From open-source to open threat: Tracking Chaos RAT’s evolution

Chaos RAT is an open-source remote administration tool written in Golang that targets Windows and Linux systems, offering extensive capabilities such as file management, remote shell, and command execution. Recent analysis uncovered new variants, a critical vulnerability in its web panel enabling remote code execution, and its use in real-world attacks disguised as a Linux network troubleshooting utility. #ChaosRAT #CVE-2024-30850 #CVE-2024-31839

Read More
AMOS Variant Distributed Via Clickfix In Spectrum-Themed Dynamic Delivery Campaign By Russian Speaking Hackers

A new variant of the Atomic macOS Stealer (AMOS) campaign uses typo-squatted domains mimicking Spectrum to deliver malicious payloads targeting macOS users by harvesting system passwords. The campaign is linked to Russian-speaking cybercriminals and employs multi-platform social engineering tactics with poorly implemented logic in its delivery infrastructure. #AtomicMacOSStealer #SpectrumTyposquatting #RussianCybercriminals

Read More
Operation Phantom Enigma

A malicious campaign named Phantom Enigma targets Brazilian users primarily through phishing emails distributing malicious browser extensions and Mesh Agent malware. The attackers use compromised company servers to send phishing emails and deploy sophisticated scripts to capture banking credentials, focusing on Banco do Brasil customers. #PhantomEnigma #MeshAgent #BancoDoBrasil

Read More
OtterCookie: Analysis of Lazarus Group Malware Targeting Finance and Tech Professionals

OtterCookie is a new stealer malware linked to the North Korean Lazarus Group, distributed via fake freelance job offers targeting professionals in tech, finance, and cryptocurrency sectors. It steals browser credentials, macOS keychains, and crypto wallets before exfiltrating data to a U.S.-based server and deploying a second-stage payload called InvisibleFerret. #OtterCookie…

Read More
⚑ Weekly Recap: APT Intrusions, AI Malware, Zero-Click Exploits, Browser Hijacks and More

This cybersecurity update highlights recent active threats, including APT41’s use of Google Calendar for command-and-control and the takedown of services aiding malware obfuscation. Key incidents involve nation-state cyberattacks, vulnerabilities in popular software, and innovative malware such as GhostSpy and Lumma Stealer. #APT41 #VoidBlizzard…

Read More
New EDDIESTEALER Malware Bypasses Chrome’s App-Bound Encryption to Steal Browser Data

A new Rust-based info stealer called EDDIESTEALER is spreading via ClickFix social engineering tactics involving fake CAPTCHA pages. It collects sensitive data from infected hosts and employs sophisticated evasion techniques, showing the increasing trend of malware developed in modern programming languages. #EDDIESTEALER #RustMalware…

Read More