Skip to content

Cybersecurity News Everyday

Stay Ahead of Cyber Threats – Daily Security Insights, Powered by AI

    • Cyber Attack & Data Breach
    • Daily Recap
    • Disclaimer
    • Hacked: Web Defacement
    • My Bookmarks
    • Security Report
    • User Bookmark Dashboard
    • Web Statistics
    • YouTube Overview
    • Welcome!
    • Threat Research
    • Security News
    • Ransom Monitor
    • Interesting Stuff

Category: Threat Research

Threat Research

Lazarus Group Exploiting Log4Shell Vulnerability (NukeSped) – ASEC BLOG

April 18, 2022October 15, 2025 Securonix

Lazarus Group targeted Korea by exploiting the Log4j CVE-2021-44228 vulnerability on unpatched VMware Horizon to install NukeSped and related components. The operation includes NukeSped backdoors, INFOSTEALER, and Jin Miner modules, with data exfiltration and …

Read More
Threat Research

Bumblebee Malware from TransferXL URLs

April 18, 2022October 15, 2025 Securonix

EXOTIC LILY is observed distributing Bumblebee malware through TransferXL by sharing ZIP archives that contain ISO disk images. The infection chain includes mounting the ISO, running a Windows shortcut that launches a hidden DLL via rundll32, followed by Bumbl…

Read More
Threat Research

Threat Actors Chaining Unpatched VMware Vulnerabilities for Full System Control | CISA

April 18, 2022October 17, 2025 Securonix

CISA warns that malicious actors linked to APT activity are exploiting CVE-2022-22954 and CVE-2022-22960 in VMware Workspace ONE Access and related products to achieve remote code execution and root-level access, chaining vulnerabilities for full system contro…

Read More
Threat Research

ITG23 Crypters Highlight Cooperation Between Cybercriminal Groups

April 18, 2022October 18, 2025 Securonix

IBM X-Force researchers dissect ITG23’s crypter operations, revealing a sprawling ecosystem where ITG23 and partner groups crypt, distribute, and deploy malware across Trickbot, Emotet, IcedID, Qakbot, MountLocker, Gozi, and more. The findings show a highly co…

Read More
Threat Research

Uncovering a Kingminer Botnet Attack Using Trend Micro Managed XDR

April 14, 2022October 15, 2025 Securonix

Trend Micro’s Managed XDR investigated a Kingminer botnet attack that targeted an MSSQL server by abusing obfuscated PowerShell and VBScript, leading to a fileless miner deployment. The findings trace the attack chain from initial exploitation through payload …

Read More
Threat Research

Chaos Ransomware Variant Sides with Russia | FortiGuard Labs 

April 14, 2022October 13, 2025 Securonix

FortiGuard Labs reports a Chaos ransomware variant that appears to side with Russia, delivering destructive payloads and offering no decryption option. The malware encrypts small files with AES-256 (RSA-wrapped keys) and fills larger files with random data, wh…

Read More
Threat Research

Harmful Help: Analyzing a Malicious Compiled HTML Help File Delivering Agent Tesla

April 14, 2022October 15, 2025 Securonix

Unit 42 analyzes a multi-stage attack that begins with a malicious Compiled HTML Help (.chm) file delivered inside a 7z archive and culminates with Agent Tesla loading and exfiltrating data via FTP. The operation uses obfuscated JavaScript and PowerShell acros…

Read More
Threat Research

Custom PowerShell RAT targets Germans seeking information about the Ukraine crisis

April 12, 2022October 13, 2025 Securonix

Threat actors lure Germans with updates about the Ukraine crisis via a decoy Baden-Württemberg site, delivering a PowerShell-based RAT that can steal data and execute commands. The operation uses AMSI bypass, creates a persistent scheduled task, and exfiltrate…

Read More
Threat Research

Onyx Ransomware Report – CYFIRMA

April 12, 2022October 16, 2025 Securonix

Onyx is a ransomware observed in April 2022 that encrypts files, appends the .ampkcz extension, and leaves a readme.txt ransom note. It uses several evasion, persistence, and exfiltration techniques, including process checks, startup-folder modifications, and …

Read More
Threat Research

KurayStealer: A Bandit Using Discord Webhooks

April 12, 2022October 14, 2025 Securonix

KurayStealer is a Python-based malware builder that harvests passwords and screenshots and exfiltrates them to Discord via webhooks. The tool is offered in free and VIP versions, with OSINT linking the author to Spain and a presence on YouTube and Discord. #Ku…

Read More
Threat Research

From 0-Day to Mirai: 7 days of BIG-IP Exploits

April 11, 2022October 15, 2025 Securonix

Two sentences: Researchers observed a rapid exploit campaign against F5 BIG-IP CVE-2022-1388, deploying web shells and Mirai-era malware within days. The events highlight the danger of exposed devices and the need for secure configurations and timely patching.…

Read More
Threat Research

Cybereason vs. Quantum Locker Ransomware

April 11, 2022October 15, 2025 Securonix

Quantum Locker is a fast, human-operated ransomware strain linked to MountLocker that encrypts data within hours of infection, often leaving defenders little time to respond. Cybereason Nocturnus classifies the threat as HIGH, notes a RansomOps playbook, and h…

Read More
Threat Research

Phishing Campaign Delivering Three Fileless Malware: AveMariaRAT / BitRAT / PandoraHVNC – Part I | FortiGuard Labs 

April 11, 2022October 14, 2025 Securonix

Fortinet FortiGuard Labs uncovered a phishing campaign that delivers three fileless malware families on Windows via a malicious Excel Add-In with VBA macros, leveraging WMI, HTML/JavaScript, and PowerShell to load and execute payloads. The operation uses persi…

Read More
Threat Research

COBALT MIRAGE conducts ransomware operations in U.S.

April 11, 2022October 15, 2025 Securonix

Secureworks CTU researchers analyzed COBALT MIRAGE’s ransomware operations in the United States, spotting two intrusion clusters: Cluster A uses BitLocker/DiskCryptor for opportunistic ransomware, while Cluster B pursues targeted intrusions with some ransomwar…

Read More
Threat Research

TA578 using thread-hijacked emails to push ISO files for Bumblebee malware

April 8, 2022October 16, 2025 Securonix

TA578, identified by Proofpoint as the threat actor behind the Contact Forms campaign, is pushing ISO files for Bumblebee malware through thread-hijacked emails. The analysis compares two May 2022 infection chains and notes similarities to the Contact Forms op…

Read More

Posts pagination

Previous 1 … 520 521 522 … 534 Next

What are you looking for ?

  • 🖥️ [ D A S H B O A R D ]
  • 🕵️‍♂️ Threat Research
  • 📰 Security News
  • 🚨 Attack & Data Breach
  • 🛑 Ransomware Monitor
  • 💀 Hacked! Web Defacement
  • ✨ Interesting Stuff
  • 📺 Youtube Overview
  • 🔍 Google Cybersecurity
  • 📢 Telegram Notification
  • 📰 News Daily Recap
  • 📰 Security Report
  • X / T W I T T E R
  • B L U E S K Y
  • L I N K E D . I N
  • T H R E A D S
  • T E L E G R A M
  • F A C E B O O K

Website Disclaimer

Proudly powered by WordPress | Theme: Fairy Dark by Candid Themes.