Skip to main content

Tag: malware operations

629 articles

Person sits in dimly lit room surrounded by broken tech, laptop displays fake error message.

macOS Users Targeted in ClickFix Malware Campaign

macOS users are being targeted in a sneaky new malware campaign called ClickFix, which tricks them into executing malicious commands by abusing the Script Editor and Terminal tools. This latest attack raises a pressing question: how can we trust our trusted tools when they're being exploited by hackers?

Analyst 207
Dimly lit server room with humming servers and tangled cables, a laptop screen in the foreground displays a distorted,…

Chaos Malware Expands to Target Misconfigured Cloud Deployments

Malware previously confined to home routers has now set its sights on cloud infrastructure, specifically targeting misconfigured cloud deployments and expanding its botnet territory. This alarming evolution in Chaos malware attacks demands attention from those responsible for securing cloud infrastructure.

Analyst 207
Shadowy figure looms over dimly lit cityscape, laptop screen displays Eastern Europe map, nearby smartphone lies broken.

APT28 Targets Ukraine, NATO Allies with PRISMEX Malware

Russian threat actor APT28 has launched a new campaign, deploying a previously unknown malware suite called PRISMEX to target Ukraine and its NATO allies, using clever concealment techniques to evade detection. This sophisticated attack combines steganography, COM hijacking, and legitimate cloud services to stay under the radar.

Analyst 207
Globe centered on Russia with shattered network, silhouettes of law enforcement disrupting tangled web.

FBI Disrupts Russian Hacker Network with DNS Hijacking Takedown

In a major cyber takedown, the FBI has successfully disrupted a Russian hacker network by pulling the plug on compromised US-based routers, effectively cutting off the threat actor's malicious infrastructure. This bold move allowed authorities to neutralize the threat without relying on individual device owners to take action.

Analyst 207
Shadowy figure in hoodie surrounded by screens and cables, coding on laptop with multiple terminals open.

North Korean Hackers Expand Malicious Package Reach Across Multiple Coding Ecosystems

Beware of the Trojan horse in your code: North Korean hackers have quietly infiltrated multiple package ecosystems, publishing around 1,700 malicious packages that masquerade as legitimate developer tools but act as malware loaders. This sneaky campaign, linked to the Contagious Interview group, puts developers and organizations relying on shared code on high alert.

Analyst 207