cyber espionage

Pierluigi Paganini January 31, 2017
Gaza Cybergang is back and is targeting Governments under DustySky campaign

Security experts at PaloAlto Networks have observed a new campaign that has been launched by a cyber espionage group known as Gaza Cybergang. Security experts at Palo Alto Networks have uncovered a new cyber espionage campaign conducted by the Gaza Cybergang hacker group, also known as “Gaza Hackers Team” and “Molerats.” On September 2015, security experts at Kaspersky Lab observed an increase […]

Pierluigi Paganini January 24, 2017
Symantec speculates Shamoon 2 attacks aided by Greenbug hackers

Security researchers at Symantec believed that Shamoon 2 attacks leveraged credentials stolen by hackers of the Greenbug group. A few days ago security experts at Palo Alto Networks have spotted a new strain of the Shamoon 2 malware that was targeting virtualization products. In December malware researchers from Palo Alto Networks and Symantec discovered a new variant of Shamoon, so-called […]

Pierluigi Paganini January 19, 2017
Quimitchin, a Mac backdoor that includes antiquated code

Researchers at Malwarebytes have discovered the first Mac malware of 2017, dubbed Quimitchin, that was used against  biomedical research institutions. Security experts have spotted the first Mac malware of 2017, dubbed Quimitchin,  and it is considered a malicious code not particularly sophisticated and includes some antiquated code. According to the researchers from Malwarebytes, the code has […]

Pierluigi Paganini January 10, 2017
A Second variant of Shamoon 2 targets virtualization products

A second variant of the Shamoon 2 malware was discovered by researchers at Palo Alto Networks, this threat also targets virtualization products. A new strain of the Shamoon 2 malware was spotted by the security experts at Palo Alto Networks, this variant targets virtualization products. Shamoon, also known as Disttrack, was first spotted in a wave of attacks that targeted […]

Pierluigi Paganini January 06, 2017
MM Core APT malware is back, Forcepoint has detected 2 new versions

Forcepoint has detected two new versions of an advanced persistent threat (APT) malware dubbed MM Core APT and first discovered in 2013. The APT MM Core malware has been in the wild since April 2013 when it was spotted for the first time by experts at FireEye. The malware researchers dubbed the first release of the […]

Pierluigi Paganini January 02, 2017
Trump will soon reveal the truth about the alleged Russian hacking

President Donald J. Trump is expressing skepticism about intelligence assessments of the Russian hacking and will provide more information very soon. The executive order issued by President Obama in retaliation of the alleged Russian interference on Presidential Election is raising a heated debate on the on the measures adopted by the US Government and its ability […]

Pierluigi Paganini December 31, 2016
Alleged Russian operation has compromised a laptop at a Vermont utility

The code associated with Russian hacking operation dubbed Grizzly Steppe by the Obama administration infected a laptop at a Vermont utility. Russian hackers are again in the headlines because according to US officials, they hacked a Vermont utility, raising concerns about the security of the electrical grid of the country. Researchers discovered on a laptop a […]

Pierluigi Paganini December 30, 2016
President Obama executive order ejected 35 Russians out of US

An executive order issued by President Obama applies sanctions on Russian military and intelligence officials. 35 Russian operatives were ejected. President Barack Obama issued an executive order to impose sanctions on a number of Russian military and intelligence officials in response to the alleged hacking campaigns against the 2016 US Presidential Election. The US ejected 35 Russian intelligence […]

Pierluigi Paganini December 16, 2016
PROMETHIUM and NEODYMIUM APTs used same Zero-Day to Target Turkish citizens

Microsoft discovered two distinct APT groups, PROMETHIUM and NEODYMIUM, that exploited the same Flash Player zero-day flaw on same targets. Security researchers have discovered two distinct APT groups, PROMETHIUM and NEODYMIUM, that exploited the same Flash Player zero-day vulnerability (CVE-2016-4117) in cyber espionage campaigns on Turkish citizens living in Turkey and various other European countries. Both […]

Pierluigi Paganini December 11, 2016
Georgia traced an attempted breach of voter registration database to DHS

Georgia’s secretary of state, Brian Kemp, revealed that voter registration database was targeted by hackers with IP address linked to the DHS. While President Barack Obama has ordered US intelligence agencies to deeper investigate the alleged Russian interference with the 2016 Presidential Election, Georgia announced it’s traced an attempted breach of the state’s voter registration database to the DHS. […]