Articles tagged "Malware"

Found 828 articles

A recent report has revealed that the FEMITBOT platform is being exploited for large-scale scams, including fake cryptocurrency schemes and fraudulent financial services. These scams also involve the distribution of malware disguised as AI tools and streaming sites. Users of Telegram are particularly at risk, as these mini apps are being used to lure individuals into these scams. The situation raises significant concerns about the safety of online financial transactions and the potential for users to lose money or have their personal information compromised. As these scams proliferate, it is crucial for users to remain vigilant and skeptical of unsolicited offers in online messaging platforms.

Read Original

DigiCert, a prominent certificate authority, has revoked a number of certificates after a security breach involving its internal support portal. Hackers managed to deliver malware through a customer chat channel, which infected an analyst’s system. This breach allowed them access to sensitive internal systems, raising concerns about the security of the certificates issued by DigiCert. The incident highlights significant vulnerabilities in customer support systems, emphasizing the need for stronger security measures in such environments. Companies relying on DigiCert for SSL certificates may need to assess the implications of this breach on their own security postures.

Read Original

The cybercrime group Silver Fox, based in China, has launched a phishing campaign targeting organizations in India and Russia using a new malware known as ABCDoor. The attackers sent emails posing as communications from the Income Tax Department of India in December 2025, followed by similar attempts aimed at Russian entities. This tactic is concerning as it exploits tax-related themes to gain trust and infiltrate systems. The use of ABCDoor malware can lead to unauthorized access to sensitive information, potentially compromising the security of targeted organizations. As cyber threats continue to evolve, it is crucial for companies in these regions to enhance their security measures and educate employees on recognizing phishing attempts.

Read Original
Critical
Paying Ransom Won’t Help as VECT 2.0 Ransomware Destroys Data Irreversibly

Hackread – Cybersecurity News, Data Breaches, AI and More

Actively Exploited

VECT 2.0 ransomware is a new and dangerous strain that has been discovered to have serious flaws that can irreversibly destroy files. Victims of this ransomware will find that paying the ransom is futile, as the data is lost permanently, making recovery impossible. This situation poses a significant risk to individuals and organizations worldwide, as it undermines the traditional hope of recovering data through ransom payments. The emergence of VECT 2.0 highlights the evolving tactics of cybercriminals and the need for better preventive measures. Users and organizations are urged to strengthen their cybersecurity defenses to avoid falling victim to this destructive ransomware.

Read Original

Recent research has revealed that scammers are exploiting Telegram's Mini App feature to conduct crypto scams and distribute Android malware. These operations involve impersonating reputable brands to trick users into providing personal information or investing in fraudulent schemes. The use of Telegram's platform allows these scams to reach a wide audience, putting many users at risk of financial loss and malware infections. This situation raises concerns about the security measures in place on social media platforms and highlights the need for users to be cautious when engaging with unfamiliar applications or links. Overall, this incident serves as a reminder for users to verify the legitimacy of offers and be vigilant against potential scams online.

Read Original

A new software supply chain attack has been linked to a GitHub account named 'BufferZoneCorp.' This campaign involved malicious Ruby gems and Go modules that were disguised as legitimate libraries. Attackers used these sleeper packages to steal user credentials and tamper with continuous integration (CI) systems. Developers and organizations using Ruby and Go programming languages should be particularly vigilant, as this could compromise their software development processes. It's crucial for teams to verify the sources of their libraries and monitor for any unusual activity to prevent potential breaches.

Read Original

A recent supply chain attack has targeted four SAP npm packages, embedding malware designed to steal user credentials. This incident is part of a broader campaign known as mini Shai-Hulud, which researchers have linked to a group of attackers aiming to exploit vulnerable software components. Organizations that rely on these SAP packages for their applications could be at risk, as the compromised packages can put sensitive information in jeopardy. Users are advised to review their systems for these packages and take appropriate measures to secure their credentials. The incident highlights ongoing vulnerabilities in software supply chains and the importance of vigilance in software management.

