Security News

New Raspberry Robin worm uses Windows Installer to drop malware
2022-05-05 21:36

Red Canary intelligence analysts have discovered a new Windows malware with worm capabilities that spreads using external USB drives. This malware is linked to a cluster of malicious activity dubbed Raspberry Robin and was first observed in September 2021.

New worm and data wiper malware seen hitting Ukrainian networks
2022-03-01 14:41

Newly discovered malware was deployed in destructive attacks against Ukrainian organizations and governmental networks before and after Russia invaded the country on February 24. While analyzing these attacks, ESET Research Labs analysts discovered a new data wiper they dubbed IsaacWiper.

Relentless Log4j Attacks Include State Actors, Possible Worm
2021-12-15 23:18

"Our reports of the last 48 hours prove that both criminal-hacking groups and nation state actors are engaged in the exploration of this vulnerability, and we should all assume more such actors' operations are to be revealed in the coming days," Check Point added. Log4J based on what I've seen, there is evidence that a worm will be developed for this in the next 24 to 48 hours.

Golang Cryptomining Worm Offers 15% Speed Boost
2021-08-06 20:41

A freshly discovered variant of the Golang crypto-worm was recently spotted dropping Monero-mining malware on victim machines; in a switch-up of tactics, the payload binaries are capable of speeding up the mining process by 15 percent, researchers said. According to research from Uptycs, the worm scans for and exploits various known vulnerabilities in popular Unix and Linux-based web servers, including CVE-2020-14882 in the Oracle WebLogic Server, and CVE-2017-11610, a remote code-execution bug which affects XML-RPC servers.

India's Koo, a Twitter-like Service, Found Vulnerable to Critical Worm Attacks
2021-08-06 04:37

Koo, India's homegrown Twitter clone, recently patched a serious security vulnerability that could have been exploited to execute arbitrary JavaScript code against hundreds of thousands of its users, spreading the attack across the platform. The vulnerability involves a stored cross-site scripting flaw in Koo's web application that allows malicious scripts to be embedded directly into the affected web application.

The Code Red worm 20 years on – what have we learned?
2021-07-15 18:57

That's because July 2001 is when the infamous Code Red computer worm showed up, spread fast, and all but consumed the internet for several days. Back in 2001, Windows didn't support DEP, short for Data Execution Prevention, so that any code shoved onto the stack could blindly be executed, even though the stack is intended to store data, not code.

Indexsinas SMB Worm Campaign Infests Whole Enterprises
2021-06-30 20:19

The Indexsinas SMB worm is on the hunt for vulnerable environments to self-propagate into, researchers warned - with a particular focus on the healthcare, hospitality, education and telecommunications sectors. Since 2019, Indexsinas has used a large infrastructure made up of more than 1,300 devices acting as attack sources, with each device responsible for only a few attack incidents each.

FreakOut malware worms its way into vulnerable VMware servers
2021-06-04 13:03

A multi-platform Python-based malware targeting Windows and Linux devices has now been upgraded to worm its way into Internet-exposed VMware vCenter servers unpatched against a remote code execution vulnerability. FreakOut spreads itself by exploiting a wide range of OS and apps vulnerabilities and brute-forcing passwords over SSH, adding the infected devices to an IRC botnet controlled by its masters.

MountLocker ransomware uses Windows API to worm through networks
2021-05-19 07:31

The MountLocker ransomware operation now uses enterprise Windows Active Directory APIs to worm through networks. In March 2021, a new group ransomware group emerged called 'Astro Locker' that began using a customized version of the MountLocker ransomware with ransom notes pointing to their own payment and data leak sites.

Purple Fox Malware Targets Windows Machines With New Worm Capabilities
2021-03-24 14:56

A malware that has historically targeted exposed Windows machines through phishing and exploit kits has been retooled to add new "Worm" capabilities. Purple Fox, which first appeared in 2018, is an active malware campaign that until recently required user interaction or some kind of third-party tool to infect Windows machines.