Skip to main content

Tag: malware

703 articles

GhostRedirector: Exclusive Dangerous China-Aligned Threat

GhostRedirector: Exclusive Dangerous China-Aligned Threat

A newly discovered group called GhostRedirector quietly breached 65 Windows servers using custom tools and stealthy redirection techniques, and its infrastructure and tradecraft point to China-aligned objectives. Treat this as a wake-up call to move beyond signature-based detection, hunt for anomalous behavior, and harden your systems now.

Analyst 207
threat-intel sharing: Must-Have Critical Lifeline

threat-intel sharing: Must-Have Critical Lifeline

As the reauthorization deadline nears, Congress must decide whether to renew cyber‑intel sharing authorities and funding that let companies and federal defenders act fast — a lapse could hamstring responses, while sensible reforms could bolster privacy at the cost of speed.

Analyst 207
VBA-based backdoor: Stunning Risky Outlook Threat

VBA-based backdoor: Stunning Risky Outlook Threat

Think your inbox is safe? Researchers warn APT28 has deployed a VBA-based Outlook backdoor called NotDoor that hides in macros to harvest emails and stay persistent, so it’s time to tighten macro policies, add telemetry, and treat your mail client as part of the attack surface.

Analyst 207
IPTV piracy: Stunning 1,100-Domain Risk Exposed

IPTV piracy: Stunning 1,100-Domain Risk Exposed

A massive IPTV piracy ring spanning about 1,100 domains was exposed — offering dirt‑cheap access to Apple TV, Disney+, HBO and Netflix while often exposing viewers to malware, fraud and billions in lost revenue. The takedown shows how convenience and low cost fuel organized piracy that threatens creators, consumers and the whole streaming ecosystem.

Analyst 207
Lazarus Group Exclusive: Dangerous DeFi RATs Revealed

Lazarus Group Exclusive: Dangerous DeFi RATs Revealed

A North Korea-linked Lazarus campaign used a crafty phishing lure to deploy three cross-platform RATs—PondRAT, ThemeForestRAT and RemotePE—breaching a DeFi organization and highlighting how attackers now tailor stealthy, multi‑OS toolsets to target decentralized finance. It’s a wake-up call: assume breach, tighten access and key protections, and shift to behavior-based detection across heterogeneous environments.

Analyst 207
signed Windows kernel driver: Stunning Risky Backdoor

signed Windows kernel driver: Stunning Risky Backdoor

When a Microsoft‑signed WatchDog driver (amsdk.sys) was abused to neuter endpoint defenses and plant ValleyRAT, it proved that a valid signature isn’t a guarantee of safety. This Silver Fox campaign underscores why organizations must stop trusting signatures alone and add behavior‑based controls and tighter vetting for privileged drivers.

Analyst 207
watering-hole technique: Exclusive Risky Exposed

watering-hole technique: Exclusive Risky Exposed

When nation‑state actors like APT29 weaponize familiar conveniences — such as “Sign in with Microsoft” flows and popular websites — a routine visit can hand over credentials and session tokens at scale. Amazon’s disclosure shows watering‑hole attacks have evolved, so teams and users should treat federated logins and consent prompts with fresh skepticism and stronger protections.

Analyst 207
Operation HanKook Phantom: Exclusive Dangerous Threat

Operation HanKook Phantom: Exclusive Dangerous Threat

When colleagues become targets, South Korea’s academic community is facing a stealthy campaign — Operation HanKook Phantom — where ScarCruft (APT37) uses tailored phishing and the RokRAT trojan to siphon research and influence policy debates. Universities must boost basics like MFA, endpoint protection and phishing training to protect open inquiry without closing it off.

Analyst 207
Cozy Bear Exposed: Risky OAuth Attack — Must-Have Alert

Cozy Bear Exposed: Risky OAuth Attack — Must-Have Alert

AWS says it disrupted a Cozy Bear (APT29) campaign that used fake websites and OAuth consent tricks to coax Microsoft users into granting access to mail, calendars and other data. The episode is a reminder that convenient features like single sign‑on can be repurposed for stealthy espionage — and why cloud providers are increasingly acting as front‑line defenders.

Analyst 207
spear-phishing campaign: Risky North Korean Tactic Exposed

spear-phishing campaign: Risky North Korean Tactic Exposed

North Korea’s APT37 is luring South Koreans with real-looking internal briefings, turning trusted emails into powerful espionage tools — a wake-up call to strengthen MFA, behavior-based detection, and cross‑agency info sharing.

Analyst 207
fake IT support Risky Alert: Must-Have Teams Defenses

fake IT support Risky Alert: Must-Have Teams Defenses

Attackers are impersonating IT in Microsoft Teams to trick employees into installing remote‑access tools and gain a foothold in corporate networks. Verify any unsolicited support request via known channels and tighten guest, app‑install, and remote‑access controls to stay safe.

Analyst 207
Salt Typhoon Stunning Risks to Global Security

Salt Typhoon Stunning Risks to Global Security

When commercial cloud and hosting services start looking like spy tools, who do you trust—and how do you protect yourself? Recent attributions tie parts of China’s tech ecosystem to the “Salt Typhoon” campaigns, showing how misconfigured or abused legitimate services can quietly power large-scale espionage and why stronger transparency, vetting and cross-border cooperation are urgently needed.

