Threat actors repurpose Open Redirect vulnerabilities to bypass spam filters and deliver the LogoKit phishing content using trusted domains such as Snapchat and Google. LogoKit dynamically generates landing pages, steals credentials, and leverages compromised …
Category: Threat Research
Cisco Talos and CSIRT describe a May 2022 compromise in which a Cisco employee’s Google account credentials (synced from a personal browser) enabled initial VPN access after MFA bypass via vishing and MFA fatigue. The investigation links the actors to an initi…
Unit 42 analyzes Tropical Scorpius (UNC2596) activity, detailing Cuba Ransomware’s evolution with new tools like ROMCOM RAT, KerberCache, and a kernel driver to defeat defenses, plus its connection to the Industrial Spy marketplace. The report covers ransomwar…
SmokeLoader (Dofoil) continues to leverage aging vulnerabilities to deliver its payload via a crafted phishing email chain, decrypt an embedded OLE stream, and drop a final DLL payload that is associated with zgRAT. The campaign demonstrates how attackers rely…
Two sentences summarizing: This analysis confirms a Maui ransomware incident in 2022 attributed to Andariel, who deployed a DTrack variant about ten hours earlier on the same target. The operation appears global in scope, with a Japanese victim and overlaps to…
Authored by Dexter Shin McAfee’s Mobile Research Team has identified new malware on the Google Play Store. Most of them…
The post New HiddenAds malware affects 1M+ users and hides on the Google Play Store appeared first on McAfee Blog….
SharpExt is a browser-extension malware used by Kimsuky to steal emails and attachments, as detailed by Volexity and related researchers. The campaign maps to older activity, leverages a large network of domains for delivery and C2, and targets US, Europe, and…
Orchard is a botnet family that uses DGA technology to generate C2 domains, incorporating Bitcoin wallet transaction data as inputs to the DGA to increase unpredictability. It has evolved across three versions since 2021, combining hardcoded DuckDNS domains wi…
An April 2022 intrusion saw BumbleBee act as the initial access loader, enabling multi-stage payloads and outbound C2 communication within a Windows environment. The operation featured credential dumping, Kerberoasting, privilege escalation tooling, and Cobalt…
Researchers analyze CrowdStrike’s Adversary Quest 2022 CATAPULT SPIDER track, which centers on a Dogecoin-driven ransomware campaign leveraging CHM phishing, encoded PowerShell, and a Dogecoin-based C2. The storyline uncovers multi-stage payloads, a vulnerable…
APT31 renewed its attacks on Russian media and energy companies by leveraging a malicious document that loads a VMProtect-packed payload, linking the activity to the APT31 toolkit. The campaign uses cloud storage services (notably Yandex.Disk) as C2 to blend i…
GwisinLocker.Linux is a Linux-based ransomware variant linked to the Gwisin threat actor, targeting South Korean industrial and pharmaceutical firms. It encrypts files using per-file AES keys (with RSA-wrapped keys), stores keys in .mcrgnx0 files, appends .mcr…
ASEC has observed ongoing distribution of North Korea–related Word files used in Kimsuky campaigns, including variants that rely on mshta. Attackers impersonate Korean organizations to trigger a follow-up email with a link to download a malicious Word document…
Dark Utilities is a C2-as-a-Service platform released in early 2022 that provides remote access, DDoS, and cryptocurrency mining capabilities, with payloads for Windows, Linux, and Python hosted on IPFS to resist takedowns. Since launch, malware samples have r…
ROADSWEEP encrypts files across discovered drives using RC4 and marks them with a .lck extension, then performs a wipe with a self-delete to cover its tracks. The activity is part of a broader campaign involving ZEROCLEAR and CHIMNEYSWEEP, tied to a politicall…