Articles tagged "Malware"

Found 828 articles

The ShinyHunters group has been at the forefront of several high-profile data breaches, demonstrating that attackers can achieve significant damage without relying on malware or zero-day exploits. Instead, they often utilize stolen credentials and other readily available information to access sensitive data. This method has led to the exposure of user information from various services, impacting numerous companies and their customers. The implications of these breaches are severe, as they compromise personal data and can lead to identity theft, financial loss, and a loss of trust in the affected services. Organizations need to strengthen their security measures, including enforcing stronger password policies and implementing multi-factor authentication to mitigate such risks.

Read Original

A recent analysis by a Kaspersky researcher has uncovered a global malicious campaign that spreads VBScript files through WhatsApp. These scripts are designed to install a Remote Monitoring and Management (RMM) software, specifically a UEMS agent, via a multi-step infection process. This type of malware could allow attackers to gain control over infected devices, posing significant risks to both individual users and organizations. The use of popular messaging platforms like WhatsApp for distribution makes this attack particularly concerning, as it can easily bypass traditional security measures. Users need to be cautious about unexpected messages and attachments on these platforms to protect themselves from this ongoing threat.

Read Original

A new type of malware called AryStinger is infecting legacy home routers, turning them into a distributed reconnaissance and proxy network. Researchers from QiAnXin's XLab have identified at least 4,300 infected routers, and that number is likely to grow. Unlike typical malware that creates a DDoS botnet, AryStinger is designed for the reconnaissance phase of an attack, gathering information before any actual intrusion occurs. This shift in tactics poses a significant risk as attackers can use these compromised devices to gather sensitive data about potential targets without raising alarms. Home users and organizations relying on older routers could find themselves vulnerable if these devices are compromised.

Read Original
Actively Exploited

The latest Malware newsletter from Security Affairs discusses several significant cybersecurity incidents affecting a wide range of sectors. Notably, a supply chain attack on OptinMonster has compromised 1.2 million websites, raising concerns about the security of third-party services. Additionally, a China-linked threat actor has targeted both public and private medical organizations, focusing on areas like artificial intelligence and national defense research. Another piece highlights the Rokarolla malware, which is designed to steal banking information from Android devices. These incidents underscore the ongoing risks faced by organizations and individuals alike, as attackers increasingly exploit vulnerabilities across various sectors.

Read Original

The latest edition of the Security Affairs newsletter discusses several cybersecurity topics, including a new malware called GentleKiller, which is designed to evade endpoint detection and response (EDR) systems. This malware is linked to a global credential-spraying operation that targets numerous organizations, exposing their login credentials. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about active exploitation of various vulnerabilities, urging companies to take immediate action to protect their systems. The newsletter serves as a reminder of the ongoing threats in the cybersecurity landscape and the need for organizations to remain vigilant against evolving attack methods.

Read Original

A new botnet called AryStinger has been discovered, infecting over 4,000 D-Link routers worldwide. This malware targets outdated devices, converting them into proxies that can handle malicious traffic. Users of affected routers may be unaware that their devices are being misused in cyberattacks. The presence of this botnet raises concerns about the security of Internet of Things (IoT) devices, particularly those that are not regularly updated. This incident serves as a reminder for users to keep their router firmware up to date and to secure their home networks against potential threats.

Read Original

A new ransomware strain called 'Prinz Eugen' has emerged, targeting recently modified files for encryption while notably avoiding the use of a ransom note on the infected systems. This approach may confuse victims, as they might not realize they've been attacked until it's too late. The ransomware's focus on recent files could affect businesses and individuals who regularly update their documents and data, making recovery more complicated. Users are urged to maintain regular backups and enhance their cybersecurity measures to protect against this evolving threat. The absence of a ransom note also raises questions about the attackers' intentions and future tactics.

Read Original
Actively Exploited

CryptoBandits is a new type of malware that combines data theft with remote code execution capabilities. It uses a local SOCKS5 proxy to route its traffic, which allows it to operate discreetly while abusing the Tor network for anonymity. This dual functionality poses significant risks, as it can both steal sensitive information and provide attackers with a backdoor into compromised systems. Users and organizations should be vigilant, as this malware can impact various systems and potentially lead to severe data breaches. The ongoing threat of CryptoBandits highlights the need for enhanced security measures in environments where sensitive data is handled.

