Malware

Pierluigi Paganini May 22, 2016
Microsoft warns of malicious macros using a new sneaky trick

Researchers at the Microsoft’s Malware Protection Center are warning of a new wave of attacks leveraging malicious macros using a new sneaky trick. Researchers at Microsoft’s Malware Protection Center are warning of a new technique attackers are using to allow macro malware elude detection solutions. The experts first spotted the technique while analyzing a file […]

Pierluigi Paganini May 19, 2016
Teslacrypt decryption tool allows victims to restore their files

A security researcher from ESET security firm issue a Teslacrypt decryption tool after the author closed the project and released a free master key. The victims of the dreaded TeslaCrypt Ransomware now have the opportunity to restore their files by using a decryptor developed by experts from the ESET security Firm. “Today, ESETÂź released a […]

Pierluigi Paganini May 18, 2016
Skimer malware evolves, it is used to target ATMs

Experts at Kaspersky Lab have detected a new variant of  the Skimer malware used to steal money and payment card data from ATMs. Security experts at Kaspersky Lab have spotted a new strain of the malware dubbed ‘Skimer’ (Backdoor.Win32.Skimer). Skimer is an old threat that has been around since 2009, it is used by criminal organizations to […]

Pierluigi Paganini May 17, 2016
Redirector.Paco, a Million-Machine Clickfraud Botnet

According to the experts at Bitdefender an HTTPS hijacking click-fraud botnet dubbed Redirector.Paco infected almost 1 million devices since now. Security experts at Bitdefender spotted a new click fraud botnet dubbed Redirector.Paco that has been around at least since September 2014 and has already infected more than 900,000 devices over the years. Crooks behind the Redirector.Paco aimed to create a clickbot that […]

Pierluigi Paganini May 16, 2016
Experts also cracked the CryptXXX ransomware 2.0

Security Experts at Kaspersky have updated their decryption tool to adapt to the second version of CryptXXX ransomware in the RannohDecryptor 1.9.1.0. A couple of hours ago I published an interesting post the summarizes the ransomware activities in the last week, and unfortunately, this kind of malware is becoming even more popular in the criminal underground. […]

Pierluigi Paganini May 15, 2016
Week in Ransomware – Week of May 13th, 2016

Just in a week several new ransomware variants, services, and updates have been discovered in-the-wild, disclosed publicly, and thoroughly analyzed. Statistical Summary This week, in a span of just five (5) days (Monday, May 9th, 2016 – Friday, May 13th, 2016), through the collaborative efforts of several organizations and individual analysts around the globe, several […]

Pierluigi Paganini May 15, 2016
Malware used in the recent banking cyberheists is linked to Sony Pictures hack

Experts at the BAE security firms collected evidence that demonstrates the malware used in the recent cyberheists is linked to 2014 Sony Pictures hack. A second bank was a victim of a malware-based attack, the news was recently confirmed by the SWIFT. The investigation conducted by the security researchers at BAE Systems are making the situation very intriguing because […]

Pierluigi Paganini May 07, 2016
STUPID LOCKY! Hackers disrupted a Locky ransomware Campaing

Hackers have disrupted a Locky campaign after they compromised one of the cybercriminal servers used by the threat actors. According to the security expert Sven Carlsen from Avira, hackers have dismantled a Locky campaign by hacking the command and control server. Carlsen explained that threat actors behind the Locky campaign spread the threat via spam […]

Pierluigi Paganini May 06, 2016
Robin Hood CyptMix ransomware promises to donate fee to charity

This is a novelty in the cyber criminal underground, crooks behind the new born CyptMix ransomware promise to donate the fee to charity. No doubts, a very creative idea to extort money to the victims enticing them to pay for a good cause and telling them to think to have the opportunity to help the children. […]

Pierluigi Paganini May 04, 2016
The Infy malware, a long running threat from Iran

Researchers at Palo Alto Networks have come across a new threat used by alleged Iran-linked Hackers in attacks since 2007. Security experts at Palo Alto Networks discovered a new malware, named Infy, that has been likely used by hackers from Iran in cyber espionage operations at least since 2007. The researchers discovered the Infy malware […]