Security News

GoBruteforcer: New Golang-Based Malware Breaches Web Servers Via Brute-Force Attacks
2023-03-14 12:02

A new Golang-based malware dubbed GoBruteforcer has been found targeting web servers running phpMyAdmin, MySQL, FTP, and Postgres to corral the devices into a botnet. The malware is mainly designed to single out Unix-like platforms running x86, x64 and ARM architectures, with GoBruteforcer attempting to obtain access via a brute-force attack using a list of credentials hard-coded into the binary.

New Hiatus malware campaign targets routers
2023-03-13 20:44

As previously exposed, routers might be used by threat actors as efficient locations to plant malware, often for cyberespionage. Lumen's Black Lotus Labs has exposed new malware targeting routers in a campaign named Hiatus by the researchers.

Warning: AI-generated YouTube Video Tutorials Spreading Infostealer Malware
2023-03-13 11:47

Threat actors have been increasingly observed using AI-generated YouTube Videos to spread a variety of stealer malware such as Raccoon, RedLine, and Vidar. "The videos lure users by pretending to be tutorials on how to download cracked versions of software such as Photoshop, Premiere Pro, Autodesk 3ds Max, AutoCAD, and other products that are licensed products available only to paid users," CloudSEK researcher Pavan Karthick M said.

KamiKakaBot Malware Used in Latest Dark Pink APT Attacks on Southeast Asian Targets
2023-03-13 06:15

The Dark Pink advanced persistent threat actor has been linked to a fresh set of attacks targeting government and military entities in Southeast Asian countries with a malware called KamiKakaBot. Dark Pink, also called Saaiwc, was first profiled by Group-IB earlier this year, describing its use of custom tools such as TelePowerBot and KamiKakaBot to run arbitrary commands and exfiltrate sensitive information.

BATLOADER Malware Uses Google Ads to Deliver Vidar Stealer and Ursnif Payloads
2023-03-11 13:32

The malware downloader known as BATLOADER has been observed abusing Google Ads to deliver secondary payloads like Vidar Stealer and Ursnif. BATLOADER, as the name suggests, is a loader that's responsible for distributing next-stage malware such as information stealers, banking malware, Cobalt Strike, and even ransomware.

Microsoft OneNote to get enhanced security after recent malware abuse
2023-03-10 21:27

Microsoft will introduce improved protection against phishing attacks pushing malware via malicious Microsoft OneNote files.To thwart phishing attacks using malicious Microsoft OneNote attachments, you can set up secure mail gateways or mail servers to automatically block OneNote documents with.

New GoBruteforcer malware targets phpMyAdmin, MySQL, FTP, Postgres
2023-03-10 19:02

A newly discovered Golang-based botnet malware scans for and infects web servers running phpMyAdmin, MySQL, FTP, and Postgres services. According to researchers with Palo Alto Networks' Unit 42, who first spotted it in the wild and dubbed it GoBruteforcer, the malware is compatible with x86, x64, and ARM architectures.

Security researchers targeted with new malware via job offers on LinkedIn
2023-03-10 17:48

A suspected North Korean hacking group is targeting security researchers and media organizations in the U.S. and Europe with fake job offers that lead to the deployment of three new, custom malware families. Mandiant says the particular group has previously targeted tech firms, media groups, and entities in the defense industry.

China-linked Hackers Targeting Unpatched SonicWall SMA Devices with Malware
2023-03-10 13:50

A suspecting China-linked hacking campaign has been observed targeting unpatched SonicWall Secure Mobile Access 100 appliances to drop malware and establish long-term persistence. "The malware has functionality to steal user credentials, provide shell access, and persist through firmware upgrades," cybersecurity company Mandiant said in a technical report published this week.

Xenomorph Android malware now steals data from 400 banks
2023-03-10 10:24

The Xenomorph Android malware has released a new version that adds significant capabilities to conduct malicious attacks, including a new automated transfer system framework and the ability to steal credentials for 400 banks. "With these new features, Xenomorph is now able to complete automate the whole fraud chain, from infection to funds exfiltration, making it one of the most advanced and dangerous Android Malware trojans in circulation," warns ThreatFabric.