Chinese Cyberspies Use New Malware in Ivanti VPN Attacks

February 28, 2024 at 07:45AM Mandiant reports that Chinese threat actors have exploited recent Ivanti Connect Secure VPN vulnerabilities, deploying new malware for persistence. Despite patches, attackers continued exploiting a vulnerability, deploying new malware families and demonstrating a nuanced understanding of the appliance to persistently execute backdoors. The threat actor, UNC5325, has been observed exploiting … Read more

New Rust-based SysJoker backdoor linked to Hamas hackers

November 27, 2023 at 09:57AM Recently, a new variant of the multi-platform malware called ‘SysJoker’ has been discovered. It has undergone a complete code rewrite in the Rust programming language. This malware, initially documented in early 2022, operates on Windows, Linux, and macOS systems. The new variant has been linked to ‘Operation Electric Powder,’ believed … Read more