News

Turla APT Uses Outlook Backdoor in Cyberespionage Operations

Delaware, USA – August 23, 2018 – Turla APT group created a unique Outlook backdoor and used it to spy on at least two European government foreign offices and one defense contractor. The APT group operates since 2008 using Gazer backdoor in cyberespionage campaigns targeted government and diplomatic bodies in Europe, Asia and South America. […]

Dark Tequila Malware Operates Since 2013

Delaware, USA – August 22, 2018 – Dark Tequila is a sophisticated modular banking malware targeted at users from Mexico that remained undetected for about five years. Researchers from Kaspersky Lab discovered and analyzed the ongoing malicious campaign. Dark Tequila is designed to steal financial information and credentials to online banking and popular websites including […]

Ryuk Ransomware Campaign Targets Enterprises Worldwide

Delaware, USA – August 21, 2018 – Researchers from Checkpoint analyzed the ongoing ransomware campaign targeted enterprises worldwide. During the campaign, attackers infect critical infrastructure of large companies with the Ryuk ransomware and demand a significant amount of ransom in bitcoins. At the moment, it is known about three affected companies that paid the ransom […]

Darkhotel Group Uses Zero-Day in Recent Campaign

Delaware, USA – August 20, 2018 – Last week experts from Trend Micro published details of the exploitation of zero-day vulnerability CVE-2018-8373, which was fixed as part of August Patch Tuesday. This vulnerability in the VBScript engine allows attackers to execute arbitrary code on the victim’s system. On July 11, researchers discovered the first attacks using […]

Hackers Steal $13.4 Million from Cosmos Bank

Delaware, USA – August 16, 2018 – Last weekend, unknown adversaries withdrew from Indian bank Cosmos 940 million rupees (more than $13 million) in three stages. The investigation of the incident continues, and the bank reports that the funds on the clients’ accounts were not affected. The first stage of the attack on Cosmos bank […]

Microsoft Patches Two Zero-Days in Windows

Delaware, USA – August 15, 2018 – Yesterday Microsoft released security updates patching 60 vulnerabilities in their products, among which there were two zero-days actively exploiting in the wild. The security flaw in the Internet Explorer scripting engine (CVE-2018-8373) allows attackers to execute code remotely. Attackers can exploit CVE-2018-8373 both when users visit a malicious […]

D-Link Routers Redirect Users to Malicious Websites

Delaware, USA – August 14, 2018 – Hackers compromise D-Link DSL routers in Brazil and change the DNS settings so that devices connect to attackers’ DNS servers. This scheme allows attackers to redirect targeted users to phishing websites, practically indistinguishable from real ones. The only visible difference is the browser marks pages as insecure so […]

DarkHydrus Prepares to Attack Government Entities in the Middle East

Delaware, USA – August 10, 2018 – One more hacker group targets government organizations in the Middle East. Palo Alto Networks Unit42 revealed one of DarkHydrus campaigns and tracked their activity until 2016. DarkHydrus leverages spear phishing attacks using documents created with the open-source Phishery tool. Such documents allow them to steal user credentials and […]

Gorgon Group Uses Wide Variety of Trojans in Their Campaigns

Delaware, USA – August 9, 2018 – Experts from Palo Alto Networks discovered a new Pakistani threat actor, which they called the Gorgon Group. The group has been active since February 2018, but the activities of its members were tracked until 2016. Gorgon Group conducts both criminal attacks and targeted attacks using the same infrastructure. […]

Over 200,000 MikroTik Routers Inject CoinHive Script in Users’ Web Traffic

Delaware, USA – August 3, 2018 – This week in Brazil, an unknown attacker started massive cryptojacking campaign targeted MikroTik routers, quickly spreading around the world. He exploits a zero-day vulnerability in MikroTik routers patched this April to inject Coinhive cryptocurrency mining script into web pages visited by users. The attacker knows these routers well […]