Articles tagged "Trojan"

Found 66 articles

A new campaign is targeting individuals and organizations in Cambodia using a remote access trojan (RAT) known as Spark RAT. The attackers are employing various lure themes, including government notices, public health information, and real estate content, to entice a wide range of potential victims. Notably, the campaign exploits a vulnerable OPSWAT driver, which allows the malware to disable security tools, making it easier for attackers to infiltrate systems undetected. This situation is concerning as it not only threatens personal and organizational data security but also raises alarms about the potential for broader impacts on national security and public safety. Users in Cambodia should be particularly vigilant and ensure their security measures are up to date.

Read Original
Actively Exploited

The 'Grandoreiro' banking Trojan has resurfaced in Mexico, adopting new features that make it more challenging for security professionals to detect and analyze. Initially disrupted by law enforcement actions, the malware has been updated to improve its stealth capabilities, raising concerns among cybersecurity experts. This malware primarily targets banking credentials, putting both individual users and financial institutions at risk. As it spreads, users in Mexico need to be particularly vigilant about their online banking security. The resurgence of Grandoreiro underscores the ongoing battle between malware developers and cybersecurity efforts, reminding everyone of the importance of safeguarding sensitive financial information.

Read Original

The Grandoreiro banking trojan has resurfaced with a new campaign targeting users in Latin America, first detected in May 2026. This malware employs a technique known as DLL sideloading to execute its malicious code. As a banking trojan, Grandoreiro is designed to steal sensitive financial information from its victims, which can lead to unauthorized access to their bank accounts. The resurgence of this trojan is concerning as it indicates that attackers are evolving their methods to bypass security measures. Users in affected regions should remain vigilant and enhance their security practices to protect against potential financial fraud.

Read Original

Researchers from Group-IB have identified a new Android malware called WindRelay that poses a significant threat to users by capturing real-time payment card data via NFC (Near Field Communication). The malware works in conjunction with the SpyNote remote access trojan, enabling attackers to gain control over a victim's device and relay sensitive information directly to them. The attack typically begins with a phone call from a fraudster impersonating a bank representative, tricking victims into revealing their financial data. This malware not only compromises personal financial security but also highlights the growing sophistication of cybercriminal tactics. Users need to be vigilant about unsolicited calls and consider additional security measures to protect their payment information.

Read Original
Actively Exploited

A new type of malware known as WindRelay is being used in conjunction with the SpyNote Remote Access Trojan (RAT) to execute live-call scams. This combination allows fraudsters to clone credit cards during phone calls, posing a significant risk to unsuspecting victims. The attackers can manipulate information in real-time, making it easier for them to deceive individuals and potentially steal their financial information. This incident serves as a reminder for users to be cautious during phone conversations, especially when discussing sensitive information. Awareness and vigilance are key to preventing falling victim to such scams.

Read Original
Actively Exploited

The latest Malware Newsletter from Security Affairs covers a variety of recent malware incidents. One notable threat involves fake Roblox cheats that are being distributed through Discord and online forums, which are actually Java stealers designed to harvest sensitive information from users. Another focus is on a complex operation involving a cluster of malicious npm packages that deliver a remote access Trojan (RAT) targeting Alibaba. This highlights the ongoing risks associated with third-party software and the importance of scrutinizing downloads from less reputable sources. As these attacks evolve, users and companies need to stay vigilant and prioritize security measures to protect their data.

Read Original

Zbtlink is facing scrutiny after claims from VulnCheck CTO Jacob Baines, who alleges that Zbtlink routers are designed to communicate with command and control servers, likening this feature to a 'phone-home trojan horse.' This allegation raises concerns about potential security vulnerabilities in Zbtlink products. The company has paused firmware downloads, which could indicate a response to these claims or an effort to address any underlying issues. Users of Zbtlink routers may need to be cautious about their device security and monitor for any unusual activity. The implications of these claims could be significant, as users’ personal data and privacy might be at risk if the allegations are proven true.

