This campaign used malicious email attachments and known Office/Windows CVEs to deliver Taskun as a dropper and Agent Tesla as an information-stealing payload, enabling credential theft, screen capture, and C2 communications. Defenders are advised to apply tar…
Tag: SPYWARE
Additionally, the tech giant reports that it identified and blocked 333,000 Google Play accounts that uploaded malware, fraudulent apps, or engaged in repeated grave policy violations….
Summary: The US State Department is imposing visa restrictions on individuals involved in the development and sale of commercial spyware, targeting those who have targeted journalists, academics, human rights defenders, dissidents, and US government personnel. Threat Actor: Commercial spyware develo…
A financially motivated group named GhostR claims the theft of a sensitive database from World-Check and threatens to publish it. World-Check is a global database utilized by various organizations, including financial institutions, regulatory bodies, and law enforcement agencies, for assessing potential risks associated with individuals and entities. It compiles information from…
Explore the escalating threat of ‘Mobile NotPetya’—a zero-click, wormable mobile malware. Learn about the surge in vulnerabilities and the critical need for robust defense.
Zscaler observed a malvertising campaign that used typosquatting domains and Google Ads to distribute a multi-stage backdoor named MadMxShell, targeting IT security and network administration professionals. The payload uses DLL sideloading, process hollowing, …
We review the new mobile Trojan banker SoumniBot, which exploits bugs in the Android manifest parser to dodge analysis and detection.
LightSpy, an advanced iOS espionage implant, has reappeared in a renewed campaign targeting Southern Asia (likely India) using a modular framework called F_Warehouse to deliver plugins that steal files, record audio, harvest credentials, and execute shell comm…
Netskope Threat Labs analyzed a Python-based ransomware family called Evil Ant that uses PyInstaller and the Fernet library to encrypt files in user folders and the root of external drives while keeping the Fernet key only in memory (though a hardcoded decrypt…
Summary: A new campaign conducted by the TA558 hacking group is using steganography to hide malicious code inside images and deliver various malware tools onto targeted systems. Threat Actor: TA558 | TA558 Victim: Various sectors and countries | SteganoAmor campaign Key Point : The TA558 hacking gro…
Summary: Cybersecurity researchers have discovered a renewed cyber espionage campaign targeting users in South Asia with the aim of delivering an Apple iOS spyware implant called LightSpy. Threat Actor: LightSpy | LightSpy Victim: Users in South Asia | South Asia Key Point : The LightSpy iOS spyware…
Summary: Apple has updated its warning system to alert users when they may have been individually targeted by mercenary spyware threats, such as the surveillance tools developed by NSO Group. Threat Actor: NSO Group | NSO Group Victim: Individuals targeted by mercenary spyware attacks Key Point : Ap…
Cisco Talos is disclosing a new threat actor we deemed “Starry Addax” targeting mostly human rights activists, associated with the Sahrawi Arab Democratic Republic (SADR) cause with a novel mobile malware….
Check Point Research detailed Agent Tesla campaigns that used phishing via Plesk/RoundCube webmail servers and RDP/SSH-accessed infrastructure to deliver Cassandra‑protected .NET Agent Tesla samples inside ISO/.img attachments targeting US and Australian organ…
Threat Actor: Black Shadow (originated from Iran), Russian hacker Victim: Atraf (Israeli LGBTQ dating app) users Information: – Atraf, a popular Israeli LGBTQ dating app, has suffered a major data breach – The data breach exposed personal information of over half a million users – The group responsi…