Multi-Malware ‘Cluster Bomb’ Campaign Drops Widespread Cyber Havoc

July 1, 2024 at 06:00PM “Unfurling Hemlock,” a financially motivated Eastern European threat actor, is using a cluster bomb cyber tactic to distribute up to 10 unique malware files at a time on systems in the US, Germany, Russia, and other countries. The attacker distributes malware through nested compressed Microsoft Cabinet (CAB) files and has … Read more

Raspberry Robin devs are buying exploits for faster attacks

February 8, 2024 at 12:20PM Researchers suspect that the criminals behind the Raspberry Robin malware are now purchasing exploits to facilitate faster cyberattacks, prioritizing the speed of development to maximize their chances of successful attacks. The malware is known for its regular updates and has been recognized as a significant player in the world of … Read more

DarkGate and Pikabot malware emerge as Qakbot’s successors

November 21, 2023 at 10:56AM A sophisticated phishing campaign using DarkGate and PikaBot malware is posing a significant threat to organizations. The campaign began after the takedown of the Qakbot operation and is considered one of the most advanced since then. The attackers employ tactics similar to the previous Qakbot campaigns, indicating a shift to … Read more

Discord still a hotbed of malware activity — Now APTs join the fun

October 16, 2023 at 05:37PM Discord is increasingly being used by hackers and advanced persistent threat (APT) groups to distribute malware, steal data, and target critical infrastructure. Trellix’s report highlights how Discord’s content delivery network (CDN) is utilized for delivering malicious payloads, while webhooks are abused for data theft. The report also notes that APT … Read more