Security News

Typhon info-stealing malware devs upgrade evasion capabilities
2023-04-05 20:30

The developers of the Typhon info-stealer announced on a dark web forum that they have updated the malware to a major version they advertise as 'Typhon Reborn V2'. They boast significant improvements designed to thwart analysis via anti-virtualization mechanisms. The original Typhon was discovered by malware analysts in August 2022.

Devs targeted by W4SP Stealer malware in malicious PyPi packages
2023-02-12 15:12

Five malicious packages were found on the Python Package Index, stealing passwords, Discord authentication cookies, and cryptocurrency wallets from unsuspecting developers. PyPI is a software repository for packages created in the Python programming language.

Microsoft urges devs to migrate away from .NET Core 3.1 ASAP
2022-11-17 14:14

NET Core versions until it reaches the end of support next month.NET Native releases, warned this July, Microsoft will stop providing technical support or servicing updates after EOS. "We recommend moving to.NET 6 as soon as possible. If you are still using.NET Core 3.1 after the end of support date, you'll need to update your app to.NET 6 or.NET 7 to remain supported and continue to receive.NET updates," Whittaker said.

Malware devs already bypassed Android 13's new security feature
2022-08-17 14:00

Roid malware developers are already adjusting their tactics to bypass a new 'Restricted setting' security feature introduced by Google in the newly released Android 13. Roid 13 was released this week, with the new operating system being rolled out to Google Pixel devices and the source code published on AOSP. As part of this release, Google attempted to cripple mobile malware that attempted to enable powerful Android permissions, such as AccessibilityService, to perform malicious, stealthy behavior in the background.

North Korean devs pose as US freelancers to aid DRPK govt hackers
2022-05-17 22:16

Thousands of North Korean "Highly skilled IT workers," at the direction of or forced by their government are targeting freelance jobs at organizations in wealthier nations. In some cases, DPRK's dispatched wage earners - typically located in China, Russia, Africa, and Southeast Asia, have aided with selling data stolen in attacks from North Korean hackers.

North Korean devs pose as US freelancers and aid DRPK govt hackers
2022-05-17 22:16

Thousands of North Korean "Highly skilled IT workers," at the direction of or forced by their government are targeting freelance jobs at organizations in wealthier nations. In some cases, DPRK's dispatched wage earners - typically located in China, Russia, Africa, and Southeast Asia, have aided with selling data stolen in attacks from North Korean hackers.

GitHub suspends accounts of Russian devs at sanctioned companies
2022-04-16 14:04

Russian software developers are reporting that their GitHub accounts are being suspended without warning if they work for or previously worked for companies under US sanctions. The GitHub accounts of Sberbank Technology, Sberbank AI Lab, and the Alfa Bank Laboratory had their code repositories initially disabled and are now removed from the platform.

TrickBot malware operation shuts down, devs move to stealthier malware
2022-02-25 23:51

The TrickBot malware operation has shut down after its core developers move to the Conti ransomware gang to focus development on the stealthy BazarBackdoor and Anchor malware families. TrickBot also has a long relationship with ransomware operations who partnered with the TrickBot group to receive initial access to networks infected by the malware.

TrickBot malware operation shuts down, devs move to BazarBackdoor
2022-02-25 23:51

The TrickBot malware operation has shut down after its core developers move to the Conti ransomware gang to focus development on the stealthy BazarBackdoor and Anchor malware families. TrickBot also has a long relationship with ransomware operations who partnered with the TrickBot group to receive initial access to networks infected by the malware.

Trojanized dnSpy app drops malware cocktail on researchers, devs
2022-01-08 19:35

Hackers targeted cybersecurity researchers and developers this week in a sophisticated malware campaign distributing a malicious version of the dnSpy. This new campaign was discovered by security researchers 0day enthusiast and MalwareHunterTeam who saw the malicious dnSpy project initially hosted at https://github[.