Tag ESET

China-Connected CeranaKeeper Focusing on Southeast Asia for Data Exfiltration

Emerging Threat Actor CeranaKeeper Targets Southeast Asia in Data Exfiltration Campaigns A novel cyber threat actor, dubbed CeranaKeeper, has been implicated in a series of data exfiltration attacks focused on Southeast Asian nations, according to Slovak cybersecurity firm ESET. The firm reported that campaigns aimed at governmental organizations in Thailand…

Read MoreChina-Connected CeranaKeeper Focusing on Southeast Asia for Data Exfiltration

Chinese Hackers Attack Taiwan and U.S. NGOs Using MgBot and MACMA Malware

A Beijing-linked state-sponsored hacking group known as Daggerfly has targeted organizations in Taiwan and a U.S. non-governmental organization (NGO) operating in China, deploying an upgraded suite of malware tools in its most recent campaign. This sophisticated operation highlights the group’s engagement in internal espionage activities, as reported today by Symantec’s…

Read MoreChinese Hackers Attack Taiwan and U.S. NGOs Using MgBot and MACMA Malware

New Telekopye Scam Toolkit Aims at Booking.com and Airbnb Customers

ESET Research has uncovered a troubling expansion of the Telekopye scam network, which now targets popular accommodation booking services such as Booking.com and Airbnb. This development marks a significant shift in the landscape of online scams, where fraudulent activities have increasingly targeted unsuspecting travelers during peak booking seasons. In July…

Read MoreNew Telekopye Scam Toolkit Aims at Booking.com and Airbnb Customers

A Shadowy Hacking Collective Unveils Two New Techniques for Extracting Data from Air-Gapped Systems

Newly Discovered Cyber Toolkit Reveals Evolving Threats to Data Security Recent research has unveiled a sophisticated toolkit designed for cyber espionage, characterized by its modular architecture and diverse functionalities developed in multiple programming languages. This toolkit aims to enhance flexibility and resilience against detection by targets, particularly when individual components…

Read MoreA Shadowy Hacking Collective Unveils Two New Techniques for Extracting Data from Air-Gapped Systems

Internet Archive (Archive.Org) Breach: 31 Million Accounts Exposed

Internet Archive Faces Major Cyberattack, Exposing 31 Million User Records In a significant cybersecurity incident, the Internet Archive has fallen victim to a large-scale cyberattack resulting in a data breach that has compromised the personal details of approximately 31 million users. This incident not only threatens the security of user…

Read MoreInternet Archive (Archive.Org) Breach: 31 Million Accounts Exposed

Evolving Pakistan-Linked Malware Campaign Expands Its Targets to Windows, Android, and macOS

Operation Celestial Force: Ongoing Malware Campaign Linked to Pakistani Threat Actors A persistent malware campaign known as Operation Celestial Force has been traced back to actors linked to Pakistan, with activities dating as far back as 2018. Cisco Talos has identified the campaign’s reliance on two primary malware tools: GravityRAT,…

Read MoreEvolving Pakistan-Linked Malware Campaign Expands Its Targets to Windows, Android, and macOS

Polish Businesses Under Threat: Cybercriminals Leverage Agent Tesla and Formbook Malware

Widespread Phishing Campaigns Targeting SMBs in Poland Unleash Multiple Malware Strains In May 2024, cybersecurity researchers identified a pervasive series of phishing attacks directed at small and medium-sized businesses (SMBs) in Poland. During these campaigns, threat actors utilized a variety of malware families, including Agent Tesla, Formbook, and Remcos RAT,…

Read MorePolish Businesses Under Threat: Cybercriminals Leverage Agent Tesla and Formbook Malware

CosmicBeetle Launches Custom ScRansom Ransomware in Collaboration with RansomHub

CosmicBeetle Introduces ScRansom Ransomware Targeting SMBs Globally In a significant escalation in the realm of cyber threats, the group known as CosmicBeetle has launched a new ransomware variant called ScRansom, focusing on attacks against small- and medium-sized businesses (SMBs) across Europe, Asia, Africa, and South America. This malicious activity follows…

Read MoreCosmicBeetle Launches Custom ScRansom Ransomware in Collaboration with RansomHub