Malware

Pierluigi Paganini January 24, 2017
Techniques for the manipulation of malicious payloads to improve evasion

Security researchers at the iSwatlab have conducted an analysis of a few methods for the creation of some malicious payloads or shellcodes. This work compares some infamous methods for the creation of malicious payloads or shellcodes. These payloads must be used to create a remote connection between the victim’s machine and the attacker’s machine that […]

Pierluigi Paganini January 23, 2017
BankBot, an Android malware based on a source code leaked online

Antivirus firm Dr. Web spotted a new Android malware dubbed BankBot that is based on a source code that was leaked on an underground forum. Bad news for Android users, researchers from the Russian antivirus maker Dr. Web have reported that the source code for another Android banking malware has been leaked on an underground hacking […]

Pierluigi Paganini January 22, 2017
The author of the NeverQuest banking Trojan arrested in Spain

The Spanish law enforcement has arrested an alleged Russian Vxer suspected of developing the infamous Neverquest banking Trojan. Today I report another success of law enforcement, the Spanish police have arrested an alleged Russian Vxer suspected of developing the infamous Neverquest banking Trojan. The malware was developed to target financial institutions across the world. Lisov is suspected of being […]

Pierluigi Paganini January 20, 2017
Satan, the ransomware-as-a-service surfaced in the dark web

The independent malware research @Xylit0l discovered the Satan ransomware, a malware belonging to the Gen:Trojan.Heur2.FU family. Yesterday the independent malware research @Xylit0l discovered the Satan ransomware, a malware belonging to the Gen:Trojan.Heur2.FU family. Satan is provided as a RaaS (Ransomware-as-a-Service). New #RaaS https://t.co/wbqn2GOuvo pic.twitter.com/skTTNCDbod — Xylitol (@Xylit0l) January 18, 2017 The Satan ransomware used RSA-2048 […]

Pierluigi Paganini January 19, 2017
Quimitchin, a Mac backdoor that includes antiquated code

Researchers at Malwarebytes have discovered the first Mac malware of 2017, dubbed Quimitchin, that was used against  biomedical research institutions. Security experts have spotted the first Mac malware of 2017, dubbed Quimitchin,  and it is considered a malicious code not particularly sophisticated and includes some antiquated code. According to the researchers from Malwarebytes, the code has […]

Pierluigi Paganini January 18, 2017
US cancer agency targeted by a singular ransomware attack

A new ransomware campaign has targeted the not-for-profit cancer services organisation “Little Red Door” requesting a US$44,000 ransom. A new ransomware campaign has targeted a not-for-profit cancer services organisation, the Little Red Door. The organization provides a number of cancer support services, including diagnostics and treatment. The system at the agency was infected by a ransomware last Wednesday, […]

Pierluigi Paganini January 16, 2017
New campaign leverages RIG Exploit kit to deliver the Cerber Ransomware

Experts from Heimdal Security warned of a spike in cyber attacks leveraging the popular RIG Exploit kit to deliver the Cerber Ransomware. The RIG exploit kit is even more popular in the criminal ecosystem, a few days ago security experts at Heimdal Security warned of a spike in cyber attacks leveraging the popular Neutrino and […]

Pierluigi Paganini January 13, 2017
Two observations about the Italian EyePyramid espionage campaign

Let’s try to analyze some facts about the Italian EyePyramid espionage campaign. Prof. Corrado Aaron Visaggio helped us in this difficult task. The Italian EyePyramid espionage campaign raised to me two simple questions: (i) Are the criminals geniuses or dummies? (ii) How can an old, known, easy-to-detect malware infect so many machines belonging to different […]

Pierluigi Paganini January 12, 2017
EyePyramid – Police arrests two for hacking into emails of politicians, lawyers, entrepreneurs, and masons

Two Italian siblings have been arrested by Italian Police and they were charged with a long-running cyber espionage campaign. This is a very intriguing story, two Italian siblings Giulio and Francesca Maria Occhionero gave been arrested by Italian Police and they were charged with a long-running cyber espionage campaign that targeted Italian politicians, lawyers, entrepreneurs, and masons. The […]

Pierluigi Paganini January 12, 2017
Spora Ransomware allows victims to pay for immunity from future attacks

 Security experts from Emsisoft spotted a new strain of malware, the Spora ransomware, that allows potential victims to pay for immunity from future attacks. Security experts from Emsisoft spotted a new strain of ransomware dubbed Spora that implements a singular extortion mechanism, it allows potential victims to pay for immunity from future attacks. According to the experts, […]