Security News

Iranian Hackers Strike Diamond Industry with Data-Wiping Malware in Supply-Chain Attack
2022-12-08 07:56

An Iranian advanced persistent threat actor known as Agrius has been attributed as behind a set of data wiper attacks aimed at diamond industries in South Africa, Israel, and Hong Kong. The wiper, codenamed Fantasy by ESET, is believed to have been delivered via a supply chain attack targeting an Israeli software suite developer as part of a campaign that began in February 2022.

New Zerobot malware has 21 exploits for BIG-IP, Zyxel, D-Link devices
2022-12-07 19:19

A new Go-based malware named 'Zerobot' has been spotted in mid-November using exploits for almost two dozen vulnerabilities in a variety of devices that include F5 BIG-IP, Zyxel firewalls, Totolink and D-Link routers, and Hikvision cameras. The purpose of the malware is to add compromised devices to a distributed denial-of-service botnet to launch powerful attacks against specified targets.

ChatGPT shows promise of using AI to write malware
2022-12-06 16:41

For even the most skilled hackers, it can take at least an hour to write a script to exploit a software vulnerability and infiltrate their target. Soon, a machine may be able to do it in mere seconds.When OpenAI last week released its ChatGPT tool, allowing users to interact with an artificial intelligence chatbot, computer security researcher Brendan Dolan-Gavitt wondered whether he could instruct it to write malicious code. So, he asked the model to solve a simple capture-the-flag challenge.

Darknet's Largest Mobile Malware Marketplace Threatens Users Worldwide
2022-12-06 12:38

Cybersecurity researchers have shed light on a darknet marketplace called InTheBox that's designed to specifically cater to mobile malware operators. "The automation allows other bad actors to create orders to receive the most up to date web injects for further implementation into mobile malware," Resecurity said.

Open Source Ransomware Toolkit Cryptonite Turns Into Accidental Wiper Malware
2022-12-06 06:11

A version of an open source ransomware toolkit called Cryptonite has been observed in the wild with wiper capabilities due to its "Weak architecture and programming." Written in Python, the malware employs the Fernet module of the cryptography package to encrypt files with a ".

Dark web recruiting techniques: Malware, phishing, and carding
2022-12-06 05:00

In this Help Net Security video, Roman Faithfull, Cyber Intelligence Analyst at Digital Shadows, talks about how threat actors mobilize new members within the cybercriminal ecosystem. Cybercriminal forums are awash with users advertising and requesting the services of developers to design fresh new malware.

Google warns stolen Android keys used to sign info-stealing malware
2022-12-05 22:30

Compromised Android platform certificate keys from device makers including Samsung, LG and Mediatek are being used to sign malware and deploy spyware, among other software nasties. Googler Łukasz Siewierski found and reported the security issue and it's a doozy that allows malicious applications signed with one of the compromised certificates to gain the same level of privileges as the Android operating system - essentially unfettered access to the victim's device.

Russian Courts Targeted by New CryWiper Data Wiper Malware Posing as Ransomware
2022-12-05 12:24

A new data wiper malware called CryWiper has been found targeting Russian government agencies, including mayor's offices and courts. "The activity of CryWiper once again shows that the payment of the ransom does not guarantee the recovery of files," the researchers said, stating the malware "Deliberately destroys the contents of files."

North Korean Hackers Spread AppleJeus Malware Disguised as Cryptocurrency Apps
2022-12-05 10:30

The Lazarus Group threat actor has been observed leveraging fake cryptocurrency apps as a lure to deliver a previously undocumented version of the AppleJeus malware, according to new findings from Volexity. "This activity notably involves a campaign likely targeting cryptocurrency users and organizations with a variant of the AppleJeus malware by way of malicious Microsoft Office documents," researchers Callum Roxan, Paul Rascagneres, and Robert Jan Mora said.

Android malware apps with 2 million installs spotted on Google Play
2022-12-04 15:11

A new set of Android malware, phishing, and adware apps have infiltrated the Google Play store, tricking over two million people into installing them. One app illustrated by Dr. Web that has amassed one million downloads is TubeBox, which remains available on Google Play at the time of writing this.