Security News

Gafgyt malware exploits five-years-old flaw in EoL Zyxel router
2023-08-10 20:35

Fortinet has issued an alert warning that the Gafgyt botnet malware is actively trying to exploit a vulnerability in the end-of-life Zyxel P660HN-T1A router in thousands of daily attacks. [...]

New Attack Alert: Freeze[.]rs Injector Weaponized for XWorm Malware Attacks
2023-08-10 14:20

Malicious actors are using a legitimate Rust-based injector called Freeze[.]rs to deploy a commodity malware called XWorm in victim environments. The novel attack chain, detected by Fortinet...

New Statc Stealer Malware Emerges: Your Sensitive Data at Risk
2023-08-10 14:08

A new information malware strain called Statc Stealer has been found infecting devices running Microsoft Windows to siphon sensitive personal and payment information. "Statc Stealer exhibits a...

QakBot Malware Operators Expand C2 Network with 15 New Servers
2023-08-08 14:15

The operators associated with the QakBot malware have set up 15 new command-and-control servers as of late June 2023. The findings are a continuation of the malware's infrastructure analysis from Team Cymru, and arrive a little over two months after Lumen Black Lotus Labs revealed that 25% of its C2 servers are only active for a single day.

New Malware Campaign Targets Inexperienced Cyber Criminals with OpenBullet Configs
2023-08-07 15:57

A new malware campaign has been observed making use of malicious OpenBullet configuration files to target inexperienced cyber criminals with the goal of delivering a remote access trojan capable of stealing sensitive information. OpenBullet is a legitimate open-source pen testing tool used for automating credential stuffing attacks.

New SkidMap Linux Malware Variant Targeting Vulnerable Redis Servers
2023-08-07 09:52

Vulnerable Redis services have been targeted by a "New, improved, dangerous" variant of a malware called SkidMap that's engineered to target a wide range of Linux distributions. "The malicious nature of this malware is to adapt to the system on which it is executed," Trustwave security researcher Radoslaw Zdonczyk said in an analysis published last week.

Reptile Rootkit: Advanced Linux Malware Targeting South Korean Systems
2023-08-05 07:52

Threat actors are using an open-source rootkit called Reptile to target Linux systems in South Korea. "Unlike other rootkit malware that typically only provide concealment capabilities, Reptile goes a step further by offering a reverse shell, allowing threat actors to easily take control of systems," the AhnLab Security Emergency Response Center said in a report published this week.

Google explains how Android malware slips onto Google Play Store
2023-08-04 17:04

The Google Cloud security team acknowledged a common tactic known as versioning used by malicious actors to slip malware on Android devices after evading the Google Play Store's review process and...

Hackers can abuse Microsoft Office executables to download malware
2023-08-03 15:48

The main executable for the Microsoft Publisher application has already been confirmed that it can download payloads from a remote server. According to recent research, even executables that are not signed by Microsoft serve purposes that are useful in attacks, such as reconnaissance.

Chrome malware Rilide targets enterprise users via PowerPoint guides
2023-08-03 14:36

The malicious Rilide Stealer Chrome browser extension has returned in new campaigns targeting crypto users and enterprise employees to steal credentials and crypto wallets. Rilide is a malicious browser extension for Chromium-based browsers, including Chrome, Edge, Brave, and Opera, that Trustwave SpiderLabs initially discovered in April 2023.