Sekoia.io reports that Predator spyware infrastructure remained active after the Predator Files disclosures, with new domains and command-and-control clusters created post-publication. The investigation links these clusters to Intellexa customers tracked as Ly…
Tag: SPYWARE
The Top 10 Malware in Q4 2023 changed slightly from the previous quarter. Here’s what the CIS Cyber Threat Intelligence team observed….
TikTok is rolling out in-app election centres across EU languages to curb misinformation and help users distinguish fact from fiction. The article also notes broader global misinformation trends and highlights ongoing cyber threats tied to misused cloud infras…
An in-depth look at a PyRation-family malware variant analyzed by StratosphereIPS, focusing on a Windows Python-based client–bot architecture and capabilities such as screen capture, keylogging, AV detection, anonymous browsing, and remote command execution. T…
Today’s attackers are taking advantage of changing business dynamics to target people everywhere they work. Staying current on the latest cybersecurity attack vectors and threats is an essential part of securing the enterprise against breaches and compromised data. https://www.proofpoint.com/us/thre…
CYFIRMA analyzes XSSLite, an infostealer released as part of the XSSWare malware development competition on a Russian forum, and its spread to other communities. The report highlights capabilities, defense-evasion techniques, and how underground competitions a…
Cyble researchers track a Go-based JKwerlo Ransomware campaign targeting French and Spanish speakers, delivered via language-specific HTML files that embed zip archives. The operation relies heavily on PowerShell for its execution flow, with multi-stage payloa…
A 2023 Glupteba campaign includes an unreported feature — a UEFI bootkit. We analyze its complex architecture and how this botnet has evolved.
The post Diving Into Glupteba's UEFI Bootkit appeared first on Unit 42….
The Avast Q4/2023 Threat Report chronicles a record year of attacks, highlighted by the revival of Qakbot, a surge in PDF-based social engineering, and expanding menace across adware, information stealers, ransomware, and mobile threats. It also covers notable…
Rapid7 analyzes Black Hunt ransomware, a variant reportedly built from leaked LockBit code with similarities to REvil in its techniques, which has impacted hundreds of Paraguayan companies. The post details its anti-analysis checks, privilege escalation, langu…
Researchers traced a fake WhatsApp phishing operation aimed at iPhone users, linked to an Italian surveillance company. The attack uses iPhone configuration profiles via a phishing site to push spyware and potentially exfiltrate device data. #WhatsApp #Cy4Gate…
If you have anything to do with cyber security, you know it employs its own unique and ever-evolving language. Jargon and acronyms are the enemies of clear writing—and are beloved by cyber security experts. So Morphisec has created a comprehensive cyber security glossary that explains commonly…
This analysis details a multi-stage infection dubbed “CrackedCantil” that uses cracked-software lures and PrivateLoader to deploy a suite of loaders, stealers, miners, proxy bots, and STOP ransomware. The report traces infection artifacts, C2 communications, p…
Arctic Wolf Labs uncovered CherryLoader, a Go-based loader masquerading as CherryTree used in intrusions to swap exploits without recompiling. It decrypts payloads, drops privilege-escalation tools (PrintSpoofer and JuicyPotatoNG), and relies on process ghosti…
Cybercriminals are increasingly leveraging Traffic Distribution Systems (TDS) to facilitate their operations, allowing them to efficiently route victims to malicious content. This systematic research uncovers the complex web of affiliations among various actor…