There has been a spike in email campaigns using HTML smuggling to deploy banking Trojans, RATs, and ransomware. Attackers use this technique to build malware on a device via the browser instead of passing payloads directly through the network. Details: https://t.co/wNmjXRX9Pe
We recently discovered the latest variant of a Mac malware tracked as UpdateAgent (aka WizardUpdate) with new persistence and evasion tactics, the latest in a series of upgrades over the past year. Given its history, this Trojan will likely continue to grow in sophistication.
Microsoft has released information on a widespread malicious email campaign carried out by a cyber actor they identify as NOBELIUM. See https://t.co/JFuPkqCp15 #Cybersecurity#InfoSec
In the past few months, Microsoft has been tracking a dynamic campaign targeting the aerospace and travel sectors with spear-phishing emails that distribute an actively developed loader, which then delivers RevengeRAT or AsyncRAT.
We’re tracking an active credential phishing attack targeting enterprises that uses multiple sophisticated methods for defense evasion and social engineering. The campaign uses timely lures relevant to remote work, like password updates, conferencing info, helpdesk tickets, etc.
Thread: High performance computing labs are currently reporting breaches. Malicious ELF64 binaries are being placed under /𝚎𝚝𝚌/𝚏𝚘𝚗𝚝𝚜/.𝚏𝚘𝚗𝚝𝚜 (suid-root loader) and /𝚎𝚝𝚌/𝚏𝚘𝚗𝚝𝚜/.𝚕𝚘𝚠 (log cleaner). Germany seems to be impacted the most with several victims.
@AkbarTravelsIN Hi, I have booking with AI 177 - pnr JRV4H flight to London on 24 March. Is this flight cancelled? Will you book me to other flight/day or will you refund please?