Search Results for: Hive

russian state-sponsored Hive0051 (aka UAC-0010, Gamaredon) Attack Detection: Adversaries Apply an Aggressive Infection Approach Leveraging Three Malware Branches
russian state-sponsored Hive0051 (aka UAC-0010, Gamaredon) Attack Detection: Adversaries Apply an Aggressive Infection Approach Leveraging Three Malware Branches

The state-sponsored russia-linked Gamaredon (aka Hive0051, UAC-0010, Armageddon APT) hacking collective comes to the spotlight launching a new wave of cyber attacks. Adversaries have been observed leveraging new iterations of Gamma malware, adopting DNS Fluxing to drop the malicious strains and leading to 1,000+ infections per day. The infection chain displays a novel, aggressive, multi-layered […]

READ MORE
Detect HiveNightmare (CVE-2021-36934) Exploitation Attempts
Detect HiveNightmare (CVE-2021-36934) Exploitation Attempts

July 2021 proceeds to be a really hot and tough month in terms of the loud cybersecurity events. While the world of cyber is still recovering from PrintNighmare vulnerability (CVE-2021-1675), Kaseya supply chain attack, and SolarWinds Serv-U zero-day (CVE-2021-35211), Windows has officially announced a new notorious flaw within its products. A recently disclosed HiveNightmare (aka […]

READ MORE
Crafty ZIP Archives Used to Deliver NanoCore RAT
Crafty ZIP Archives Used to Deliver NanoCore RAT

Delaware, USA – November 7, 2019 – Adversaries have found another way to bypass secure email gateways and antimalware solutions using specially crafted ZIP archives. Researchers from Trustwave spotted an interesting spam campaign spreading NanoCore RAT, and an analysis of the attached file revealed a new method for hiding malicious files in archives, which, however, […]

READ MORE
Over 200,000 MikroTik Routers Inject CoinHive Script in Users’ Web Traffic
Over 200,000 MikroTik Routers Inject CoinHive Script in Users’ Web Traffic

Delaware, USA – August 3, 2018 – This week in Brazil, an unknown attacker started massive cryptojacking campaign targeted MikroTik routers, quickly spreading around the world. He exploits a zero-day vulnerability in MikroTik routers patched this April to inject Coinhive cryptocurrency mining script into web pages visited by users. The attacker knows these routers well […]

READ MORE
Coinhive Injections in WordPress Sites
Coinhive Injections in WordPress Sites

Delaware, USA – October 31, 2017 – Coinhive remains the most popular platform for mining Monero cryptocurrency in user’s browsers. Despite the creation of a cryptocurrency miner modification, which allows users to control mining process in their browser and even disable it, the original version of the Coinhive JavaScript miner is actively used by attackers […]

READ MORE