@TheEnergyStory@artem_i_baranov Are these vendors planning a publication?
Regarding the described APT, could you provide a few more general details to better assess the value of the discovery? What regions\countries were affected by this company? What is the expected general attribution? Who might be behind?
Together with @bzvr_, @2igosha and Anton Kargin, we identified that the DAEMON Tools software has been compromised in a complex supply chain attack since April 8. We see thousands of infections across 100+ countries. If you use DAEMON Tools, run a malware scan immediately! [1/7]
Heartbroken to hear about the passing of @Skvern0. He was one of the best threat hunters in the industry - even APTs were afraid of him. I’m grateful for the time we worked together and for everything I learned from him. Rest in peace.
It turned out there are many more payloads used in the Notepad++ attack! To stay undetected, its masterminds were COMPLETELY changing execution chains about every month.
Here are more IPs used in the attack:
45.76.155[.]202
45.32.144[.]255
Read below for many other IoCs! [1/8]
🚀 If you plan to join @kaspersky#CTF and want advice from a seasoned player, check out the webinar recording from yesterday! @bzvr_, one of the CTF organizers, shares the basics and practical examples to help you win in Kaspersky{CTF}.
🌴 Winners of the five regional competitions will receive a complimentary #TheSAS2025 invitation to the CTF finals!
The webinar recording is available without registration: https://t.co/XAYhFxYr8n
#CFP extended — your last chance to rock the floor at #TheSAS2025!
Just 10 days left to propose your research for the BIG stage and share your findings with peers from world-class cybersecurity organizations.
If you research:
▪️ Transportation and smart city vulnerabilities
▪️ New tactics and tricks from notorious #APTs
▪️ Ransomware
▪️ Best incident response practices
▪️ Supply chain and #OSS security
▪️ OT and critical infrastructure security
▪️ Vulnerabilities and fixes
then our program committee is waiting for you!
⚠️ Submit your topic by August 10th
⏩ https://t.co/41ZlbIcJa1
🚨 Less than 10 days until the SAS CTF 2025 Quals kick off! 🚨
Register your team now and claim the spot in the top 8 to compete for a share of the $18,000 prize pot at the on-site finals at the SAS conference in Thailand.
Register: https://t.co/kfN9zsozyd
⚡ We discovered a malicious campaign distributing a #SilentCryptoMiner disguised as a restriction bypass tool. Attackers, who pose as tool developers, blackmail YouTubers creating videos about bypassing blocks. Threatened with copyright strikes, content creators were being pressured to share a malicious link to an infected archive.
#Malware #Miner #YouTube
🧵 Check more details below…
Malware developers don't necessarily have to invent something innovative to earn lots of money. Check out how this actor managed to steal almost $485,000 with the help of a dozen GitHub accounts, AI, and a bit of luck: https://t.co/RrMBrFwWL9
EAGERBEE backdoor has been used in targeted attacks in APAC region. We (myself and @vaber_b) released a blog post about its recent activity in Middle East region, where it was being deployed at ISP and governmental entities in Middle East.
https://t.co/KogIlqwkgU
My first #Lazarus report at #Kaspersky is out ! The newly discovered #CookiePlus is a plugin-based malware that has the ability to download both DLL and shellcode.
It was a great experience working with great coworkers and learning a lot.
https://t.co/Nbn1bWu3DB
Such an amazing pleasure to share the investigation I made with my colleague @kucher1n about #careto
The paper it's public already: https://t.co/3img11n9BS
and the post for securelist is here: https://t.co/wATMxqqibx @kaspersky
Feel free to also see the presentation at @virusbtn https://t.co/NgpxwKRzJL
🚨 We discovered two malicious Python packages in #PyPI repository that remained undetected for over a year. These packages mimicked tools for working with popular AI language models (#ChatGPT and #Claude), silently exfiltrating data and compromising developer environments.
Full details and IOCs in the thread 👇