River of Phish is a sophisticated spear phishing campaign attributed to COLDRIVER (FSB) targeting civil society figures and NGOs across Russia, the West, and worldwide with personalized social engineering and encrypted-PDF lures. A second actor, COLDWASTREL, a…
Tag: SPYWARE
Summary: The United Kingdom and France are set to initiate a consultation aimed at addressing the proliferation and misuse of commercial cyber intrusion tools, as part of the Pall Mall Process. This initiative seeks to establish good practices and standards for the use of such tools, involving vario…
APT groups targeting Russian government agencies and IT firms are deploying increasingly sophisticated malware campaigns, signaling elevated cyber-espionage tensions. Notable operations include EastWind, CloudSorcerer, GrewApacha, and CMoon, which employ data …
This HYAS Threat Intelligence report analyzes the prevalence of Dynamic DNS (DDNS) in cyberattacks, especially its use with the DarkComet RAT for C2 infrastructure. It notes how DDNS eases attacker control over compromised devices and highlights DarkComet’s de…
Previously unknown spyware LianSpy targets Android devices by exploiting root privileges to steal data and leveraging Yandex Disk cloud service as C2.
Summary: This report highlights a recent case of brand impersonation involving Google ads, where users searching for Google Authenticator were misled into downloading malware. The attack exploited a fake advertisement to redirect victims to a fraudulent website that hosted malicious software. Threat…
Summary: Security researchers have identified a new version of Mandrake, a sophisticated Android cyber-espionage malware that evaded detection for years while hidden in Google Play applications. The updated malware features advanced obfuscation techniques and a multi-stage infection chain, making it…
Only trust official sources they say, but what happens when a Google vetted ad is for a Google product?…
Mandrake spyware threat actors resume attacks with new functionality targeting Android devices while being publicly available on Google Play.
Hamster Kombat’s rising popularity has drawn cybercriminals targeting Android and Windows users with Android spyware (Ratel), fake app stores, and Lumma Stealer cryptors on Windows. The report covers threat details, MITRE mappings, and IoCs, warning that the g…
Summary: The content discusses the new version of the HardBit ransomware, which includes binary obfuscation enhancement with passphrase protection, making it more difficult for security researchers to analyze. Threat Actor: HardBit ransomware | HardBit ransomware Victim: N/A Key Point : The new vers…
Discover how OilAlpha’s malicious applications are targeting humanitarian aid groups in Yemen. Learn about their tactics and how to mitigate risks.
Cybereason Security Services issue Threat Analysis reports to inform on impacting threats. The Threat Analysis reports investigate these threats and provide practical recommendations for protecting against them….
GuardZoo is a surveillanceware targeting military personnel in Middle Eastern countries, attributed to a Yemeni Houthi-aligned group. The malware, based on Dendroid RAT, utilizes military themes for luring victims and continues to be an active threat as of 202…
Summary: The report warns of a resurgence of CapraRAT spyware targeting mobile gamers and weapons enthusiasts through malicious Android applications. Threat Actor: Transparent Tribe, also known as APT36 | Transparent Tribe Victim: Mobile gamers and weapons enthusiasts | Mobile gamers and weapons ent…