Tag: malware operations
619 articles

Phishing Attacks Propel Cyber Incidents to New Highs
Phishing attacks are now the top threat, making up over half of all cyber incidents - a significant jump from the previous quarter when they accounted for just one-third of cases. This resurgence in phishing has propelled cyber incidents to new highs, putting organizations on high alert.

Dysphoria Botnet Spreads to 200k Devices, Enables Global DDoS Attacks
A rapidly growing botnet called Dysphoria has infected over 200,000 devices worldwide, enabling massive global DDoS attacks. This sneaky threat uses blockchain technology to hide its tracks and evade detection.

SourTrade Malvertising Campaign Builds Malware in Browser
Meet SourTrade, a sneaky malvertising campaign that's assembling malware right in your browser - all while security tools and network logs show nothing out of the ordinary. Its operators impersonate popular trading and crypto platforms to trick victims into a stealthy malware delivery process.

TELESHIM Malware Exploits Telegram for C2 in Middle East Attacks
TELESHIM malware has launched a sophisticated attack in the Middle East, using a multi-stage chain to infect systems and cleverly leveraging Telegram's API to disguise its command-and-control communications as legitimate internet traffic. This sneaky tactic allows the malware to blend in seamlessly, making it a formidable threat.

Ransomware Groups Master EDR Kill Techniques
Ransomware groups have mastered the art of disabling endpoint detection and response (EDR) tools, making it standard practice to shut them down before encryption begins. This sinister tactic has significantly shortened defenders' response time, leaving them with limited opportunities to detect and contain attacks.

Steam Forum Abused in ClickFix Attacks Spreading XMRig Cryptominers
Cyber attackers are exploiting Steam's forum by creating fake accounts that offer 'helpful' fixes to users with game issues, tricking them into downloading and installing a notorious XMRig cryptominer. This sneaky tactic uses a PowerShell script to quietly install the malware as a persistent Windows service.

Malvertising Campaign SourTrade Exploits Browsers to Deliver Malware
Meet SourTrade, a sneaky malvertising campaign that's exploiting browsers to deliver malware - without leaving a single piece of malware on the network. This clever attack uses a complex web of code to assemble Windows executables right inside your browser.

Malvertising Campaign Exploits Browsers to Assemble Malware in Memory
Meet the sneaky malvertising campaign that's turning web browsers into malware factories, assembling attacks entirely in memory using fake pages for popular services like Solana, Luno, and TradingView. This stealthy operation has been active since late 2024, targeting users across 12 countries and 25 languages.

Botnets Persist Despite Takedowns, Fueled by Residential Proxy Networks
Botnets just won't quit, and it's no surprise why - there's a thriving market for access to millions of IPs, making it easy for them to keep growing and snaring more victims. Residential proxy networks are fueling this expansion, with nearly 60 million victim IP addresses globally and a significant chunk of them right here in the US.

BlueNoroff Phishing Kit Targets Crypto Wallets with Zoom Lures
BlueNoroff's phishing kit is a masterclass in deception, using Zoom lures and compromised industry contacts to trick victims into divulging their crypto wallet info. This sophisticated scam combines social engineering and malware to selectively target high-value victims.

Golden Chickens Malware Evolves With Modular Implants
The Golden Chickens malware has taken a significant leap forward with the emergence of four new, highly modular malware families, signaling a major evolution in the threat landscape. This development is a red flag, as it suggests a more sophisticated and adaptable attack strategy from the financially motivated malware-as-a-service developer behind it.

Dolphin X Malware Exploits AI to Prioritize High-Value Targets
Meet Dolphin X Malware, a sneaky threat that uses AI to help attackers zero in on their most prized targets - and it's equipped with an impressive 329 features to do so. Its AI Profiler tool can sort and rank infected computers, giving hackers a daily summary of the most valuable victims.

Bing Ads Deliver SectopRAT Malware via Fake Claude App
Malvertising on Bing Ads led to a massive attack, compromising at least 29 organizations in just two days with SectopRAT malware via a fake Claude app installer. A malicious artifact on Claude's own domain was downloaded over 7,100 times before being taken down.

