Cyber Crime

Pierluigi Paganini September 20, 2021
Pakistani man sentenced to 12 years of prison for his role in AT&T hacking scheme

A Pakistani national has been sentenced to 12 years of prison in the US for his role in a hacking scheme against the telecom giant AT&T. The Pakistani national Muhammad Fahd (35) was sentenced to 12 years of prison in the United States for his primary role in a seven-year scheme to illegally unlock nearly […]

Pierluigi Paganini September 18, 2021
Threat actor has been targeting the aviation industry since at least 2018

Security researchers from the Cisco Talos team uncovered a spear-phishing campaign targeting the aviation industry for two years avoiding detection. Security researchers from Cisco Talos uncovered a spear-phishing campaign targeting, dubbed Operation Layover, that targeted the aviation industry for two years without being detected. The experts believe that the threat actor behind this campaign is […]

Pierluigi Paganini September 17, 2021
New Go malware Capoae uses multiple flaws to target WordPress installs, Linux systems

A new malware written in Golang programming language, tracked as Capoae, is targeting WordPress installs and Linux systems. Akamai researchers spotted a new strain of malware written in Golang programming language, dubbed Capoae, that was involved in attacks aimed at WordPress installs and Linux systems.Ā  The malware spread through attacks exploiting known vulnerabilities (i.e. CVE-2020-14882 […]

Pierluigi Paganini September 16, 2021
Bitdefender released free REvil ransomware decryptor that works for past victims

Researchers from Bitdefender released a free master decryptor for the REvil ransomware operation that allows past victims to recover their files for free. Good news for the victims of REvil ransomware gangs that were infected before the operations were temporarily halted on July 13th, Bitdefender released a free master decryptor that allows them to recover […]

Pierluigi Paganini September 14, 2021
Mēris Bot infects MikroTik routers compromised in 2018

Latvian vendor MikroTik revealed that recently discoveredĀ Mēris botnetĀ is targeting devices that were compromised three years ago. Last week, the Russian Internet giant YandexĀ has been targeting by the largest DDoS attackĀ in the history of Runet, the Russian Internet designed to be independent of the world wide web and ensure the resilience of the country to an […]

Pierluigi Paganini September 14, 2021
Vermilion Strike, a Linux implementation of Cobalt Strike Beacon used in attacks

Researchers discovered Linux and Windows implementations of theĀ Cobalt Strike BeaconĀ developed by attackers that were actively used in attacks in the wild. Threat actors re-implemented from scratch unofficial Linux and Windows versions of theĀ Cobalt Strike Beacon and are actively using them in attacks aimed at organizations worldwide.Cobalt StrikeĀ is a legitimate penetration testing tool designedĀ as an attack […]

Pierluigi Paganini September 13, 2021
BlackMatter ransomware gang hit Technology giant Olympus

Technology giant Olympus announced it was the victim of a ransomware attack and is currently investigating the extent of the incident. Olympus issued a statement to announce that its European, Middle East and Africa computer network was hit by a ransomware attack. “Upon detection of suspicious activity, we immediately mobilized a specialized response team including […]

Pierluigi Paganini September 13, 2021
The new maxtrilha trojan is being disseminated and targeting several banks

A new banking trojan dubbed maxtrilha (due to its encryption key) has been discovered in the last few days and targeting customers of European and South American banks. The new maxtrilha trojan is being disseminated and targeting several banks around the world. Criminals are constantly creating variants of popular banking trojans, keeping in mind the sameĀ modus operandiĀ but […]

Pierluigi Paganini September 13, 2021
Department of Justice and Constitutional Development of South Africa hit by a ransomware attack

The Department of Justice and Constitutional Development of South Africa was hit by a ransomware attack that crippled bail services. A ransomware attack hit the Department of Justice and Constitutional Development of South Africa, multiple services, including email and bail services have been impacted. The incident did not affect child maintenance payments for the month […]

Pierluigi Paganini September 12, 2021
Revil ransomware operators are targeting new victims

Recently we observed that part of the REvil ransomware infrastructure was up and running again, now we can confirm that they hit new victims. On September 7, the servers of the REvil ransomware gang were back online after around two months since their shutdown. The circumstance was immediately noted by many researchers, me too. The […]