Volexity documents a multi-year campaign by the state-aligned threat actor EvilBamboo that uses repackaged mobile apps, fake sites, Telegram communities, and browser profiling to deliver Android and iOS spyware. The actor operates at least three Android famili…
Tag: SPYWARE
Lookout researchers analyzed BadBazaar, a mobile surveillanceware family attributed to APT15, describing an Android variant with broad data‑collection features and an iOS variant (masqueraded as TibetOne) with more limited but still privacy‑invasive capabiliti…
Spyware Telegram mod in Uighur and Chinese spreads through Google Play stealing messages and other user data.
Q2 2023 overview: targeted attacks such as Operation Triangulation, CloudWizard and Lazarus activity, Nokoyawa ransomware, and others.
The article discusses SapphireStealer, an open-source information stealer that’s been gaining traction in public malware repositories and underground forums, and how attackers are leveraging open-source tooling to customize and evade detection. It also notes d…
Cyfirma analyzes a persistent Remcos RAT campaign driven by a broad infrastructure of malicious IPs and multi-stage payloads, delivering and controlling Remcos across compromised hosts. The report details how the attackers use PowerShell-enabled scripts, regis…
This report analyzes a multi-stage implant operation targeting industrial organizations in Eastern Europe, focusing on persistent access, data gathering (including from air-gapped systems), and data exfiltration via cloud services. It details a three-layer imp…
Cleafy Labs reports that SpyNote spyware has been repurposed to perform aggressive banking fraud campaigns across Europe by abusing Android Accessibility services, media projection APIs, and built-in remote access workflows. The malware collects keystrokes, SM…
Halcyon researchers expose Command-and-Control Providers (C2Ps) as a key pillar of the ransomware economy, offering services to attackers while presenting themselves as legitimate businesses. The report links Cloudzy as a common service provider used by actors…
Doctor Web uncovered a Windows-focused campaign using Trojan.Fruity.1, a modular downloader that can deploy Remcos RAT or other malware. The attack employs fake installers, multi-stage infection, steganography, and anti-detection tricks to increase success. #T…
Authored by Yukihiro Okutomi McAfee’s Mobile team observed a smishing campaign against Japanese Android users posing as a power and…
The post Android SpyNote attacks electric and water public utility users in Japan appeared first on McAfee Blog….
Lookout attributes two modular Android surveillanceware families, WyrmSpy and DragonEgg, to Chinese APT41 based on shared signing certificates and overlapping C2 infrastructure linking to Chengdu 404. Both implants request broad device permissions, download se…
ThreatFabric documents Letscall, a multi-stage vishing toolkit that blends phishing, spyware, and VOIP manipulation to hijack calls and exfiltrate data from victims in South Korea, with potential expansion to the EU. The campaign uses a downloader, a second-st…
A Trend Micro analysis uncovers a new signed rootkit loader cluster that acts as a universal kernel-driver loader, enabling second-stage unsigned modules to be loaded in the target system. The activity is linked to a China-based actor (associated with FiveSys)…
Neo_Net runs a global eCrime campaign targeting thousands of bank clients, focusing on Spanish and Chilean banks, from June 2021 to April 2023. The operation includes Ankarex Smishing-as-a-Service, phishing panels, and Android trojans to exfiltrate data via Te…