Month: August 2018

Microsoft Patches Two Zero-Days in Windows

Delaware, USA ā€“ August 15, 2018 ā€“ Yesterday Microsoft released security updates patching 60 vulnerabilities in their products, among which there were two zero-days actively exploiting in the wild. The security flaw in the Internet Explorer scripting engine (CVE-2018-8373) allows attackers to execute code remotely. Attackers can exploit CVE-2018-8373 both when users visit a malicious […]

Read More
D-Link Routers Redirect Users to Malicious Websites

Delaware, USA ā€“ August 14, 2018 ā€“ Hackers compromise D-Link DSL routers in Brazil and change the DNS settings so that devices connect to attackers’ DNS servers. This scheme allows attackers to redirect targeted users to phishing websites, practically indistinguishable from real ones. The only visible difference is the browser marks pages as insecure so […]

Read More
DarkHydrus Prepares to Attack Government Entities in the Middle East

Delaware, USA ā€“ August 10, 2018 ā€“ One more hacker group targets government organizations in the Middle East. Palo Alto Networks Unit42 revealed one of DarkHydrus campaigns and tracked their activity until 2016. DarkHydrus leverages spear phishing attacks using documents created with the open-source Phishery tool. Such documents allow them to steal user credentials and […]

Read More
Gorgon Group Uses Wide Variety of Trojans in Their Campaigns

Delaware, USA ā€“ August 9, 2018 ā€“ Experts from Palo Alto Networks discovered a new Pakistani threat actor, which they called the Gorgon Group. The group has been active since February 2018, but the activities of its members were tracked until 2016. Gorgon Group conducts both criminal attacks and targeted attacks using the same infrastructure. […]

Read More
Over 200,000 MikroTik Routers Inject CoinHive Script in Users’ Web Traffic

Delaware, USA ā€“ August 3, 2018 ā€“ This week in Brazil, an unknown attacker started massive cryptojacking campaign targeted MikroTik routers, quickly spreading around the world. He exploits a zero-day vulnerability in MikroTik routers patched this April to inject Coinhive cryptocurrency mining script into web pages visited by users. The attacker knows these routers well […]

Read More
PowerGhost Miner Attacks Corporate Networks

Delaware, USA ā€“ August 2, 2018 ā€“ Researchers from Kaspersky Lab discovered a new PowerGhost cryptocurrency miner, which attacks networks of organizations worldwide. Attackers use several fileless infection techniques to prevent detection by antivirus solutions. The initial system is infected remotely either by remote administration tools or by using exploits. Researchers from Sonicwall Capture Labs […]

Read More
BitPaymer Ransomware Paralyzes IT Systems of the Alaskan Town

Delaware, USA ā€“ August 1, 2018 ā€“ Another Ransomware attack practically froze the Matanuska-Susitna borough. The incident occurred on Tuesday, July 24, and the network did not fully recover so far. Attackers used BitPaymer Ransomware to encrypt 500 computers and 120 servers connected to government networks. According to official representatives of the Borough, no sensitive […]

Read More