Malware

Pierluigi Paganini October 28, 2019
New FuxSocy Ransomware borrows code from defunct Cerber

Researchers discovered a new piece of ransomware called FuxSocy that borrows part of code from Cerber ransomware. Experts at MalwareHunterTeam discovered a new piece of ransomware called FuxSocy that borrows part of code from Cerber ransomware. The Cerber ransomware was first spotted in 2016, it was offered in the criminal underground as a ransomware-as-a-service (RaaS). The name of the […]

Pierluigi Paganini October 28, 2019
SWEED targets precision engineering companies in Italy

Security expert Marco Ramilli published a quick analysis of an interesting attack carried out by SWEED threat actor targeting precision engineering firms in Italy. Introduction Today I’d like to share a quick analysis of an interesting attack targeting precision engineering companies based in Italy. Precision engineering is a very important business market in Europe, it […]

Pierluigi Paganini October 28, 2019
Raccoon info stealer already infected 100,000+ worldwide

A new information stealer, dubbed Raccoon, made the headlines infecting hundreds of millions of victims worldwide. Security experts at Cybereason have spotted a new information stealer, dubbed Raccoon, that is infecting hundreds of millions of victims worldwide. The malware was designed to steal victims’ credit card data, email credentials, cryptocurrency wallets, and other sensitive data. […]

Pierluigi Paganini October 27, 2019
Ransomware hit TrialWorks, law firms and lawyers were not able to access court documents

TrialWorks, one of the most established providers of legal case management software for law firms and attorneys, was hit by ransomware. TrialWorks, a company that provides the most established and widely used legal case management software solutions, was a victim of a ransomware attack earlier this month. At result of the attack, law firms and lawyers, were […]

Pierluigi Paganini October 27, 2019
Experts found 17 apps in the Apple App Store infected with clicker Trojan

Wandera researchers discovered seventeen iOS applications infected with clicker Trojan into the official Apple App Store. Experts at Wandera discovered seventeen iOS applications infected with clicker Trojan into the official Apple App Store. The mobile apps were instructed by the C&C to simulate user interactions, allowing crooks to fraudulently collect ad revenue. “The clicker trojan […]

Pierluigi Paganini October 27, 2019
Security Affairs newsletter Round 237

A new round of the weekly newsletter arrived! The best news of the week with Security Affairs Hi folk, let me inform you that I suspended the newsletter service, anyway I’ll continue to provide you a list of published posts every week through the blog. Fake UpdraftPlus WordPress Plugins used to backdoor sites TA505 cybercrime […]

Pierluigi Paganini October 25, 2019
Experts attribute NukeSped RAT to North Korea-Linked hackers

Experts at Fortinet analyzed NukeSped malware samples that share multiple similarities with malware associated with North Korea-linked APTs. Fortinet has analyzed the NukeSped RAT that is believed to be a malware in the arsenal of the Lazarus North-Korea linked APT group. The attribution to the Lazarus group is based on the similarities with other malware […]

Pierluigi Paganini October 23, 2019
Experts believe the Magecart Group 5 could be linked to the Carbanak APT

Security experts linked the Magecart group 5 to the infamous Dridex banking Trojan and the Carbanak cybercrime group. Researchers at Malwarebytes found a link between a scheme associated with the Magecart group and Dridex phishing campaigns and the activities of the Carbanak group.  The Magecart group tracked as Magecart Group 5, one of the most […]

Pierluigi Paganini October 22, 2019
German firm Pilz still down a week after getting infected with ransomware

German company Pilz, one of the world’s biggest producers of automation tools is still down after getting infected by ransomware more than a week ago. German firm Pilz was still down after getting infected by the BitPaymer ransomware more than a week ago, on October 13, 2019. “Since Sunday, October 13, 2019, all servers and […]

Pierluigi Paganini October 21, 2019
Winnti APT group uses skip-2.0 malware to control Microsoft SQL Servers

Security experts have a new malware, dubbed skip-2.0 used by the China-linked APT group to establish a backdoor in Microsoft SQL Server systems. Security experts at ESET have discovered a new malware, dubbed skip-2.0, used by the Chinese Winnti cyberespionage group to gain persistence on Microsoft SQL Server systems. The Winnti group was first spotted by […]