Advertisement
Marimo RCE via CVE-2024-41663 Exploited to Deliver NKAbuse Malware
Attackers are exploiting a critical RCE in Marimo Python notebooks (CVE-2024-41663) to deploy NKAbuse malware via Hugging Face. Update to version 0.7.5.
SVG File Phishing: How Attackers Hide Malicious JavaScript in Images
Discover how attackers use Scalable Vector Graphics (SVG) to embed malicious JavaScript for phishing and credential theft while bypassing security filters.
AgingFly Malware: Credential Theft Operations Against Ukraine
Analysis of AgingFly malware, a new threat observed actively targeting Ukrainian government and hospital entities to steal credentials from Chromium browsers and…
Signed Software Abuse: How Malicious Scripts Disable EDR and AV
Analysis of signed adware being used to deploy antivirus-killing scripts with SYSTEM privileges across government and healthcare sectors.
Mirax RAT Analysis: Android Devices Targeted for Proxy Node Abuse
Mirax RAT targets Android users in Europe via MaaS, converting infected devices into residential proxy nodes. Technical analysis of capabilities and TTPs.
Mirax Android RAT: Bypassing Security via Malicious Meta Ads
Mirax Android RAT targets 220,000 users via Meta Ads, turning devices into SOCKS5 proxies. Learn to detect and mitigate this emerging mobile threat.
JanelaRAT Malware Analysis: 14,000+ Attacks Target Latin American Banks
Analyze the JanelaRAT campaign targeting Brazil and Mexico. Learn how this BX RAT variant steals financial data and how to detect JanelaRAT attacks.
Scanning for EncystPHP Webshell on FreePBX Systems — Detection Guide
Attackers are actively scanning for the EncystPHP webshell, targeting vulnerable FreePBX systems to establish persistent access and execute remote commands.
Storm Infostealer: Bypassing Local Decryption for Session Hijacking
Storm infostealer exfiltrates encrypted browser data for server-side decryption, allowing attackers to bypass MFA and hijack active user sessions.
Detect Obfuscated JavaScript Phishing Delivered via RAR Archives
Security researchers identify a new phishing campaign using heavily obfuscated JavaScript within RAR archives to bypass traditional endpoint detection.
LucidRook Malware Targets Taiwan NGOs via DLL Side-Loading
Analysis of the Lua-based LucidRook malware targeting Taiwanese NGOs and universities through spear-phishing and sophisticated DLL side-loading techniques.
Magecart Skimmer Hides in Pixel-Sized SVG on Magento Stores
A sophisticated Magecart campaign targets nearly 100 Magento stores, concealing credit card-stealing JavaScript within tiny, pixel-sized SVG images.
Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns
The Masjesu botnet targets IoT devices across multiple architectures to facilitate DDoS-for-hire services via Telegram, posing risks to global infrastructure.
Chaos Malware Variant Targets Cloud Infrastructure via SOCKS Proxy
A new variant of Chaos malware targets misconfigured cloud deployments, leveraging SOCKS proxy capabilities to expand botnet infrastructure beyond edge devices.
Masjesu Botnet: Stealthy DDoS Malware Targets Linux IoT Devices
Masjesu is a highly evasive DDoS botnet targeting Linux IoT devices. It prioritizes persistence and avoids critical infrastructure to remain undetected.
Medusa Ransomware: Rapid Vulnerability Weaponization and Analysis
An analysis of Medusa ransomware's rapid exploitation of vulnerabilities and Zero-Day bugs to exfiltrate and encrypt data within days of initial access.
Qilin and Warlock Ransomware Bypass 300+ EDR Tools via BYOVD
Threat actors Qilin and Warlock use Bring Your Own Vulnerable Driver (BYOVD) tactics and msimg32.dll to disable security software on compromised endpoints.
SparkCat Mobile Malware Variant Steals Crypto Recovery Phrases
A new SparkCat malware variant targets iOS and Android users, stealing crypto wallet recovery phrase images from compromised apps on official stores.
Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak
Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and…
Casbaneiro Banking Trojan: Evasion and Lateral Movement in Latin America
Analyzing Casbaneiro, a sophisticated banking Trojan employing advanced evasion, process injection, and network worming to target financial institutions and users in…
Ransomware Preparation: Healthcare Facilities' Defense Strategy
Hospitals face inevitable ransomware attacks. Learn why proactive incident response planning, regular rehearsals, and robust technical controls are crucial for defense.
CrystalRAT Malware: A New MaaS Threat with RAT, Stealer, and Prankware
CrystalRAT is a new malware-as-a-service (MaaS) promoted on Telegram, offering remote access, data theft, keylogging, and system disruption features, posing a…
NoVoice Android Malware on Google Play: 2.3 Million Devices Infected
NoVoice Android malware, disguised in over 50 Google Play apps, infected 2.3 million devices, exhibiting aggressive adware and subscription fraud.
Venom Stealer MaaS: Commoditizing Information Theft via ClickFix Attacks
Analyze Venom Stealer MaaS, a new cybercrime platform enabling automated, persistent information-stealing through social engineering 'ClickFix' attacks. Learn detection…