Malware Exploits Trust In Ordinary Systems
This week's ThreatsDay bulletin revealed a disturbing trend: hackers are disguising malware as ordinary tools and features, using familiar names and routine functions to infiltrate code repositories, desktop systems, mobile apps, and more. Even trusted platforms like GitHub and PyPI are being exploited, with GitHub announcing a security update to block vulnerable support bundle uploads.

Hackers Exploit Notepad++ Plugins to Install Stealthy Malware
Beware of a sneaky malware attack that's using a harmless-looking PDF to trick victims into installing stealthy malware through a fake Notepad++ plugin. The malware is delivered through a cleverly disguised ZIP file that sets off a chain of events, ultimately leading to a malicious DLL being installed on your device.

Chaos Ransomware Exploits Headless Browsers for Covert C2 Traffic
Cisco Talos uncovered a sneaky tactic used by Chaos Ransomware, where a Rust implant called msaRAT hijacks a victim's browser to disguise its communications, making it look like they're coming from a legitimate browser process. This clever trick lets the malware fly under the radar by using the Chrome DevTools Protocol to control the browser.

GitHub Actions Abused to Target cPanel, WHM Servers
Malicious actors have cleverly exploited GitHub Actions to launch attacks on cPanel and WHM servers, using compromised source repositories to unleash a wave of automated exploits. By adding dozens of malicious workflows, attackers can scan and exploit vulnerable systems with alarming ease.

Dolphin X Stealer Uses AI to Target High-Value Victims
Meet Dolphin X Stealer, a sneaky new Windows malware that's packing some serious AI-powered punch, allowing cybercriminals to zero in on high-value targets with ease. Its operator panel boasts an impressive 329 features, giving attackers an unprecedented level of control and insight.

Chaos Ransomware Gang Exploits Browsers for Stealthy C2 Communications
Cisco Talos researchers have uncovered a sneaky new backdoor, msaRAT, that hijacks Chrome or Microsoft Edge to secretly communicate with its command center, avoiding direct network connections. This stealthy tactic uses the browser's remote debugging interface to inject JavaScript and stay under the radar.

Ransomware Attacks Intensify as AI Enhances Phishing Tactics
Ransomware attacks are getting smarter and more effective, with AI-powered phishing tactics leading to a significant increase in successful breaches. In fact, 65% of organizations hit by ransomware say AI tools made the attack more convincing and effective.

Malware Targets AI Tools in Software Development Environments
A new wave of malware is targeting the very tools developers rely on to build and deploy software, with a recently discovered worm, Sandworm_Mode, capable of stealing sensitive credentials and accessing critical systems. This emerging threat could compromise the entire AI development stack, from AI assistants to cloud providers and API keys.

Scammers Exploit 'Odyssey' Release with Rapid-Fire Pirated Movie Scams
Scammers wasted no time in exploiting the release of Christopher Nolan's highly anticipated film, The Odyssey, using rapid-fire pirated movie scams to target unsuspecting users just hours after its debut. These scams cleverily avoided software vulnerabilities, instead relying on fake browser warnings and malicious downloads to compromise victims' devices.

Ransomware Risk Amplified by Enterprise GenAI Deployments
With enterprise GenAI deployments on the rise, the ransomware risk is skyrocketing - after all, Microsoft alone detects over 38 million identity risk signals daily, a stark reminder that AI-enabled attacks can strike at any moment. As attackers supercharge their ops with AI, businesses are unwittingly increasing their vulnerability by deploying AI systems that can be exploited.

TrickBot Adopts DNS Tunneling in Latest Evolution
TrickBot's latest evolution uses DNS tunneling to evade detection, with FortiGuard Labs spotting the malware moving a 1.2 MB file in just 40 seconds. This sneaky new tactic lets TrickBot fly under the radar, routing encrypted data to a public resolver via DNS packets.