Read Original

Recently, researchers uncovered a series of malicious npm packages specifically designed to target developers using Alibaba tools. These packages contain a cross-platform remote access trojan (RAT), which allows attackers to gain unauthorized access to infected systems. The threat primarily affects developers working within the Alibaba ecosystem, raising significant security concerns for users who might inadvertently download and execute these harmful packages. This incident underscores the ongoing risks associated with open-source software repositories and highlights the importance of vigilance when managing dependencies. Developers are advised to verify the integrity of the packages they use to avoid falling victim to such attacks.

Read Original

A new Russian malware delivery service known as DOUBLECUP is utilizing a technique called ClickFix to infect users. This method involves embedding malware within PNG images that are stored in victims' browser caches. Once the PNG is loaded, it extracts hidden data and executes two types of malware: CountLoader and a new remote access trojan (RAT) called DeviceManager. This approach allows attackers to bypass traditional security measures and effectively deliver their payloads without raising immediate alarms. Users who fall victim to this scheme could face significant security risks, as the RATs can provide attackers with extensive control over infected devices.

Read Original

Researchers have identified a series of malicious npm packages that are specifically targeting users of Alibaba developer tools. This attack involves a cross-platform remote access trojan (RAT) and is part of a broader software supply chain attack aimed at Chinese-speaking environments. One notable package among those discovered is 'lib-mtop,' which shares its name with a private Alibaba package, suggesting a deliberate attempt to deceive users. The implications of this attack are significant, as it could allow attackers to gain unauthorized access to sensitive systems and data. Users of Alibaba tools should be particularly vigilant and consider reviewing their package dependencies to ensure they are not using any compromised versions.

Read Original

The source code for the Flying Eagle Android remote access trojan (RAT) has been found circulating in criminal Telegram channels, raising concerns about potential exploitation. Researchers from Hunt.io and NetAskari traced this malicious framework to 170 internet servers, linking it to a deceptive application masquerading as a Chinese Public Security service. This application targets Android users in China and reportedly supports functionalities related to payment passwords. The distribution of this RAT poses significant risks to users, as it can enable attackers to gain unauthorized control over devices, potentially leading to data theft and financial fraud. Users in China, particularly those using the compromised app, should be vigilant and avoid downloading unverified applications to protect their personal information.

Read Original

Two beta versions of npm packages from the @joyfill namespace have been compromised to include a remote access trojan (RAT) linked to the DEV#POPPER malware family. The affected packages are @joyfill/layouts version 0.1.2-2773.beta.0 and @joyfill/components version 4.0.0-rc24-2773-beta.4. When these packages are imported into a Node.js environment, they execute an implant that runs encrypted malicious code. This incident poses a significant risk to developers who might unknowingly use these compromised packages in their projects. Users are advised to avoid these specific versions and monitor for any unusual activity in their systems.

Read Original

The Lampion banking malware, which is believed to have originated in Brazil, is still making waves as it targets organizations in Portugal. This banking Trojan is designed to steal sensitive financial information, posing a significant risk to businesses and individuals alike. Recent reports indicate that Lampion is actively involved in ongoing attacks, raising alarms about the safety of financial transactions within the affected organizations. As cyber threats continue to evolve, it’s crucial for companies to remain vigilant and implement strong security measures to protect against such malware. The implications are serious, as breaches can lead to financial losses and damage to reputation.

Read Original
Actively Exploited

A new malware called Dolphin X has emerged, functioning as a remote access trojan (RAT) that utilizes artificial intelligence to assess and rank the value of its victims. By scoring infected users, cybercriminals can prioritize their targets based on the potential payoff. This AI-driven profiling allows attackers to focus their efforts on high-value individuals or organizations, making the threat particularly concerning for anyone at risk of being compromised. The introduction of such technology could lead to more targeted and effective cyberattacks, raising alarms for security professionals and users alike. As the malware spreads, it highlights the evolving tactics of cybercriminals and the need for enhanced security measures.

Read Original
Actively Exploited

A Brazilian banking Trojan is currently spreading in Portugal, targeting Portuguese businesses that share the same language as the attackers. This malware is particularly dangerous as it can compromise sensitive financial information, leading to significant financial losses for companies. With the seamless communication between Brazilian hackers and their Portuguese victims, the threat level has increased. Businesses need to be vigilant about their cybersecurity practices to protect themselves from this growing menace. The situation underscores the need for enhanced security measures, particularly for financial transactions and sensitive data handling.

Read Original
Page 1 of 5Next