Trend Micro telemetry links Vice Society to manufacturing attacks and notes the group has evolved from using known ransomware variants to developing a custom ransomware builder, potentially hinting at a ransomware-as-a-service model. The group continues to emp…
Tag: SPYWARE
Hive ransomware operates as a ransomware-as-a-service (RaaS) that has victimized thousands across sectors like Healthcare and Public Health, encrypting data and threatening leaks. The advisory inventories Hive’s TTPs, IOCs, and mitigations, including initial a…
Cyble researchers uncovered a phishing campaign targeting Bank Rakyat Indonesia (BRI) that escalates by distributing Android SMS stealers to harvest OTPs and bypass 2FA. The operation begins with credential- and OTP-phishing sites, then installs a custom SMS s…
SentinelLabs provides a comprehensive analysis of Black Basta’s operational TTPs, revealing custom tools, EDR-evasion capabilities, and a likely link to FIN7. The findings suggest FIN7 developers may have contributed to Black Basta’s toolset, with privilege es…
Palo Alto Networks describes a proactive detector that spots potentially malicious newly observed domains (NODs) by ingesting WHOIS data, DNS traffic, and passive DNS signals, enabling earlier detection of abuse as domains become active. The system analyzes mi…
Cyble Research & Intelligence Labs (CRIL) uncovered a mass tech support scam ecosystem that uses phishing sites impersonating Microsoft and Apple support to push fake Windows Defender alerts. Victims who contact the fake helplines are then compromised via remo…
The article documents BazarCall’s evolution from email bait to phone-based social engineering that prompts victims to download malware, including BazaarLoader and other families such as Trickbot, Gozi IFSB, and IcedID. It outlines a three-phase attack (bait, a…
OnionPoison spreads a malicious Tor Browser installer via a popular Chinese YouTube channel, luring targets to download a compromised, less-private Tor variant. The malware collects sensitive data, can run shell commands, and communicates with a C2 using encry…
New findings by R3D, with technical support from the Citizen Lab, document Pegasus infections of Mexican journalists and a human rights defender between 2019 and 2021, including an infection of opposition politician Agustín Basave Alanís in 2021. The report sh…
Fortinet FortiGuard Labs analyzed malicious Microsoft Office documents that abused legitimate sites MediaFire and Blogger to deliver two malware variants: Agent Tesla and njRat (Bladabindi). The operation uses a multi-stage chain—VBA macros, mshta, and PowerSh…
NullMixer acts as a dropper delivering a wide range of malware families by redirecting users from cracked software sites through SEO-driven pages. It drops numerous trojans and stealers, including SmokeLoader, RedLine Stealer, PseudoManuscrypt, ColdStealer, an…
Avast Threat Labs details Bobik, a .NET Remote Access Trojan that now functions as a DDoS module within a botnet used by the pro-Russian group NoName057(16) to target Ukraine and nearby countries. The report maps the botnet’s C2 infrastructure, the multi-stage…
A phishing campaign spreading the AgentTesla information stealer targets businesses worldwide by sending spoofed emails with malicious disk images (.IMG/.ISO) named “Draft Contract”; the attack harvests browser and email credentials and other system data. A Po…
Morphisec Labs details DoNot Team (APT-C-35) updates to their Windows framework (YTY/Jaca), including new modules, a shellcode loader, and an upgraded browser stealer, with a focus on modular delivery and evasion techniques. The post also highlights infection …
Avast Threat Labs uncovered a targeted zero-day in Google Chrome (CVE-2022-2294) used in the wild to attack Avast users in the Middle East, including Lebanese journalists. The campaign combined watering hole attacks, a Chrome WebRTC exploit chain, and a BYOVD …