Category: Malware

Google Docs interface showing a fake decryption panel used for malware distribution 0

Malicious Google Docs Weaponized as Interactive Installers

Adversaries have ingeniously manipulated Google Docs to perform a function utterly unexpected from a cloud-based word processor: they transformed a standard document into an interactive malware installation vector. Following the conclusion of the prestigious...

Red Heron exploiting Gitea N-day flaw to deploy Linux rootkit 0

Red Heron Weaponizes Gitea Flaw for Source Code Theft

In a matter of mere days, a publicly disclosed exploit targeting Gitea rapidly metamorphosed into an industrialized instrument for source code theft. The Red Heron threat group ruthlessly automated the discovery of vulnerable servers,...

Sogou Input Method backdoor attack flow and GRAYRABBIT deployment 0

Sogou Input Method Exploited in Espionage Campaign

A seemingly innocuous link transformed a popular Chinese character input application into a vulnerable gateway for espionage. The security firm Gen exposed a sophisticated exploit chain utilized by the UNC3569 threat group to infect...

Mantax Otax Android ransomware spyware encrypting files and spying through camera and screen capture 0

Mantax Otax Fuses Android Ransomware With Spyware

Android ransomware is no longer confined to locking files: Mantax Otax transforms an infected smartphone into a spying instrument and a channel of pressure on its owner at once. Zimperium has described the malware,...

Ted Backdoor HAProxy malware and CurlRAT cyberattack structure 0

Suspected North Korean Hackers Deploy Ted Backdoor

Suspected North Korean hackers may have spied on South Korean organizations for years using trojanized Linux system services and an HAProxy backdoor. Rapid7 researchers discovered a previously unknown set of malicious tools. These tools...

REVSTEALER malware components architecture and infostealer infection process 0

The Hidden Perils of REVSTEALER Infections

Eradicating a data stealer from a computer does not mean the system is safe. The cybersecurity firm Elastic has outlined four previously unknown components linked to the REVSTEALER credential harvesting infostealer. Unlike the primary...

Pegasus spyware in Serbia forensic report detailing Pegasus spyware infections 0

Pegasus Spyware in Serbia Targets Student Activist

TL;DR Researchers at the Citizen Lab and the SHARE Foundation confirmed a mercenary spyware attack in Serbia. A zero-click exploit delivered Pegasus spyware to an iPhone belonging to a pro-democracy student activist. Meanwhile, independent...

A conceptual illustration of a hacker exploiting Microsoft Teams to gain unauthorized remote access to a corporate network. 0

Teams Phishing Targets Enterprise Access

An unexpected request originating from corporate technical support frequently appears entirely innocuous. This perception persists until an employee unwittingly surrenders computer control directly to an unknown individual. Microsoft recently exposed a highly active campaign...