Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

State-sponsored Attack Groups Capitalise on Russia-Ukraine War for Cyber Espionage – Check Point Research

March 22, 2022October 15, 2025 Securonix

Check Point Research shows how state-sponsored APT groups are exploiting the Russia-Ukraine war to run cyber-espionage campaigns worldwide, using war-themed spear-phishing, decoy documents, and multi-stage payloads against financial, governmental, and energy s…

Read More
Threat Research

Spoofed Invoice Used to Drop IcedID | FortiGuard Labs 

March 21, 2022October 16, 2025 Securonix

FortiGuard Labs uncovered a spearphishing operation targeting a Kyiv fuel company that used a spoofed invoice to entice a recipient to open a zipped attachment containing an ISO image that drops the IcedID banking Trojan. The actors use a LNK shortcut and Regs…

Read More
Threat Research

New Milestones for Deep Panda: Log4Shell and Digitally Signed Fire Chili Rootkits

March 21, 2022October 15, 2025 Securonix

FortiEDR detected a Deep Panda operation exploiting the Log4Shell flaw in VMware Horizon servers, resulting in opportunistic infections across multiple sectors and countries. The campaign introduced a backdoor called Milestone and a novel kernel rootkit named …

Read More
Threat Research

Transparent Tribe campaign uses new bespoke malware to target Indian government officials

March 21, 2022October 16, 2025 Securonix

Cisco Talos reports a new Transparent Tribe campaign targeting Indian government and military entities, deploying CrimsonRAT alongside bespoke stagers and implants. The operation uses fake domains mimicking legitimate government sites and multiple delivery met…

Read More
Threat Research

Emotet is Back

March 21, 2022October 14, 2025 Securonix

Emotet—a modular banking trojan that can download other malware such as TrickBot and IcedID—has re-emerged, with Cisco GTA enhancing detection coverage for its latest wave. The article details its infection flow, PowerShell payload chain, observable IOCs, and …

Read More
Threat Research

Purple Fox Uses New Arrival Vector and Improves Malware Arsenal

March 21, 2022October 13, 2025 Securonix

Purple Fox is a long-standing threat that has evolved with a new arrival vector and early access loaders, distributing trojanized installers masquerading as legitimate apps. This campaign expands the botnet by introducing new payloads, including a FatalRAT var…

Read More
Threat Research

New Conversation Hijacking Campaign Delivering IcedID

March 18, 2022October 14, 2025 Securonix

A new IcedID campaign uses conversation hijacking in phishing emails delivered from compromised Microsoft Exchange accounts to drop the IcedID loader. The operation shifts from office documents to ISO attachments, uses regsvr32 to proxy-run a DLL, and targets …

Read More
Threat Research

Conti Ransomware Attacks Persist With an Updated Version Despite Leaks

March 17, 2022October 19, 2025 Securonix

ThreatLabz analyzed Conti ransomware’s January 2022 update, noting it appeared before the February 2022 leaks but continued attacks afterward and added encryption and evasion improvements. The update introduced Safe Mode boot encryption, new command-line optio…

Read More
Threat Research

Muhstik Gang targets Redis Servers | Official Juniper Networks Blogs

March 17, 2022October 15, 2025 Securonix

Juniper Threat Labs uncovered a Muhstik-bot variant that targets Redis Servers via CVE-2022-0543 in Redis Debian packages, enabling code execution through Lua sandboxing. The campaign ties Muhstik activity to prior Confluence and Log4j attacks, deploying a dow…

Read More
Threat Research

Chinese Threat Actor Scarab Targeting Ukraine

March 16, 2022October 16, 2025 Securonix

Ukraine CERT (CERT-UA) ties the Chinese threat actor Scarab to UAC-0026, marking one of the first publicly reported Ukraine-targeted operations by a non-Russian APT. The campaign centers on a HeaderTip backdoor delivered via macro-enabled lure documents and a …

Read More
Threat Research

New JSSLoader Trojan Delivered Through XLL Files

March 16, 2022October 21, 2025 Securonix

Morphisec Labs reports a new JSSLoader variant delivered via unsigned XLL Excel add-ins, leveraging Excel’s add-in loading to fetch a payload. The campaign highlights evasion tactics (obfuscation and varying user-agents) and notes FIN7 as the historical threat…

Read More
Threat Research

Beware of Email Scams Related to Current Events | FortiGuard Labs

March 16, 2022October 14, 2025 Securonix

Threat actors exploit timely events with phishing emails to harvest PII and establish footholds, using Emotet delivered through Excel 4.0 macros in tax-season and Ukraine-related scams. Fortinet FortiGuard Labs observed these campaigns and highlights defenses …

Read More
Threat Research

Operation Dragon Castling: APT group targeting betting companies – Avast Threat Labs

March 16, 2022October 16, 2025 Securonix

Avast Threat Labs identify Operation Dragon Castling, a Chinese-speaking APT campaign targeting betting companies in Southeast Asia (Taiwan, the Philippines, and Hong Kong). The operation uses a modular toolkit (MulCom backdoor, Proto8 CoreX/Core Module, and W…

Read More
Threat Research

Midas Ransomware: Tracing the Evolution of Thanos Ransomware Variants

March 16, 2022October 16, 2025 Securonix

ThreatLabz analyzes Thanos-based ransomware variants (Prometheus, Haron, Spook, and Midas) to show how operators shifted tactics in 2021, using RaaS builders, double extortion, and variant revamps to extend campaigns. The Midas variant encrypts files with Sals…

Read More
Threat Research

Vidar Malware Launcher Concealed in Help File | Trustwave

March 15, 2022October 14, 2025 Securonix

Phishing email delivers an ISO attached as request.doc that unpacks a CHM loader and Vidar payload. Vidar collects system and browser data, downloads dependencies from Mastodon-based C2, and can fetch additional malware from the same infrastructure. #Vidar #CH…

Read More

Posts pagination

Previous 1 … 479 480 481 … 489 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.