Pro-Hamas Hacktivists Targeting Israeli Entities with Wiper Malware

October 30, 2023 at 01:10PM A pro-Hamas hacktivist group has developed a new Linux-based wiper malware called BiBi-Linux Wiper. The malware targets Israeli entities during the ongoing Israeli-Hamas war. BiBi-Linux Wiper is destructive and can potentially destroy an entire operating system if run with root permissions. It overwrites files and renames them with the string … Read more

Hackers Using MSIX App Packages to Infect Windows PCs with GHOSTPULSE Maware

October 30, 2023 at 12:42AM A cyber attack campaign has been using MSIX Windows app package files to distribute a new malware loader named GHOSTPULSE. The attack targets popular software like Google Chrome, Microsoft Edge, Brave, Grammarly, and Cisco Webex. Potential victims are enticed to download the packages through compromised websites, SEO poisoning, or malvertising. … Read more

N. Korean Lazarus Group Targets Software Vendor Using Known Flaws

October 27, 2023 at 11:43AM The Lazarus Group, a North Korea-linked threat actor, has launched a new cyber attack campaign targeting a software vendor through known security flaws in another software. The attack involved the deployment of malware families such as SIGNBT and LPEClient. The Lazarus Group has demonstrated advanced evasion techniques and targeted other … Read more

Advanced ‘StripedFly’ Malware With 1 Million Infections Shows Similarities to NSA-Linked Tools

October 27, 2023 at 10:43AM Cybersecurity firm Kaspersky has warned about a highly advanced piece of malware named StripedFly that has been infecting over one million devices for the past five years. The threat is designed as a modular framework and can target both Windows and Linux systems. It utilizes a Tor network tunnel for … Read more

Complex Spy Platform StripedFly Bites 1M Victims

October 26, 2023 at 09:31AM Researchers at Kaspersky have discovered that a malware called StripedFly, initially thought to be a basic cryptominer, is actually a sophisticated spy platform infecting over 1 million victims. The malware allows attackers to gain control over networks, exfiltrate data, and mine cryptocurrency. It includes a Tor network tunnel and uses … Read more

Iranian Group Tortoiseshell Launches New Wave of IMAPLoader Malware Attacks

October 26, 2023 at 04:48AM The Iranian threat actor Tortoiseshell is responsible for a new series of watering hole attacks. They use a malware called IMAPLoader, which acts as a downloader for additional payloads. The attacks target various sectors, including maritime, shipping, logistics, and nuclear industries. Tortoiseshell has a history of strategic website compromises and … Read more

YoroTrooper: Researchers Warn of Kazakhstan’s Stealthy Cyber Espionage Group

October 26, 2023 at 04:48AM A new threat actor called YoroTrooper, likely consisting of operators from Kazakhstan, has been identified. The group employs various tactics to hide their activities, including targeting Kazakhstani entities and using VPN exit nodes in Azerbaijan. YoroTrooper primarily uses spear-phishing and malware to steal data, and has now shifted to custom … Read more

Meet Rhysida, a New Ransomware Strain That Deletes Itself

October 24, 2023 at 04:26PM The emerging ransomware strain called Rhysida, operating since May, is targeting users of Brazil’s PIX payment system. Rhysida, which functions as a ransomware-as-a-service (RaaS), has a unique self-deletion mechanism and is compatible with pre-Windows 10 versions of Microsoft. It faced initial configuration challenges but quickly adapted. Alongside Rhysida, there is … Read more

DoNot Team’s New Firebird Backdoor Hits Pakistan and Afghanistan

October 23, 2023 at 02:09PM DoNot Team, a threat actor suspected to be of Indian origin, has been using a new .NET-based backdoor called Firebird to target victims in Pakistan and Afghanistan. The attack also involves a downloader named CSVtyrei. Kaspersky discovered the attack and noted ongoing development efforts. Transparent Tribe, another hacking group, has … Read more

Number of hacked Cisco IOS XE devices plummets from 50K to hundreds

October 22, 2023 at 01:42PM The number of Cisco IOS XE devices hacked with a malicious backdoor implant has dramatically decreased from over 50,000 to only a few hundred. It is unclear why this decline has occurred, with researchers speculating that the threat actors may have deployed an update to hide their presence or a … Read more