News

Ryuk Ransomware is Back Again

Delaware, USA – January 3, 2019 – The last days of the year 2018 were extremely troubled for one of the biggest US’ media group. Ryuk ransomware seriously disrupted crucial production and printing processes, so the Sunday morning was clouded for the readers of printed newspapers. A Tribune Publishing spokesperson said that websites and mobile […]

Dark Overlord Threaten to Release Files Related to 9/11 Attack

Delaware, USA – January 2, 2019 – On the eve of the New Year, the Dark Overlord group, infamous for their attacks on financial and media companies, posted on Pastebin an announcement of readiness to disclose stolen data related to the September 11 attacks. Cybercriminals shared via torrent file 10Gb of encrypted data and demanded […]

JungleSec Ransomware Infects Linux Servers through IPMI Cards

Delaware, USA – December 28, 2018 – Adversaries have found a new way to infect servers through unsecured Intelligent Platform Management Interface cards. JungleSec ransomware appeared almost two months ago, cybercriminals use it to encrypt files on systems running Linux, MacOS and Windows, and Mac demanding a ransom of 0.3 bitcoin, but many users who […]

Updated Smoke Loader Malware Spreads via Phishing Emails

Delaware, USA – December 27, 2018 – When the cybersecurity community is studying reports and making plans for the upcoming year, the criminals are still improving their weapons. The recently published investigation reveals the details of the malware attack which used a top-level domain registered by cybercriminals as a command and control server. Bulk mailing […]

One More Windows Zero-Day PoC Exploit Disclosed by SandboxEscaper

Delaware, USA – December 21, 2018 – New exploit allows reading data from specific locations with system level access. SandboxEscaper publishes the third exploit in the last few months, previous exploits were quickly weaponized by cybercriminals and actively used even after Microsoft released security updates. The first exploit led to a local privilege escalation enabling […]

APT33 Attacks Organizations Using Shamoon and Filerase Wipers

Delaware, USA – December 20, 2018 – The investigation of recent attacks on the oil and gas industry in the Middle East revealed that the Iranian group APT33 is behind this operation. The attackers have been preparing for the campaign for at least several months, collecting credentials of companies employees using phishing sites with job […]

Fancy Bear Creates New Variant of Zebrocy Malware

Delaware, USA – December 19, 2018 – This month, researchers from Palo Alto discovered a new version of Zebrocy malware written using the Go programming language. It was used in a cyber-espionage campaign, which experts associate with attacks of the Fancy Bear group (aka APT28) targeted government organizations in North America and Europe. The first […]

L0rdix Malware Available on DarkNet Forums

Delaware, USA – December 18, 2018 – Multifunctional malware for Windows, discovered last month, is actively advertised on underground forums and is available to anyone for as little as $60. For the first time, L0rdix was spotted by Ben Hunter, the security researcher from enSilo. He analyzed several samples and reported that its authors continue […]

New Trojan Receives Instructions via Twitter

Delaware, USA – December 17, 2018 – Adversaries use steganography to hide commands in malicious memes posted on Twitter. Researchers from TrendMicro discovered a new malware strain that downloads images from a specific Twitter account to extract the command that starts with the ‘/’ character. The trojan is capable of making screenshots, retrieving username and […]

Shamoon Malware Attacks Saipem’s Network

Delaware, USA – December 14, 2018 – The details on the cyber attack targeted Saipem, which happened last weekend, have become known. The data-wiping attack on the Italian oil and gas company mainly affected servers in the Middle East, but it also made inoperative assets in Italy, India and Scotland. Undefined cybercriminals used a new […]