Read Original
Actively Exploited

Three individuals have been arrested in connection with a significant hacking incident involving over 610,000 stolen Roblox accounts. The suspects are accused of distributing malware that allowed them to gain unauthorized access to users' accounts and then selling that access on Russian online marketplaces. This breach not only puts the affected users at risk of losing their personal information and in-game assets but also raises broader concerns about online security and the vulnerability of gaming platforms. The incident highlights the necessity for stronger cybersecurity measures to protect user accounts, especially in popular online environments like Roblox, where many young users are active.

Read Original
Actively Exploited

The Brazilian hacker group LofyGang has made a comeback, targeting Minecraft players with a new malware strain called LofyStealer or GrabBot. This marks their first attack in over three years, indicating a renewed focus on exploiting gamers. The malware is designed to steal sensitive information from users, which can lead to account takeovers and other malicious activities. As Minecraft remains a popular game, players should be particularly vigilant about their account security and be cautious of any suspicious links or downloads. This resurgence of LofyGang emphasizes the ongoing risks faced by online gaming communities.

Read Original
Actively Exploited

A recent supply chain attack, dubbed the Mini Shai-Hulud attack, has targeted SAP's NPM packages. This attack involves a preinstall hook that downloads and executes a malicious Bun binary, which allows the attackers to evade security monitoring measures. As a result, developers using these NPM packages may unknowingly execute harmful code within their environments. This incident raises significant concerns about the integrity of software supply chains, especially for organizations relying on third-party packages for their development processes. Users of SAP NPM packages should be vigilant and review their dependencies to mitigate potential risks.

Read Original

Researchers have identified a new Python-based backdoor called DEEP#DOOR, which is designed to gain persistent access to compromised systems and steal sensitive information, including browser and cloud credentials. The attack is initiated through a batch script named 'install_obf.bat', which disables essential Windows security features, allowing the malware to operate undetected. This backdoor can pose significant risks to both individual users and organizations, as it can access a wide range of data stored on affected devices. The stealthy nature of DEEP#DOOR makes it particularly dangerous, as it can remain hidden while actively siphoning off sensitive credentials. Users and companies need to be vigilant about their security measures to prevent such intrusions.

Read Original

The Silver Fox group is actively targeting organizations in Russia and India by impersonating tax authorities. They are distributing two types of malware: ValleyRAT and the newly identified ABCDoor backdoor. This tactic not only exploits trust in governmental entities but also poses significant risks to sensitive data and organizational operations. The use of these backdoors can allow attackers to gain unauthorized access to networks, potentially leading to data breaches and operational disruptions. Companies in these regions should be vigilant and ensure their cybersecurity measures are robust against such impersonation attacks.

Read Original

Researchers have identified two new malware families, CORDIAL SPIDER and SNARKY SPIDER, that pose significant risks to organizations. These threats primarily target enterprise systems, potentially exposing sensitive data and compromising network integrity. CORDIAL SPIDER is known for its ability to evade traditional security measures, while SNARKY SPIDER employs social engineering tactics to trick users into executing malicious payloads. Companies must remain vigilant and adopt advanced threat detection tools, such as Falcon Shield, to safeguard against these evolving attacks. Failure to do so could result in severe financial and reputational damage.

Read Original

Cybersecurity researchers have identified a new wave of attacks linked to North Korea, involving malicious code embedded in an npm package called '@validate-sdk/v2'. This package, which is falsely advertised as a utility for software development, actually serves as a vehicle for malware. The attackers have utilized artificial intelligence to insert this malicious code, making it harder to detect. As a result, developers who unknowingly incorporate this package into their projects could be exposing their systems to remote access trojans (RATs). This incident highlights the increasing sophistication of cyber threats, particularly from state-sponsored actors, and emphasizes the need for developers to scrutinize third-party packages before use.

Read Original

Researchers have identified a malicious npm dependency that is associated with an AI-assisted code commit. This dependency is designed to steal sensitive information and compromise cryptocurrency wallets. Developers who incorporate this malicious package into their projects risk exposing their private keys and other critical data. This situation is particularly concerning for those involved in crypto transactions, as the attackers could gain unauthorized access to funds. Users and developers should be vigilant and review their dependencies carefully to avoid falling victim to this scheme.

Read Original
PreviousPage 29 of 56Next