The newest SNORTⓇ rule update is out now. Cisco Talos released this ruleset providing additional protection against the CrimsonRAT malware.
The Transparent Tribe APT, as highlighted by Talos researchers, recently added CrimsonRAT to their arsenal as they began targeting more government contractors.
Here's a breakdown of Thursday's rule release:
Shared object rules | Modified shared object rules | New rules | Modified rules |
---|---|---|---|
0 | 0 | 19 | 12 |
snort.conf
in this release.Talos' rule release:
Talos has added and modified multiple rules in the file-pdf, malware-cnc, os-other, server-apache and server-webapp rule sets to provide coverage for emerging threats from these technologies.