Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

Qakbot Being Distributed in Korea Through Email Hijacking – ASEC BLOG

April 6, 2023October 17, 2025 Securonix

ASEC identifies Qakbot being distributed in Korea via hijacked email threads containing malicious PDF attachments. The attack chain involves opening the PDF, downloading a password-protected ZIP, an obfuscated WSF script, PowerShell, and rundll32 to execute Qa…

Read More
Threat Research

Increase in Observations of Qakbot Malware 

April 6, 2023October 17, 2025 Securonix

eSentire observed a surge in Qakbot information-stealing malware incidents across multiple industries in early April 2023, with phishing emails delivering zip archives containing a Windows script (.wsf), a PDF, or an HTML file via HTML smuggling. The campaign …

Read More
Threat Research

GuLoader Targeting the Financial Sector Using a Tax-themed Phishing…

April 6, 2023October 15, 2025 Securonix

GuLoader, also known as CloudEyE, targeted the financial sector via a tax-themed phishing lure and delivered Remcos RAT through a multi-stage PowerShell/VBS chain. eSentire’s TRU team documented the attack, including phishing, registry-based persistence, in-me…

Read More
Threat Research

Tech Support Scam Pivots from DigitalOcean to StackPath CDN

April 6, 2023October 16, 2025 Securonix

Attackers who previously abused DigitalOcean to host a tech support scam have expanded their operation to StackPath CDN to distribute the scam. Netskope Threat Labs observed a 10x increase in traffic to StackPath-hosted scam pages from February 1 to March 16 a…

Read More
Threat Research

Linux – focus on a cryptomining attack dubbed color1337 – TEHTRIS

April 6, 2023October 14, 2025 Securonix

TEHTRIS Threat Hunters document illicit cryptomining activity targeting Linux-based machines, observed on a France-hosted honeypot in January. The campaign, named Color1337, toggles between full-capacity cryptomining using diicot and rebound reconnaissance via…

Read More
Threat Research

Malware Disguised as Document from Ukraine’s Energoatom Delivers Havoc Demon Backdoor | FortiGuard Labs

April 5, 2023October 13, 2025 Securonix

FortiGuard Labs documents a malicious spoofed document impersonating Energoatom that delivers Havoc Demon backdoor via a multi-stage macro. The operation blends anti-analysis techniques, a payload hidden in a custom XML part, and Havoc C2 communications, with …

Read More
Threat Research

Another Malicious HTA File Analysis – Part 2

April 5, 2023October 17, 2025 Securonix

Part 2 of the HTA file analysis explains how the embedded payload is decrypted: base64 decoding, AES decryption in ECB mode, and gzip decompression to reveal the final payload. It also outlines the tooling workflow (base64dump.py, myjson-transform.py, numbers-…

Read More
Threat Research

Nokoyawa ransomware attacks with Windows zero-day

April 5, 2023October 18, 2025 Securonix

Security researchers uncovered a zero-day CLFS elevation-of-privilege flaw (CVE-2023-28252) used to deploy Nokoyawa ransomware, with patches issued by Microsoft on April 11, 2023. The campaign involved multiple unique CLFS exploits and a chain that includes ba…

Read More
Threat Research

Analysis of the First NuGet (.Net) Malicious Package Attack | JFrog

April 5, 2023October 16, 2025 Securonix

JFrog Security analyzes a NuGet supply-chain attack delivering Impala Stealer, a custom crypto stealer used against Exodus Wallet via typosquatting NuGet packages. The campaign uses a two-stage payload: a PowerShell init.ps1 that downloads and runs a Windows e…

Read More
Threat Research

Beijing Calling: About Chinese APTs | SECUINFRA

April 5, 2023October 20, 2025 Securonix

Two paragraphs summarize ongoing Chinese APT activity against EU governments and businesses, highlighting groups, tools, and defensive recommendations. The report details APT27, APT31, APT15, and Mustang Panda campaigns, including Linux and Windows backdoors a…

Read More
Threat Research

QueueJumper: Critical Unauthorized RCE Vulnerability in MSMQ Service

April 5, 2023October 13, 2025 Securonix

Check Point Research uncovered three MSMQ vulnerabilities, including the critical QueueJumper (CVE-2023-21554) that enables unauthenticated remote code execution via the 1801/tcp port, which was patched in the April Patch Tuesday update. Administrators are urg…

Read More
Threat Research

Recent IcedID (Bokbot) activity – SANS Internet Storm Center

April 5, 2023October 14, 2025 Securonix

IcedID (Bokbot) activity is described as thread-hijacked emails with PDFs linking to Google Firebase Storage hosting password-protected ZIP archives. The ZIP contains a digitally-signed EXE that installs IcedID on a Windows host, with persistence via scheduled…

Read More
Threat Research

Following the Lazarus group by tracking DeathNote campaign

April 5, 2023October 20, 2025 Securonix

The Lazarus group’s DeathNote cluster uses weaponized Word documents with decoys related to cryptocurrency to drop multi-stage payloads, evolving to target defense contractors and supply chains with new infection methods like remote template injection and Troj…

Read More
Threat Research

Threat Actor Spotlight: RagnarLocker Ransomware – Sygnia

April 4, 2023October 15, 2025 Securonix

Sygnia analyzes RagnarLocker, detailing its double-extortion operations against critical infrastructure and the group’s TTPs, including the use of RMS and AnyDesk for C2 and data exfiltration. The report also offers mitigations and hunting guidance to help org…

Read More
Threat Research

ASEC Weekly Phishing Email Threat Trends (March 26th, 2023 – April 1st, 2023) – ASEC BLOG

April 4, 2023October 16, 2025 Securonix

ASEC tracked phishing email threats for the week of March 26 to April 1, 2023, focusing on attachments and detailing distribution cases across FakePage, Downloader, Infostealer, Backdoor, Worm, and Trojan variants. FakePage was the dominant method (59%), accom…

Read More

Posts pagination

Previous 1 … 416 417 418 … 490 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.