@HuntressLabs
A Google AD is serving a malicious WinSCP Python installer, resulting in rapid lateral movement 🧵
1. Google AD -> gaweeweb[.]com -> winccp[.]net
2023-10-12 (Thursday): The latest example of #DarkGate malware distributed through Microsoft Teams. Attacker poses as target organization's CEO and sends victim a Teams invite. Message contains password-protected zip archive. IOCs available at https://t.co/Eq58fmW5G3
We are hiring! Our SE team have a number of roles across multiple regions. For more information and the opportunity to work with @arnlopez please visit: https://t.co/x9klT6lfos @McAfee_Business #infosec#infosecjobs
A North Korean cyber-espionage group breached one of the most popular North Korean-themed news sites on the internet in order to carry out a watering hole attack and infect some of the site’s visitors with malware https://t.co/dKT9E05d3X
REvil #ransomware Linux variant spotted, encrypts *nux systems and ESXi. We created a demo: https://t.co/OtU0GBE3WL hash: ea1872b2835128e3cb49a0bc27e4727ca33c4e6eba1e80422db19b505f965bc4 H/T @Glacius_@McAfee_Labs#DFIR
Gamer alert! @nvidia bugs allow privilege-escalation attacks, arbitrary code execution, denial of service (DoS) and information disclosure-- YIKES https://t.co/0CyUjcKBPG #patchoftheday#CyberSecurity
Prevalence for the China Chopper web shells reveals recent activity targeting nine countries, including US, UK, France, Canada. Details and updated IoCs here: https://t.co/3S7zMyPeHN #cybersecurity#infosec#malware