Security News > 2022 > February

Social Media Hijacking Malware Spreading Through Gaming Apps on Microsoft Store
2022-02-26 02:19

A new malware capable of controlling social media accounts is being distributed through Microsoft's official app store in the form of trojanized gaming apps, infecting more than 5,000 Windows machines in Sweden, Bulgaria, Russia, Bermuda, and Spain. Israeli cybersecurity company Check Point dubbed the malware "Electron Bot," in reference to a command-and-control domain used in recent campaigns.

Data stolen from Nvidia, blueprints leak threatened
2022-02-26 00:39

The crooks said unless Nvidia releases a software update that removes its recent crypto-coin mining limiter, they will leak what sounds like internal hardware documents - a hw folder, specifically. NCC Group released figures indicating a huge jump in the use of ransomware, with America the top target at 53 per cent of monitored infections, and Europe at 30 per cent.

Nvidia probes cyberattack on internal systems
2022-02-26 00:39

NCC Group released figures indicating a huge jump in the use of ransomware, with America the top target at 53 per cent of monitored infections, and Europe at 30 per cent. The top targets remain government organizations and the industrial sector, which account for around 20 per cent each of the total.

TrickBot malware operation shuts down, devs move to stealthier malware
2022-02-25 23:51

The TrickBot malware operation has shut down after its core developers move to the Conti ransomware gang to focus development on the stealthy BazarBackdoor and Anchor malware families. TrickBot also has a long relationship with ransomware operations who partnered with the TrickBot group to receive initial access to networks infected by the malware.

TrickBot malware operation shuts down, devs move to BazarBackdoor
2022-02-25 23:51

The TrickBot malware operation has shut down after its core developers move to the Conti ransomware gang to focus development on the stealthy BazarBackdoor and Anchor malware families. TrickBot also has a long relationship with ransomware operations who partnered with the TrickBot group to receive initial access to networks infected by the malware.

Iran's MuddyWater Hacker Group Using New Malware in Worldwide Cyber Attacks
2022-02-25 23:01

Cybersecurity agencies from the U.K. and the U.S. have laid bare a new malware used by the Iranian government-sponsored advanced persistent threat group in attacks targeting government and commercial networks worldwide. "MuddyWater actors are positioned both to provide stolen data and accesses to the Iranian government and to share these with other malicious cyber actors," the agencies said.

Friday Squid Blogging: Squid Videos
2022-02-25 22:00

Here are six beautiful squid videos. I know nothing more about them. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Read my blog...

TrickBot Takes a Break, Leaving Researchers Scratching Their Heads
2022-02-25 21:32

The group behind the TrickBot malware is back after an unusually long lull between campaigns, according to researchers - but it's now operating with diminished activity. A report from Intel 471 published on Thursday flagged a "Strange" period of relative inactivity, where "From December 28, 2021 until February 17, 2022, Intel 471 researchers have not seen new TrickBot campaigns."

GPU giant Nvidia is investigating a potential cyberattack
2022-02-25 20:51

US chipmaker giant Nvidia confirmed today it's currently investigating an "Incident" that reportedly took down some of its systems for two days.Systems impacted in what looks like a cyberattack include the company's developer tools and email systems, as first reported by The Telegraph.

Ransomware gangs, hackers pick sides over Russia invading Ukraine
2022-02-25 20:13

Hacker crews are picking sides as the Russian invasion into Ukraine continues, issuing bans and threats for supporters of the opposite side. Earlier today, the Conti ransomware group stated their "Full support of Russian government" and threatened with cyberattacks against anyone launching attacks against Russia.