The DreamBus botnet has resurfaced after a two-year break and it has been seen exploiting a recently patched Apache RocketMQ vulnerability in attacks whose goal is the delivery of a cryptocurrency miner. Apache RocketMQ is a widely used distributed messaging and streaming platform. The exploited vulnerability is tracked as CVE-2023-33246 and its existence came to ..
Tag : malware
Researchers at Secureworks have come across a mysterious piece of malware that scans for nearby Wi-Fi access points in an effort to obtain the location of the infected device. The malware, dubbed Whiffy Recon, targets Windows systems and is designed to conduct Wi-Fi scanning every 60 seconds. The collected data is fed to a geolocation ..
Ago 22, 2023 Marina Londei In evidenza, Minacce, Minacce, News, RSS, Trojan, Vulnerabilità 0 Qbot continua a far tremare l’Italia: secondo il Global Threat Index di Check Point Research relativo al mese di luglio, il malware è stato la minaccia principale del mese con un impatto del 6% rispetto al 5,39% globale. Conosciuto anche come ..
Cybersecurity company Cyfirma claims to have uncovered the real identity of the developer behind the CypherRAT and CraxsRAT remote access trojans (RATs). Using the online handle of ‘EVLF DEV’ and operating out of Syria for the past eight years, the individual is believed to have made over $75,000 from selling the two RATs to various ..
Threat actors are leveraging access to malware-infected Windows and macOS systems to deploy a proxy application, AT&T’s Alien Labs reports. To date, AT&T Alien Labs researchers have identified over 400,000 systems that act as proxy exit nodes in this network. However, it is unclear how many of these were infected, and the company that offers ..
Ago 09, 2023 Marina Londei Apt, Attacchi, In evidenza, Malware, Minacce, Minacce, News, RSS 0 Il gruppo iraniano APT34 ha colpito di nuovo: conosciuti largamente anche come OilRig e Twisted Kitten, i cybercriminali hanno preso di mira diversi obiettivi legati alle istituzioni governative degli Emirati Arabi Uniti. Come si legge su DarkReading, ricercatori di Kaspersky ..
Ago 03, 2023 Marina Londei In evidenza, Malware, Minacce, Minacce, News, RSS 0 Emergono nuovi dettagli su AVRecon, un trojan per l’accesso remoto basato su Linux attivo ormai da due anni, e non sono rassicuranti: il malware è molto più diffuso di ciò che si pensava inizialmente. A metà luglio i ricercatori di Lumen avevano ..
The US Cybersecurity and Infrastructure Security Agency (CISA) has published analysis reports on three malware families deployed in an attack exploiting a recent remote command injection vulnerability in Barracuda Email Security Gateway (ESG). Tracked as CVE-2023-2868 and affecting versions 5.1.3.001 to 9.2.0.006 of the appliance, the flaw was exploited as a zero-day starting at least ..
Getty Images reader comments 4 with Security researchers have unearthed a rare malware find: malicious Android apps that use optical character recognition to steal credentials displayed on phone screens. The malware, dubbed CherryBlos by researchers from security firm Trend Micro, has been embedded into at least four Android apps available outside of Google Play, specifically ..
A threat actor infected their own computer with an information stealer, which has allowed Israeli threat intelligence company Hudson Rock to uncover their real identity. Using the online moniker ‘La_Citrix’, the threat actor has been active on Russian speaking cybercrime forums since 2020, offering access to hacked companies and info-stealer logs from active infections. La_Citrix, ..


