Tag Malware

The Escalating Danger of Pegasus Spyware: Recent Discoveries and Increasing Alarm

In recent years, the Pegasus spyware, developed by the Israeli cyber intelligence firm NSO Group, has gained notoriety for its involvement in high-profile surveillance cases. The spyware has been implicated in numerous security breaches, most notably the unauthorized monitoring of Amazon founder Jeff Bezos through collaboration with a Saudi prince…

Read MoreThe Escalating Danger of Pegasus Spyware: Recent Discoveries and Increasing Alarm

SmokeLoader Malware Leverages MS Office Vulnerabilities to Steal Browser Credentials

Cybersecurity Alert: SmokeLoader Malware Targets Taiwanese Industries Recent investigations by Fortinet’s FortiGuard Labs have revealed a sophisticated malware campaign primarily employing SmokeLoader to target various sectors in Taiwan, including manufacturing, healthcare, and information technology. This campaign signifies a direct and alarming threat to entities within these industries, highlighting the need…

Read MoreSmokeLoader Malware Leverages MS Office Vulnerabilities to Steal Browser Credentials

Illegal Movie Piracy Streaming Service Shut Down; Malware Distribution Investigation Underway

A significant illegal streaming piracy operation has been dismantled through a coordinated effort led by Italy’s Postal and Cybersecurity Police Service. This operation involved collaboration with Europol, Eurojust, and a specialized cyber team linked to the UK’s National Cyber Security Centre (NCSC). Ongoing investigations have revealed that the dismantled service…

Read MoreIllegal Movie Piracy Streaming Service Shut Down; Malware Distribution Investigation Underway

Snail Mail Cyber Attacks Target Android Users and Raise Security Concerns for 23andMe Data

Cybercriminals Exploit Traditional Mail to Target Android Users The rise of cybercrime has introduced a bizarre twist to conventional means of communication, as nefarious actors are now leveraging traditional postal services, commonly referred to as “Snail Mail,” to distribute malware aimed at Android smartphones. The Swiss National Cyber Security Center…

Read MoreSnail Mail Cyber Attacks Target Android Users and Raise Security Concerns for 23andMe Data

Cybersecurity Update: T-Mobile Confirms Data Breach, AnnieMac Exposed, NewGlove Malware Risk – CISO Series

T-Mobile Confirms Data Breach as Cybersecurity Threats Loom In a recent development that underscores ongoing vulnerabilities in the cybersecurity landscape, T-Mobile has confirmed a data breach affecting its systems. The incident highlights the increasing challenges businesses face in safeguarding sensitive information against increasingly sophisticated cybercriminal tactics. The breach reportedly involves…

Read MoreCybersecurity Update: T-Mobile Confirms Data Breach, AnnieMac Exposed, NewGlove Malware Risk – CISO Series

The Hidden Dangers of Google Searches: How Basic Keywords Can Expose You to Cyber Threats

Cyber Threats in Google Searches: Understanding Risks and Safeguards Google has revolutionized the way we gather information, seamlessly integrating into our everyday lives. From quickly finding directions to researching complex topics, Google’s search engine has become indispensable. However, the ease of access to information comes with a hidden risk: the…

Read MoreThe Hidden Dangers of Google Searches: How Basic Keywords Can Expose You to Cyber Threats

BlueBravo Targets European Diplomats with GraphicalProton Backdoor July 28, 2023 Cyber Espionage / Malware The Russian state-sponsored group known as BlueBravo has been detected attacking diplomatic entities in Eastern Europe with the intent of deploying a new backdoor malware dubbed GraphicalProton. This move highlights the ongoing evolution of cyber threats, according to a recent report from Recorded Future. The phishing campaign, active from March to May 2023, employs legitimate internet services (LIS) to obscure command-and-control (C2) activities. BlueBravo, also referred to as APT29, Cloaked Ursa, and Midnight Blizzard (formerly Nobelium), is linked to Russia’s Foreign Intelligence Service (SVR) and has historically utilized platforms like Dropbox, Firebase, Google Drive, Notion, and Trello to bypass detection and maintain covert communication with compromised systems. GraphicalProton marks the latest in a series of malware targeting diplomatic organizations, following GraphicalNeutrino (SNOWYAMBER), HALFRIG, and QUARTERRIG.

BlueBravo Deploys GraphicalProton Backdoor Targeting European Diplomatic Entities On July 28, 2023, reports emerged detailing a sophisticated cyber espionage campaign orchestrated by the Russian state-sponsored group known as BlueBravo. This threat actor has turned its focus towards diplomatic institutions located in Eastern Europe, utilizing a newly developed backdoor named GraphicalProton.…

Read MoreBlueBravo Targets European Diplomats with GraphicalProton Backdoor July 28, 2023 Cyber Espionage / Malware The Russian state-sponsored group known as BlueBravo has been detected attacking diplomatic entities in Eastern Europe with the intent of deploying a new backdoor malware dubbed GraphicalProton. This move highlights the ongoing evolution of cyber threats, according to a recent report from Recorded Future. The phishing campaign, active from March to May 2023, employs legitimate internet services (LIS) to obscure command-and-control (C2) activities. BlueBravo, also referred to as APT29, Cloaked Ursa, and Midnight Blizzard (formerly Nobelium), is linked to Russia’s Foreign Intelligence Service (SVR) and has historically utilized platforms like Dropbox, Firebase, Google Drive, Notion, and Trello to bypass detection and maintain covert communication with compromised systems. GraphicalProton marks the latest in a series of malware targeting diplomatic organizations, following GraphicalNeutrino (SNOWYAMBER), HALFRIG, and QUARTERRIG.

STARK#MULE Cyber Campaign Targets Korean Speakers with U.S. Military-Themed Malware Documents

July 28, 2023
Cyber Attack / Malware

A persistent cyber attack campaign identified as STARK#MULE is aimed at Korean-speaking individuals, using U.S. Military-themed documents to lure victims into executing malware on compromised systems. Cybersecurity firm Securonix has been monitoring this activity, though the full extent of the attacks remains unclear and it is unknown if any of them have successfully compromised systems. Security researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov noted in a report shared with The Hacker News that these attacks are reminiscent of previous ones linked to North Korean groups like APT37, which has historically targeted South Korea, particularly its government officials. APT37, also known by various aliases including Nickel Foxcroft, Reaper, Ricochet Chollima, and ScarCruft, is recognized as a North Korean state-sponsored actor focused on southern targets.

STARK#MULE Targets Koreans with U.S. Military-Themed Document Lures In a notable development in cyber threats, a new campaign has emerged targeting Korean-speaking individuals through the use of U.S. military-themed documents designed to deliver malware. Cybersecurity experts from Securonix have named the campaign STARK#MULE and are actively monitoring its activities. While…

Read More

STARK#MULE Cyber Campaign Targets Korean Speakers with U.S. Military-Themed Malware Documents

July 28, 2023
Cyber Attack / Malware

A persistent cyber attack campaign identified as STARK#MULE is aimed at Korean-speaking individuals, using U.S. Military-themed documents to lure victims into executing malware on compromised systems. Cybersecurity firm Securonix has been monitoring this activity, though the full extent of the attacks remains unclear and it is unknown if any of them have successfully compromised systems. Security researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov noted in a report shared with The Hacker News that these attacks are reminiscent of previous ones linked to North Korean groups like APT37, which has historically targeted South Korea, particularly its government officials. APT37, also known by various aliases including Nickel Foxcroft, Reaper, Ricochet Chollima, and ScarCruft, is recognized as a North Korean state-sponsored actor focused on southern targets.