Security News

Russian Hackers Exploit New NTLM Flaw to Deploy RAT Malware via Phishing Emails
2024-11-14 05:43

A newly patched security flaw impacting Windows NT LAN Manager (NTLM) was exploited as a zero-day by a suspected Russia-linked actor as part of cyber attacks targeting Ukraine. The vulnerability...

Cybercriminals Use Excel Exploit to Spread Fileless Remcos RAT Malware
2024-11-11 06:13

Cybersecurity researchers have discovered a new phishing campaign that spreads a new fileless variant of known commercial malware called Remcos RAT. Remcos RAT "provides purchases with a wide...

Russian RomCom Attacks Target Ukrainian Government with New SingleCamper RAT Variant
2024-10-17 16:13

The Russian threat actor known as RomCom has been linked to a new wave of cyber attacks aimed at Ukrainian government agencies and unknown Polish entities since at least late 2023. The intrusions...

New Malware Campaign Uses PureCrypter Loader to Deliver DarkVision RAT
2024-10-15 15:20

Cybersecurity researchers have disclosed a new malware campaign that leverages a malware loader named PureCrypter to deliver a commodity remote access trojan (RAT) called DarkVision RAT. The...

Blind Eagle Targets Colombian Insurance Sector with Customized Quasar RAT
2024-09-09 12:24

The Colombian insurance sector is the target of a threat actor tracked as Blind Eagle with the end goal of delivering a customized version of a known commodity remote access trojan (RAT) known as...

macOS Version of HZ RAT Backdoor Targets Chinese Messaging App Users
2024-08-27 16:08

Users of Chinese instant messaging apps like DingTalk and WeChat are the target of an Apple macOS version of a backdoor named HZ RAT. The artifacts "almost exactly replicate the functionality of...

Blind Eagle Hackers Exploit Spear-Phishing to Deploy RATs in Latin America
2024-08-20 06:14

Cybersecurity researchers have shed light on a threat actor known as Blind Eagle that has persistently targeted entities and individuals in Colombia, Ecuador, Chile, Panama, and other Latin...

New UULoader Malware Distributes Gh0st RAT and Mimikatz in East Asia
2024-08-19 13:06

A new type of malware called UULoader is being used by threat actors to deliver next-stage payloads like Gh0st RAT and Mimikatz. There is evidence pointing to UULoader being the work of a Chinese speaker due to the presence of Chinese strings in program database files embedded within the DLL file.

Ransomware gang targets IT workers with new RAT masquerading as IP scanner
2024-08-06 13:25

Ransomware-as-a-service outfit Hunters International is wielding a new remote access trojan. Angry IP Scanner is an IP address and port scanner, and as such is more likely to be downloaded and used by IT workers.

Gh0st RAT Trojan Targets Chinese Windows Users via Fake Chrome Site
2024-07-29 04:56

The remote access trojan known as Gh0st RAT has been observed being delivered by an "Evasive dropper" called Gh0stGambit as part of a drive-by download scheme targeting Chinese-speaking Windows users. These infections stem from a fake website serving malicious installer packages masquerading as Google's Chrome browser, indicating that users searching for the software on the web are being singled out.