malware

Pierluigi Paganini November 05, 2015
Trojanized adware: already infected more than 20,000 Android Apps

Researchers at Lookout firm have come across a new malicious adware family distributed via trojanized versions of popular Android applications. Researchers at mobile security firm Lookout have come across a new malicious adware family distributed via trojanized versions of popular Android applications. Security experts at Lookout have discovered a new strain of adware dubbed Shuanet, which is distributed via […]

Pierluigi Paganini November 04, 2015
CryptoWall 4.0 Released with a New Look and Several New Features

The fourth member of the CryptoWall family of ransomware, CryptoWall 4.0, has just been released, complete with new features and a brand new look. We recently reported that CryptoWall 3.0 has allegedly caused over $325 million in annual damages. CryptoWall first emerged in April 2014. Its first major upgrade was dubbed CryptoWall 2.0, and first emerged in October […]

Pierluigi Paganini November 04, 2015
GovRAT, the malware-signing-as-a-service platform in the underground

Security Experts at InfoArmor discovered GovRAT, a malware-signing-as-a-service platform that is offered to APT groups in the underground. In the past, I have explained why digital certificates are so attractive for crooks and intelligence agencies, one of the most interesting uses is the signature of malware code in order to fool antivirus. Naturally, digital certificates […]

Pierluigi Paganini November 03, 2015
Chimera, a new strain of ransomware in the wild

According to a German website, there is a new strain of ransomware dubbed Chimera that also threatens to publish personal data on the Internet. A new strain of ransomware is targeting German companies, it is named Chimera and this time crooks don’t limit their extortion scheme to the file encrypting, they are also threatening victims […]

Pierluigi Paganini October 31, 2015
How CoinVault or Bitcryptor victims could try to recover their files

Victims of CoinVault ransomware can now rely on a new set of encryption keys added to the free CoinVault Ransomware Decryptor tool to recover their files. Every day, dozens of users ask me how to decrypt their data locked by various ransomware such as CoinVault or Bitcryptor? Now I have a good news for them, […]

Pierluigi Paganini October 29, 2015
Chikdos cross-platform DDoS botnet hit SQL servers worldwide

Experts at Symantec have discovered a new variant of  the Chikdos DDoS-Trojan that is targeting MySQL servers worldwide. There is a malware in the wild that abuses MySQL Servers for DDoS Attacks, the experts named it Chikdos. The threat was detected for the first time by the Polland CERT and according to the experts it has […]

Pierluigi Paganini October 27, 2015
Dridex Botnets are still active and effective

The Dridex Banking Trojan has risen again despite the recent operation conducted by law enforcement on a global scale. Spam campaign relying on the Dridex malware continues to threaten banking users across the world despite the operations conducted by law enforcement on a global scale. We left Dridex malware spreading across the Europe, in particular targeting […]

Pierluigi Paganini October 27, 2015
Duuzer, a data stealer Trojan targets South Korean organizations

Researchers at Symantec uncovered bad actors that have been using a backdoor Trojan dubbed Duuzer to target organizations in South Korea and elsewhere. According to Symantec, threat actors have been using a data stealer Trojan dubbed Duuzer to target organizations mainly located in South Korea. The bad actors conducted targeted attacks against organizations in the manufacturing […]

Pierluigi Paganini October 23, 2015
Pawn Storm APT targets MH17 crash investigation

The Pawn Storm APT group set up rogue VPN and SFTP servers to target Dutch Safety Board employees involved in the MH17 crash investigation. July 17, 2014, Flight MH17, traveling from Amsterdam to Kuala Lumpur, was shot down by a missile in mysterious circumstances. Flight MH17 was flying over a conflict zone in eastern Ukraine […]

Pierluigi Paganini October 20, 2015
eFast browser deletes and replaces your Chrome Browser

Security researchers have documented the existence of a new strain of malware dubbed eFast browser that deletes and replaces the entire Chrome Browser. Security experts from Malwarebytes have analyzed a new strain of  malware that attempts to delete Chrome and replace it with a bogus version that allows attackers to hijack several file associations including HTML, […]