Read Original

A recent operation known as Operation Endgame has successfully removed SocGholish malware from around 15,000 websites linked to the notorious Evil Corp hacking group. This malware is often used to deliver ransomware and has been a significant threat to users who visit compromised sites. The operation aims to disrupt the infrastructure that Evil Corp relies on to spread their malicious software, which is a positive step in combating cybercrime. By targeting these infected sites, authorities hope to reduce the risk of malware infections and protect users from potential data loss or financial harm. This incident highlights ongoing efforts to dismantle the operations of major ransomware gangs and improve online security for everyone.

Read Original

In a significant law enforcement operation dubbed Operation Endgame, authorities took down 106 command and control (C&C) servers and domains associated with the SocGholish botnet. This action has led to the cleanup of around 15,000 WordPress websites that were compromised by this malware. The SocGholish botnet is known for distributing malicious software through fake updates and compromised sites, which can lead to serious security risks for both website owners and their visitors. This takedown not only disrupts the botnet's operations but also helps protect countless users from falling victim to its deceptive tactics. The operation underscores the ongoing battle against cybercrime and the importance of proactive measures to secure online platforms.

Read Original

A new malware campaign is manipulating VirusTotal, a widely used malware scanning service, to enhance the reputation of malicious software. This campaign primarily involves a clipboard hijacker, which can steal sensitive information from users' clipboards. To boost its visibility, the attackers are also using 'ghost networks' on social media, which artificially inflate engagement and spread awareness of their malicious tools. This approach not only makes the malware seem more legitimate but also complicates detection efforts. As a result, users who visit compromised sites or engage with these ghost networks may unknowingly expose their data to theft.

Read Original
Actively Exploited

Authorities have successfully dismantled the SocGholish botnet operated by the cybercrime group Evil Corp. This operation involved the shutdown of 106 servers and the remediation of nearly 15,000 infected websites. SocGholish is known for distributing malware that targets users by masquerading as legitimate software updates, often leading to credential theft or system compromise. The action taken by cybersecurity firms and law enforcement is significant as it disrupts a major source of cyber threats that affect both businesses and individual users online. The widespread impact of this botnet highlights the ongoing risks posed by such malware campaigns and the importance of proactive cybersecurity measures.

Read Original
Critical
Operation Endgame Disrupts SocGholish Malware Infrastructure

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

International law enforcement agencies recently launched Operation Endgame, targeting the infrastructure behind the SocGholish malware, associated with the threat actor TA569. This operation resulted in the takedown of over 100 command-and-control servers and addressed nearly 15,000 compromised websites that were being used to distribute the malware. SocGholish is primarily known for its role in delivering ransomware and other malicious payloads, affecting users worldwide. The dismantling of this infrastructure is significant as it disrupts the operations of cybercriminals and protects potential victims from falling prey to these malicious attacks. By targeting such extensive networks, authorities aim to reduce the overall risk of cyber threats stemming from this group.

Read Original
Actively Exploited

Researchers have discovered a new Rust-based crypto clipper that uses fake GitHub stars and AI-generated YouTube videos to attract victims. This malware secretly steals cryptocurrency by intercepting clipboard data, making it particularly dangerous for users engaging in crypto transactions. The clipper disguises itself as a legitimate tool, misleading users into downloading it. This incident is concerning as it highlights how attackers are increasingly using social engineering tactics to gain trust and spread malware. Users are advised to be cautious about the tools they download and to verify sources before installation.

Read Original

International law enforcement has successfully taken action against the SocGholish botnet, which is linked to the notorious Russian cybercrime group Evil Corp. They cleaned nearly 15,000 WordPress websites infected with malware and dismantled over 100 servers used in these attacks. This operation is significant as SocGholish is known for distributing malware that targets users through fake software updates and phishing tactics. The cleanup effort not only helps to secure the affected websites but also disrupts the operations of a well-established cybercrime group, which could reduce the risk of future attacks on unsuspecting users. The impact of this operation highlights the ongoing battle against cybercrime and the importance of maintaining secure online environments.

Read Original
PreviousPage 21 of 56Next