{"id":3785,"date":"2021-09-27T11:49:59","date_gmt":"2021-09-27T16:49:59","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=3785"},"modified":"2021-09-27T11:50:00","modified_gmt":"2021-09-27T16:50:00","slug":"darkoxide-group-targeting-confidential-information","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/","title":{"rendered":"DarkOxide group targeting confidential information"},"content":{"rendered":"\n<p>Threat actors are any malicious entity that initiates violations against an organization&#8217;s security measures. Let&#8217;s face it: Today, almost everyone depends on technology to send and receive information. Threat actors take advantage of our need for constant data transmission with malicious tactics like fake phishing emails posing as familiar people, such as coworkers or family members. Of course, this is just one example of nefarious activity that can jeopardize the sensitive data of a company or individual and today we will see a group called DarkOxide which was tracked by CrowdStrike Intelligence.<\/p>\n\n\n\n<p>The DarkOxide group exhibits a very specific set of TTPs that have changed very little in the last two years. Initially, the actor engages with a target through a business-oriented social media platform under the pretext of conducting a recruiting drive, after which the target is encouraged to download a decoy document allegedly related to a job vacancy which you should already know is suspicious. Actually, this file is a malicious executable with a double file extension. The executables in these decoys have used non-standard executable file extensions such as .PIF (program information file) and .SCR (screen saver). Since Windows by default hides the extension for known file types, these files initially appear to be legitimate document files when viewed in Windows File Explorer.<\/p>\n\n\n\n<p>To date, the targets of phishing attacks have included engineering personnel with access to confidential documents and source code, indicating that intellectual property theft is the likely motivation for these operations and therefore security measures must be taken To avoid these types of threats, train your staff and yourself, it is the best thing you can do since this is not the only threat on the Internet, there are many other cybercriminals in addition to the DarkOxide group.<\/p>\n\n\n\n<p>More reads:<br><a href=\"https:\/\/truxgoservers.com\/blog\/mustang-panda-group-that-attacks-goverment-entities\/\">Mustang Panda group that attacks goverment entities<\/a><br><a href=\"https:\/\/truxgoservers.com\/blog\/synack-group-has-released-keys-for-they-old-ransom\/\">SynAck group has released keys for they old ransom<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Threat actors are any malicious entity that initiates violations against an organization&#8217;s security measures. Let&#8217;s face it: Today, almost everyone depends on technology to send and receive information. Threat actors take advantage of our need for constant data transmission with malicious tactics like fake phishing emails posing as familiar people, such as coworkers or family [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":3794,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[36],"class_list":["post-3785","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-cybersecurity"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>DarkOxide group targeting confidential information - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"As we well know, cybercriminal groups are constantly active and today we will see a group called DarkOxide discovered by CrowdStrike.....\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DarkOxide group targeting confidential information - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"As we well know, cybercriminal groups are constantly active and today we will see a group called DarkOxide discovered by CrowdStrike.....\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-09-27T16:49:59+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-09-27T16:50:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/group.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"577\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"DarkOxide group targeting confidential information\",\"datePublished\":\"2021-09-27T16:49:59+00:00\",\"dateModified\":\"2021-09-27T16:50:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/\"},\"wordCount\":319,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/group.jpg\",\"keywords\":[\"Cybersecurity\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/\",\"name\":\"DarkOxide group targeting confidential information - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/group.jpg\",\"datePublished\":\"2021-09-27T16:49:59+00:00\",\"dateModified\":\"2021-09-27T16:50:00+00:00\",\"description\":\"As we well know, cybercriminal groups are constantly active and today we will see a group called DarkOxide discovered by CrowdStrike.....\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/group.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/09\\\/group.jpg\",\"width\":1000,\"height\":577},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/darkoxide-group-targeting-confidential-information\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"DarkOxide group targeting confidential information\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"DarkOxide group targeting confidential information - Truxgo Server Blog","description":"As we well know, cybercriminal groups are constantly active and today we will see a group called DarkOxide discovered by CrowdStrike.....","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/","og_locale":"es_MX","og_type":"article","og_title":"DarkOxide group targeting confidential information - Truxgo Server Blog","og_description":"As we well know, cybercriminal groups are constantly active and today we will see a group called DarkOxide discovered by CrowdStrike.....","og_url":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/","og_site_name":"Truxgo Server Blog","article_published_time":"2021-09-27T16:49:59+00:00","article_modified_time":"2021-09-27T16:50:00+00:00","og_image":[{"width":1000,"height":577,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/group.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"DarkOxide group targeting confidential information","datePublished":"2021-09-27T16:49:59+00:00","dateModified":"2021-09-27T16:50:00+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/"},"wordCount":319,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/group.jpg","keywords":["Cybersecurity"],"articleSection":["Cybersecurity"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/","url":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/","name":"DarkOxide group targeting confidential information - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/group.jpg","datePublished":"2021-09-27T16:49:59+00:00","dateModified":"2021-09-27T16:50:00+00:00","description":"As we well know, cybercriminal groups are constantly active and today we will see a group called DarkOxide discovered by CrowdStrike.....","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/group.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2021\/09\/group.jpg","width":1000,"height":577},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/darkoxide-group-targeting-confidential-information\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"DarkOxide group targeting confidential information"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3785","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=3785"}],"version-history":[{"count":2,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3785\/revisions"}],"predecessor-version":[{"id":3806,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/3785\/revisions\/3806"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/3794"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=3785"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=3785"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=3785"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}