Skip to main content

Tag: microsoft threat intelligence

5 articles

Empty corporate office with computer workstations and daylight through tall windows.

Medusa Affiliate Unveils StormEncryptor Ransomware

A former Medusa affiliate, now tracked as Storm-1175, has resurfaced with a new ransomware called StormEncryptor, marking a significant shift away from Medusa and a return to malicious activity after a months-long hiatus. This development signals a fresh threat in the cybersecurity landscape.

Analyst 207
Person sitting at laptop in coffee shop with blurred screen.

MacOS Malware Campaign Exploits Browser Fingerprinting

A sneaky MacOS malware campaign, known as ClickFix, has set up over 250 fake websites that trick visitors into downloading malware by fingerprinting their browsers and only serving the malicious content to those that appear to be genuine Mac users. This clever tactic allows the attackers to selectively target their victims, making it harder to detect and defend against.

Analyst 207
Laptop on a desk with a Chromium browser window open, displaying a search results page.

Malicious Chrome Extension Exploits Perplexity AI Brand for Data Collection

Beware of a fake Chrome extension hiding in plain sight: masquerading as Perplexity AI, it secretly intercepts your searches and reroutes them through attacker-controlled servers. This sneaky impostor uses a similar name and branding to the real deal, but its true intentions are far from AI-powered assistance.

Analyst 207
Software development workspace with laptop, screens, and tools, hinting at network infrastructure.

Miasma Malware Poisons Over 20 npm Packages

In a lightning-fast attack, hackers poisoned over 20 npm packages with Miasma malware, completing the coordinated operation in under three seconds. The attackers compromised an npm maintainer account to publish tainted updates to popular packages.

Analyst 207
Person sitting at desk with laptop open, hands poised over keyboard in a brightly-lit office setting.

Cybercriminals Exploit AI Hype in Social Engineering Attacks

Cybercriminals are cleverly exploiting our curiosity about AI to launch sophisticated social engineering attacks, using trusted AI names and urgent lures to trick victims into divulging sensitive info or downloading malware. By tapping into our desire to stay ahead of the curve, attackers are able to bypass our usual caution and catch us off guard.

Analyst 207