News

Roaming Mantis Greatly Increased the Number of Targeted Countries

Delaware, USA – May 21, 2018 – Roaming Mantis banking trojan now contains 27 languages ​​for attacks on users from Europe and the Middle East. Also, attackers created a phishing page to attack owners of iOS devices. Experts from Kaspersky Lab published a study in which they examined all the changes in the trojan over […]

WinstarNssmMiner Crashes the System When You Try to Remove It

Delaware, USA – May 18, 2018 – This week, researchers from 360 Total Security discovered the campaign distributing new cryptocurrency mining malware. WinstarNssmMiner attacked more than 500,000 systems in three days. After getting into a system, malware scans it for specific antivirus tools installed, if any of them is detected, it quits automatically. If no […]

New Dharma Ransomware Samples Spotted in the Wild

Delaware, USA – May 17, 2018 – A new version of Dharma ransomware was discovered on May 15 by researcher Michael Gillespie. The strain adds .bip extension to the files and generates two ransom notes. The appearance of new ransomware variant may indicate the preparation of the next malicious campaign. Dharma can be distributed both […]

Fresh Zero-Day in Adobe Acrobat and Reader Patched This Monday

Delaware, USA – May 16, 2018 – At the end of March researchers from ESET discovered a malicious PDF document that exploited two zero-day vulnerabilities: CVE-2018-4990 in Adobe Acrobat and Reader, and CVE-2018-8120 in Windows 7 and Windows Server 2008. This exploit chain leads to arbitrary code execution with high privileges on the attacked system. […]

RIG Exploit Kit is Still Alive

Delaware, USA – May 15, 2018 – Despite the fact that since 2016 the active use of exploit kits is on the wane, attackers continue to leverage them for delivery of malware. Experts from FireEye published a research in which they analyzed recent attacks using RIG to deliver Grobios trojan. The attacks follow a standard […]

Panda Banking Trojan Targeted North America and Japan

Delaware, USA – May 14, 2018 – Panda banking trojan was created two years ago based on the code of the infamous Zeus trojan, and it is actively used in attacks on financial organizations across the globe. This month Researchers from F5 discovered several campaigns spreading this trojan, they think all these attacks were conducted […]

Attackers Exploit DLL Hijacking to Bypass SmartScreen

Delaware, USA – May 11, 2018 – DLL Hijacking technique has long been known remaining effective enough to bypass some of the security solutions, so attackers used it in new malware. ElvenPath analyzed banking trojan N40, used in a recent campaign against Chilean banks. This malware is the evolved Brazilian banking trojan used in attacks […]

BaseStriker Zero-Day Exploited in the Wild

Delaware, USA – May 10, 2018 – New zero-day vulnerability in Office 365 allows adversaries to bypass Microsoft’s security, including advanced security services. Researchers from Avanan published a report in which they described BaseStriker zero-day and noted that they detected its use in phishing attacks. BaseStriker vulnerability also can be used to distribute various malware. […]

SynAck Ransomware Uses New Code Injection Technique

Delaware, USA – May 8, 2018 – SynAck Ransomware uses a new sophisticated code injection technique to mask malicious processes and avoid detection by antivirus solutions. Researchers from Kaspersky Lab discovered highly targeted attacks on organizations in the US, Germany, Iran and Kuwait. SynAck was first seen in early August 2017 and for several months […]

Chinese hacker groups attack IT companies in the US, Japan and South Korea

Delaware, USA – May 7, 2018 – Last week, security researchers from ProtectWise 401TRG published a report about cyber attacks and campaigns of Chinese hacker groups. Analysis of the infrastructure and targets of the attackers’ operations makes it possible to state with high confidence that some of the previously considered independent cyberespionage groups work together […]