malware

Pierluigi Paganini July 27, 2019
Hackers inject Magecart multi-gateway skimmer in fake Google domains

Attackers deployed a Magecart credit card skimmer script into fake Google domains used to trick visitors into making online transactions.  Experts at Sucuri discovered threat actors using fake Google domains hosting a Magento skimmer script used to steal payment data when unaware visitors make transactions. The campaign was uncovered when the owner of a website […]

Pierluigi Paganini July 27, 2019
Marcus Hutchins sentenced to supervised release, no jail for the expert

Marcus Hutchins has been sentenced to “time served” and one year of supervised release his role in developing and selling the Kronos banking malware. The popular researcher Marcus Hutchins, also known as MalwareTech, has been sentenced to “time served” and one year of supervised release his role in developing and selling the Kronos banking malware. […]

Pierluigi Paganini July 26, 2019
Johannesburg residents left in the dark after a ransomware attack at City Power

South African electric utility City Power that provides energy to the city of Johannesburg, has suffered serious disruptions after a ransomware attack. A ransomware infected systems at City Power, an electricity provider in the city of Johannesburg, South Africa, and some residents were left without power. The energy utility informed its customers via Twitter of […]

Pierluigi Paganini July 25, 2019
New variant of Linux Botnet WatchBog adds BlueKeep scanner

Experts at Intezer researchers have spotted a strain of the Linux mining that also scans the Internet for Windows RDP servers vulnerable to the Bluekeep. Researchers at Intezer have discovered a new variant of WatchBog, a Linux-based cryptocurrency mining botnet, that also includes a module to scan the Internet for Windows RDP servers vulnerable to the Bluekeep vulnerability (CVE-2019-0708). […]

Pierluigi Paganini July 25, 2019
Android Spyware Monokle, developed by Russian defense contractor, used in targeted attacks

Researchers at Lookout discovered a new mobile spyware dubbed Monokle that was developed by a Russian defense contractor. Experts at Lookout discovered a new Android mobile spyware in the wild, dubbed Monokle, that was developed by a Russian defense contractor named Special Technology Centre Ltd. (STC). “Lookout has discovered a highly targeted mobile malware threat that […]

Pierluigi Paganini July 24, 2019
Emsisoft releases the third decryptor in a few days, this time for LooCipher ransomware

Security experts at Emsisoft released the third decryptor in a few days, this time announced a free one for the LooCipher ransomware. A few days ago, the experts at Emsisoft released two free decryptors for the ZeroFucks ransomware and Ims00rry ransomware, now the malware team announced the released of a decryptor for the LooCipher ransomware. […]

Pierluigi Paganini July 24, 2019
China-Linked APT15 group is using a previously undocumented backdoor

ESET researchers reported that China-linked cyberespionage group APT15 has been using a previously undocumented backdoor for more than two years. Security researchers at ESET reported that China-linked threat actor APT15 (aka Ke3chang, Mirage, Vixen Panda, Royal APT and Playful Dragon) has been using a previously undocumented backdoor for more than two years. APT15 has been active […]

Pierluigi Paganini July 23, 2019
Experts spotted P2P worm spreading Crypto-Miners in the wild

Malware researchers at Yoroi-Cybaze Z-Lab have discovered a P2P worm that is spreading Crypto-Miners in the wild. Introduction In the past months we published a white paper exploring the risks that users can encounter when downloading materials from P2P sharing network, such as the Torrent one. We discussed how crooks easily lure their victims to download malware […]

Pierluigi Paganini July 21, 2019
Security Affairs newsletter Round 223 – News of the week

A new round of the weekly SecurityAffairs newsletter arrived! The best news of the week with Security Affairs. Kindle Edition Paper Copy Once again thank you! For nearly a year, Brazilian users have been targeted with router attacks NCSC report warns of DNS Hijacking Attacks SAP Patch Day – July 2019 addresses a critical flaw […]

Pierluigi Paganini July 18, 2019
Experts spotted a rare Linux Desktop spyware dubbed EvilGnome

Experts at Intezer discovered a new backdoor, dubbed EvilGnome, that is targeting Linux systems for cyber espionage purpose. Intezer spotted a new piece of Linux malware dubbed EvilGnome because it disguises as a Gnome extension. The researchers attribute the spyware to the Russia-linked and Gamaredon Group.  The modules used by EvilGnome are reminiscent of the Windows tools used […]