Malware

Pierluigi Paganini August 04, 2019
Security Affairs newsletter Round 225 and Important Update

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Hi folk, let me inform you that I suspended the newsletter service, anyway I’ll continue to provide you a list of published posts every week through the blog. Once again thank you! Crooks used rare Steganography technique […]

Pierluigi Paganini August 04, 2019
Houston County Schools in Alabama delayed the school year’s opening due to a malware attack

It has happened again, for the second time in a few days, Houston County Schools in Alabama delayed the school year’s opening due to a malware attack. The long wave of malware attacks against US schools continues, for the second time in a week, the Houston County Schools in Alabama delayed the school year’s opening scheduled for […]

Pierluigi Paganini August 04, 2019
DealPly adware abuses reputation services to remain under the radar

Malware researchers from enSilo have spotted a new variant of the DealPly adware that uses a new method to avoid detection. Researchers from enSilo have discovered a new variant of the modular DealPly adware that abuses the reputation services provided by Microsoft’s SmartScreen (aka Windows Defender SmartScreen) and McAfee’s WebAdvisor to avoid detection. The main […]

Pierluigi Paganini August 03, 2019
SystemBC, a new proxy malware is being distributed via Fallout and RIG EK

Researchers at Proofpoint discovered SystemBC, a new strain of proxy malware that is being distributed via Fallout and RIG Exploit Kits A new piece of malware dubbed SystemBC was discovered by experts at Proofpoint, it is being distributed via exploit kits like Fallout and RIG. The malware was tracked as “SystemBC” based on the URI path […]

Pierluigi Paganini August 01, 2019
New Mirai botnet hides C2 server in the Tor network to prevent takedowns

Researchers at Trend Micro have discovered a new Mirai Botnet that has command and control server in the Tor network to make takedowns hard. Experts at Trend Micro have discovered a new Mirai Botnet that uses a Command and Control hidden in the Tor Network, a choice that protects the anonymity of the operators and […]

Pierluigi Paganini July 30, 2019
Malware researchers analyzed an intriguing Java ATM Malware

Experts spotted a Java ATM malware that was relying on the XFS (EXtension for Financial Service) API to “jackpot” the infected machine Introduction Recently our attention was caught by a really particular malware sample most probably linked toa recent cybercriminal operation against the banking sector. This piece of malicious code is a so-called ‘ATM malware‘: […]

Pierluigi Paganini July 29, 2019
Sonicwall warns of a spike in the number of attacks involving encrypted malware and IoT malware

According to experts at Sonicwall, scanning of random ports and the diffusion of encrypted malware are characterizing the threat landscape. In 2018, global malware volume recorded by SonicWall hit a record-breaking 10.52 billion attacks. The situation is better in the first half of 2019, when SonicWall recorded 4.8 billion attacks, a 20% drop compared to […]

Pierluigi Paganini July 27, 2019
No More Ransom project has helped victims to save $108 million of ransom

Over the past three years, the website of No More Ransom was visited by 3 million users and allowed to save $108 million in ransom to the victims of 109 ransomware. After three years, No More Ransom confirms the success of the initiative that aims at helping victims of ransomware. The No More Ransom was […]

Pierluigi Paganini July 27, 2019
Hackers inject Magecart multi-gateway skimmer in fake Google domains

Attackers deployed a Magecart credit card skimmer script into fake Google domains used to trick visitors into making online transactions.  Experts at Sucuri discovered threat actors using fake Google domains hosting a Magento skimmer script used to steal payment data when unaware visitors make transactions. The campaign was uncovered when the owner of a website […]

Pierluigi Paganini July 26, 2019
Johannesburg residents left in the dark after a ransomware attack at City Power

South African electric utility City Power that provides energy to the city of Johannesburg, has suffered serious disruptions after a ransomware attack. A ransomware infected systems at City Power, an electricity provider in the city of Johannesburg, South Africa, and some residents were left without power. The energy utility informed its customers via Twitter of […]