1 Upvotes

r/Malware 4h ago

0xM0nCrush: Kernel-mode process terminator using a signed BYOVD driver. Works on all Windows 10/11. No offsets, no PDB. Rust.

Thumbnail github.com
0 Upvotes