New GnatSpy Mobile Malware Family Discovered
Earlier this year researchers first disclosed a targeted attack campaign targeting various sectors in the Middle East. This threat actor was called Two-tailed Scorpion/APT-C-23. Later on, a mobile component called VAMP was found, with a new variant (dubbed FrozenCell) discovered in October. (We detect these malicious apps as ANDROIDOS_STEALERC32). VAMP targeted various types of data from the phones of victims: […] more…Coin Miner Mobile Malware Returns, Hits Google Play
By Jason Gu, Veo Zhang, Seven Shen The efficacy of mobile devices to actually produce cryptocurrency in any meaningful amount is still doubtful. However, the effects on users of affected devices are clear: increased device wear and tear, reduced battery life, comparably slower performance. Recently, we found that apps with malicious cryptocurrency mining capabilities on […] more…Ztorg: money for infecting your smartphone
This research started when we discovered an infected Pokémon GO guide in Google Play. It was there for several weeks and was downloaded more than 500,000 times. We detected the malware as Trojan.AndroidOS.Ztorg.ad. After some searching, I found some other similar infected apps that were being distributed from the Google Play Store. The first of […] more…PUA Operation Spreads Thousands of Explicit Apps in the Wild and on Legitimate App Stores
One of the most popular ways to make money online is through pornography—whether through legitimate distribution or different online scams. Last year we detected a new variant of the Marcher Trojan targeting users through porn sites, and the year before that popular porn apps were used as lures to compromise millions of mobile users in […] more…TorrentLocker Changes Attack Method, Targets Leading European Countries
The TorrentLocker ransomware, which has been in a lull as of late, has recently come back with new variants (Detected by Trend Micro as Ransom_CRYPTLOCK.DLFLVV, Ransom_CRYPTLOCK.DLFLVW, Ransom_CRYPTLOCK.DLFLVS and Ransom_CRYPTLOCK.DLFLVU). These new variants are using a delivery mechanism that uses abused Dropbox accounts. This new type of attack is in line with our 2017 prediction that […] more…How To Prevent Ransomware (and Leprechauns) From Locking Up Your Data
St. Patrick’s Day is right around the corner, but before you crowd into your local pub and raise a green pint in honor of the Irish patron saint, keep an eye out for mischievous leprechauns… a.k.a: cybercriminals. No pot of gold is safe: including your company data. Leprechauns may be the stuff of folklore, but […] more…Lurk: Retracing the Group’s Five-Year Campaign
by Fyodor Yarochkin and Vladimir Kropotov (Senior Threat Researchers) Fileless infections are exactly what their namesake says: they’re infections that don’t involve malicious files being downloaded or written to the system’s disk. While fileless infections are not necessarily new or rare, it presents a serious threat to enterprises and end users given its capability to […] more…More information
- Dan Geer: US should buy zero-days, reveal them
- Microsoft Teams suffers another outage in the North America region
- Mr. Coffee with WeMo: Double Roast
- Critical cPanel & WHM Vulnerability Exploited as Zero-Day for Months
- phpbash – A Terminal Emulator Web Shell
- McAfee 2023 Threat Predictions: Evolution and Exploitation
- CISA Expands ‘Must-Patch’ List With Log4j, FortiOS, Other Vulnerabilities
- Cybercrime attacks on business bank accounts are dropping
- Cisco Unveils SecureX Security Platform
- Why Everyone Needs a VPN