Category: Malware

A conceptual diagram of Group Policy Objects being weaponized 0

PAYLOAD Extortion Skips Encryption, Exploits GPO

The PAYLOAD extortion operators recently targeted a Middle Eastern manufacturing enterprise without executing a single encryptor payload on any Windows machine. After successfully acquiring domain administrator privileges, the malicious actors weaponized Active Directory Group...

MovieReaper malware spreading through compromised movie torrents using the Solana blockchain for C2 0

MovieReaper Malware Spreads Through Movie Torrents

An attempt to download a film through a familiar torrent tracker could infect a computer even without the tracker itself being hacked. Attackers compromised iTorrents.org, a popular repository of torrent files, and made the...

Google Docs interface showing a fake decryption panel used for malware distribution 0

Malicious Google Docs Weaponized as Interactive Installers

Adversaries have ingeniously manipulated Google Docs to perform a function utterly unexpected from a cloud-based word processor: they transformed a standard document into an interactive malware installation vector. Following the conclusion of the prestigious...

Red Heron exploiting Gitea N-day flaw to deploy Linux rootkit 0

Red Heron Weaponizes Gitea Flaw for Source Code Theft

In a matter of mere days, a publicly disclosed exploit targeting Gitea rapidly metamorphosed into an industrialized instrument for source code theft. The Red Heron threat group ruthlessly automated the discovery of vulnerable servers,...

Sogou Input Method backdoor attack flow and GRAYRABBIT deployment 0

Sogou Input Method Exploited in Espionage Campaign

A seemingly innocuous link transformed a popular Chinese character input application into a vulnerable gateway for espionage. The security firm Gen exposed a sophisticated exploit chain utilized by the UNC3569 threat group to infect...

Mantax Otax Android ransomware spyware encrypting files and spying through camera and screen capture 0

Mantax Otax Fuses Android Ransomware With Spyware

Android ransomware is no longer confined to locking files: Mantax Otax transforms an infected smartphone into a spying instrument and a channel of pressure on its owner at once. Zimperium has described the malware,...

Ted Backdoor HAProxy malware and CurlRAT cyberattack structure 0

Suspected North Korean Hackers Deploy Ted Backdoor

Suspected North Korean hackers may have spied on South Korean organizations for years using trojanized Linux system services and an HAProxy backdoor. Rapid7 researchers discovered a previously unknown set of malicious tools. These tools...

REVSTEALER malware components architecture and infostealer infection process 0

The Hidden Perils of REVSTEALER Infections

Eradicating a data stealer from a computer does not mean the system is safe. The cybersecurity firm Elastic has outlined four previously unknown components linked to the REVSTEALER credential harvesting infostealer. Unlike the primary...