Summary: A Mandiant report highlights the escalating cyber threats faced by Mexico, driven by a mix of global espionage and local cybercrime targeting various sectors. The report reveals that nation-state actors, particularly from China, North Korea, and Russia, are increasingly focusing on Mexican…
Tag: SPYWARE
Summary: A new Android malware named Trojan Ajina.Banker is targeting users in Central Asia by disguising itself as legitimate applications to steal banking information and intercept two-factor authentication (2FA) messages. The malware spreads primarily through social engineering tactics on messagi…
Mexico faces a diverse cyber threat landscape, with global state-sponsored espionage from PRC, North Korea, and Russia alongside rising ransomware and extortion campaigns, and growing use of commercial spyware against journalists and activists. Google and Mand…
Summary: Insikt Group has reported a resurgence of Predator spyware infrastructure, which was thought to be inactive due to sanctions and public exposure. The entity behind Predator, Intellexa, has reengineered its delivery system, enabling continued covert surveillance on high-profile targets world…
Summary: Recent international efforts have intensified to combat spyware and hack-for-hire services, revealing a complex web of entities involved in the spyware ecosystem. Despite sanctions against prominent vendors like NSO Group and Intellexa, many other spyware tools continue to thrive due to int…
Summary: Despite sanctions imposed by U.S. officials in March, the commercial spyware tool Predator has shown resilience, with evidence of increased usage and new customers in various countries. Researchers indicate that Predator operators have adapted their tactics to maintain operations and evade…
Intellexa’s Predator spyware infrastructure re-emerges after sanctions. Learn how this mercenary spyware is evolving, targeting high-profile individuals, and what defensive measures can be taken.
Summary: A new wave of sextortion emails has emerged, featuring personalized threats that include images of victims’ homes, aiming to increase the fear factor and compel payment. The emails falsely claim that the sender has recorded compromising footage and demands a Bitcoin ransom to prevent its re…
CYFIRMA analyzes a newly identified PowerShell-based keylogger that stealthily captures keystrokes and sensitive information from infected systems, leveraging cloud proxy and Onion/Tor-based C2 channels for anonymity. The report notes encoded command execution…
Summary: The article discusses the emergence of a new mobile banking malware strain named Rocinante, originating from Brazil, which targets local banking institutions through keylogging, phishing, and remote access capabilities. This malware represents a shift in the Latin American cybercriminal lan…
Summary: The BlackByte ransomware group has evolved its tactics, leveraging new vulnerabilities and enhancing its self-propagating capabilities while maintaining its core strategies. Recent investigations reveal a significant uptick in activity, with the group adapting quickly to incorporate newly d…
A novel phishing campaign targets mobile users via PWAs and WebAPKs to impersonate Czech banking apps and steal credentials, bypassing typical warnings. The activity involves two threat actor groups with Czech, Hungarian, and Georgian victims, and banks were n…
Summary: A pro-Russian hacker group named Vermin is exploiting Ukraine’s military operations to deploy malware, utilizing deceptive tactics involving images of alleged Russian war criminals. This campaign, reportedly backed by the Kremlin, employs tools like Spectr spyware and a new malware called F…
Summary: A dormant software vulnerability in Google’s Pixel devices, stemming from a pre-installed app called “Showcase.apk,” could allow malicious actors to execute code and install malware due to its excessive system privileges and unsecured configuration file retrieval. Although the app is not in…
Check Point Research uncovered Styx Stealer, a new malware variant derived from Phemedrone Stealer that can harvest browser data, messaging sessions, and cryptocurrency wallets, and is sold via styxcrypter[.]com. The investigation reveals an OpSec lapse by the…