JokerSpy is a multi-stage macOS spyware campaign described by BitDefender and Elastic, featuring a trojanized QR code generator (QRLog), cross-platform backdoors (shared.dat and sh.py), and a macOS stager (xcc). The actors show a likely financially motivated e…
Tag: SPYWARE
During routine detection maintenance, our Mac researchers stumbled upon a small
set of files with backdoor capabilities that seem to form part of a more complex
malware toolkit. The following analysis is incomplete, as we are trying to
identify the puzzle pieces that are still missing.
As of now, these samples are still largely undetected and very little
information is available about any of them. The earliest mention we could find
is an anonymous April 18 upload on VirusTotal (IoC A), as well
RedLine Stealer is a credential-stealing malware distributed via phishing URLs, malicious Chrome extensions, and loader chains, with campaigns impacting healthcare and manufacturing sectors. Splunk’s Threat Research Team analyzes a RedLine Loader, its defense …
A Brazilian threat actor is targeting users of over 30 Portuguese financial institutions with custom backdoors.
A malvertising campaign redirects Windows users to a convincing fake system update, delivering a loader that bypasses many AVs and sandboxes to drop Aurora Stealer. The operation uses a “Invalid Printer” loader, patches it to defeat sandbox checks, and exfiltr…
Authored by By Yashvi Shah McAfee Labs have identified an increase in Wextract.exe samples, that drop a malware payload at…
The post Deconstructing Amadey’s Latest Multi-Stage Attack and Malware Distribution appeared first on McAfee Blog….
The article explains how threat actors use fake applications impersonating trusted brands (notably IRCTC) to deceive users into downloading spyware, with social engineering and phishing as core tactics. It analyzes an IRCTC advisory, details the spyware’s capa…
Lookout researchers uncovered BouldSpy, an Android surveillance tool attributed with moderate confidence to Iran’s Law Enforcement Command (FARAJA) that has been used to target minorities and collect extensive device data. The spyware installs via physical acc…
PaperCut CVE-2023-27350 and CVE-2023-27351 allow remote code execution and authentication bypass on PaperCut MF/NG servers, with unpatched systems actively exploited in the wild. The article highlights PoC dispersion via hacktivist channels and rising ransomwa…
ASEC reports BlackBit ransomware being distributed in Korea, masquerading as svchost.exe and active since September of last year. It obfuscates with .NET Reactor and shows traits similar to LokiLocker; the campaign includes persistence, recovery prevention, an…
The article analyzes the March 2023 NullMixer malware operation, highlighting how opportunistic attackers used malvertising and cracked software to infect thousands of endpoints across Europe, including Italy and France. It also details a MaaS/PPI ecosystem de…
MacOS threat actors are increasingly focusing on data theft rather than ransom, exfiltrating session cookies, keychains, SSH keys, and other sensitive data to monetize or enable espionage. The article outlines where these data assets reside, how attackers acce…
Trigona is a newly observed ransomware strain that security researchers first noted in Oct 2022 and was highly active in Dec 2022 with at least 15 victims across multiple industries. The operation uses HTML Application ransom notes with embedded JavaScript con…
Threat actors are weaponizing ChatGPT’s popularity to spread malware and phishing campaigns across Windows and Android, using fraudulent pages and typosquatted domains to lure victims into downloading malicious payloads. The campaigns distribute stealer malwar…
HardBit 2.0 is a ransomware variant observed from late 2022 that encrypts data after stealing sensitive information, negotiating ransom rather than paying a fixed bitcoin amount. It combines data theft, encryption, and multiple defense-evading and persistence …