Analyst 207
generative AI: Stunning Risky Threats

generative AI: Stunning Risky Threats

When generative AI meant to boost productivity starts handing criminals step-by-step playbooks, everyone loses — Anthropic warns Claude is being misused to draft ransomware, fake IT credentials and scale social-engineering attacks. We urgently need smarter safeguards, stronger authentication and faster defender adoption to make AI a force for protection, not a shortcut to crime.

Analyst 207
AI-powered ransomware: Stunning New Risk Exposed

AI-powered ransomware: Stunning New Risk Exposed

ESET just uncovered PromptLock — the first AI-powered ransomware that runs OpenAI’s gpt-oss:20b locally via Ollama to generate bespoke Lua payloads on the fly. It’s a wake-up call: dynamically generated malware can evade signature-based defenses, so teams must lock down local model hosting, boost runtime monitoring, and update incident playbooks.

Analyst 207
ShadowSilk Exclusive: Risky Cyber Heist Exposes 36 Govs

ShadowSilk Exclusive: Risky Cyber Heist Exposes 36 Govs

Group-IB says ShadowSilk quietly siphoned sensitive data from 36 government-linked targets across Central Asia and the Asia‑Pacific, proving stealthy, data-driven espionage can outflank regional defenses. Its modular tools and persistent backdoors underscore why governments must share intelligence, harden networks, and treat cybersecurity as an ongoing strategic priority.

Analyst 207
web hijacking: Stunning Diplomatic Threat

web hijacking: Stunning Diplomatic Threat

Imagine being a diplomat and not knowing your web traffic is being silently rerouted—Google has warned of a suspected state-backed web hijacking campaign hitting foreign ministries and diplomats across Asia. This stealthy interception can steal credentials, deploy malware, and influence negotiations, so stronger encryption, hardened captive‑portal workflows, and robust MFA are now mission‑critical.

Analyst 207
AI-powered ransomware: Exclusive Risky Breakthrough

AI-powered ransomware: Exclusive Risky Breakthrough

Researchers have uncovered PromptLock, a proof‑of‑concept ransomware that uses an open‑weight LLM to draft highly persuasive extortion messages—currently inactive in the wild but a clear warning that AI can amplify attackers’ social‑engineering tactics. Take it as a wake‑up call: patch, back up, segment networks, and sharpen detection before opportunistic criminals turn this experiment into a real threat.

Analyst 207
Hook Android Trojan: Stunning Dangerous Ransomware Threat

Hook Android Trojan: Stunning Dangerous Ransomware Threat

A new Hook Android Trojan variant now combines banking fraud with ransomware-style lockouts, letting attackers both steal credentials and hold phones hostage. Millions of users should tighten app sources, review permissions, and keep backups as defenders scramble to catch up.

Analyst 207
phishing campaign: Critical RAT Threat Exposed

phishing campaign: Critical RAT Threat Exposed

Researchers warn of a global phishing campaign that uses highly personalized emails and convincing fake sites to slip UpCrypter-wrapped downloads that install remote access trojans, giving attackers persistent control of machines. Stay cautious—verify unexpected requests, avoid untrusted downloads, enable MFA, and keep endpoint defenses tuned to block obfuscated threats.

Analyst 207
MixShell malware: Exclusive Risky Supply-Chain Threat

MixShell malware: Exclusive Risky Supply-Chain Threat

Attackers behind the ZipLine campaign are skipping noisy phishing emails and weaponizing corporate “Contact Us” forms to trick procurement staff into running an in-memory, fileless loader called MixShell that evades detection and targets U.S. supply-chain manufacturers. Treat unexpected vendor downloads with skepticism, verify requests through known channels, and beef up memory-level detection—because human trust is now a favorite attack vector.

Analyst 207
malware-laden Android apps: Stunning Threats Reveal Risk

malware-laden Android apps: Stunning Threats Reveal Risk

Got a scary “your phone is infected” pop-up despite downloading from Google Play? A new Zscaler report found over 19 million installs of malware-laden Android apps that slipped past scans via malicious SDKs, repackaging and delayed activation — a reminder to keep apps updated, check permissions, and stay a little skeptical even in official stores.

Analyst 207
fake support sites: Stunningly Dangerous macOS Threat

fake support sites: Stunningly Dangerous macOS Threat

Think twice before downloading “help” tools from ads—attackers are using convincing fake macOS support sites and malvertising to deliver the Atomic macOS Stealer (AMOS) and quietly scoop up credentials, cookies and crypto wallets. Verify support pages with vendors directly and treat unsolicited downloads like risky strangers offering to fix your device.

Analyst 207
Trojanized Go module: Stunning Risky Credential Stealer

Trojanized Go module: Stunning Risky Credential Stealer

A trojanized Go module posing as an SSH testing tool was found quietly exfiltrating successful login IPs, usernames and passwords to a hard‑coded Telegram bot—proof that convenience in open‑source can hide dangerous supply‑chain risks. Audit and pin dependencies, verify modules, and monitor outbound traffic to stop silent credential leaks before they become breaches.

Analyst 207
fake CAPTCHAs: Stunningly Dangerous ClickFix Scam

fake CAPTCHAs: Stunningly Dangerous ClickFix Scam

That harmless prove youre human CAPTCHA is being weaponized—attackers use convincing fake CAPTCHAs to trick people into pasting commands that download and run malware. Microsofts ClickFix report shows how believable pages and step‑by‑step prompts turn everyday trust into a direct route to compromise.

Analyst 207