Security News

Hackers Use Microsoft MSC Files to Deploy Obfuscated Backdoor in Pakistan Attacks
2024-12-17 14:11

A new phishing campaign has been observed employing tax-themed lures to deliver a stealthy backdoor payload as part of attacks targeting Pakistan. Cybersecurity company Securonix, which is...

Winnti hackers target other threat actors with new Glutton PHP backdoor
2024-12-15 15:19

​The Chinese Winnti hacking group is using a new PHP backdoor named 'Glutton' in attacks on organizations in China and the U.S., and also in attacks on other cybercriminals. [...]

Thai Officials Targeted in Yokai Backdoor Campaign Using DLL Side-Loading Techniques
2024-12-14 10:16

Thai government officials have emerged as the target of a new campaign that leverages a technique called DLL side-loading to deliver a previously undocumented backdoor dubbed Yokai. "The target of...

Secret Blizzard Deploys Kazuar Backdoor in Ukraine Using Amadey Malware-as-a-Service
2024-12-11 18:02

The Russian nation-state actor tracked as Secret Blizzard has been observed leveraging malware associated with other threat actors to deploy a known backdoor called Kazuar on target devices...

More_eggs MaaS Expands Operations with RevC2 Backdoor and Venom Loader
2024-12-06 08:22

The threat actors behind the More_eggs malware have been linked to two new malware families, indicating an expansion of its malware-as-a-service (MaaS) operation. This includes a novel...

Hackers Target Uyghurs and Tibetans with MOONSHINE Exploit and DarkNimbus Backdoor
2024-12-05 12:43

A previously undocumented threat activity cluster dubbed Earth Minotaur is leveraging the MOONSHINE exploit kit and an unreported Android-cum-Windows backdoor called DarkNimbus to facilitate...

ANEL and NOOPDOOR Backdoors Weaponized in New MirrorFace Campaign Against Japan
2024-12-05 07:30

The China-linked threat actor known as MirrorFace has been attributed to a new spear-phishing campaign mainly targeting individuals and organizations in Japan since June 2024. The aim of the...

Researchers Uncover Backdoor in Solana's Popular Web3.js npm Library
2024-12-04 09:48

Cybersecurity researchers are alerting to a software supply chain attack targeting the popular @solana/web3.js npm library that involved pushing two malicious versions capable of harvesting users'...

Hackers exploit ProjectSend flaw to backdoor exposed servers
2024-11-27 21:00

Threat actors are using public exploits for a critical authentication bypass flaw in ProjectSend to upload webshells and gain remote access to servers. [...]

RomCom hackers chained Firefox and Windows zero-days to deliver backdoor
2024-11-26 10:00

Russia-aligned APT group RomCom was behind attacks that leveraged CVE-2024-9680, a remote code execution flaw in Firefox, and CVE-2024-49039, an elevation of privilege vulnerability in Windows...