Sept. 8, 2023, 10:20 a.m. | Guru Baran

GBHackers On Security gbhackers.com

A new sophisticated stealing campaign named  “Steal-It”  has been discovered that exfiltrates NTLMv2 hashes using customized versions of Nishang’s Start-CaptureServer PowerShell script. It is believed that the Steal-It campaign may be attributed to APT28 (aka Fancy Bear) based on its similarities with the APT28 cyber attack. Fancy Bear is a Russian cyber espionage group that […]


The post Hackers Steal NTLMv2 Hashes using Custom Powershell Scripts appeared first on GBHackers - Latest Cyber Security News | Hacker News.

apt28 attack bear campaign cyber fancy bear hackers hacks hashes may ntlmv2 powershell powershell script powershell scripts russian script scripts start steal stealing

Technical Senior Manager, SecOps | Remote US

@ Coalfire | United States

Global Cybersecurity Governance Analyst

@ UL Solutions | United States

Security Engineer II, AWS Offensive Security

@ Amazon.com | US, WA, Virtual Location - Washington

Senior Cyber Threat Intelligence Analyst

@ Sainsbury's | Coventry, West Midlands, United Kingdom

Embedded Global Intelligence and Threat Monitoring Analyst

@ Sibylline Ltd | Austin, Texas, United States

Senior Security Engineer

@ Curai Health | Remote