Threat Report Executive Summary:FortiGuard Labs has identified a sophisticated SSH backdoor, dubbed ELF/Sshdinjector.A!tr, being used by Chinese hackers attributed to the DaggerFly espionage group. This malware is part of the Lunar Peek campaign, which began in
Continue ReadingBlog
SparkCat Crypto Stealer in Google Play and App Store
Threat Report: SparkCat Crypto Stealer Published: February 5, 2025 Source: Securelist (https://securelist.com/sparkcat-stealer-in-app-store-and-google-play/115385/) Summary: In late 2024, researchers discovered a new malware campaign dubbed 'SparkCat'. This campaign targeted Android and iOS users through both official and unofficial
Continue ReadingStealers on the Rise: A Closer Look at a Growing macOS Threat
Threat Report: Stealers on the Rise Published: Feb 4, 2025 Short Description:This report examines the increasing prevalence of macOS infostealers, focusing on three prominent threats: Atomic Stealer, Poseidon Stealer, and Cthulhu Stealer. These malware variants target
Continue ReadingFrom Credit Card Skimming to Exploiting Zero-Days
Threat Report: XE Group Evolution Introduction The XE Group, a cybercriminal organization active since 2013, has evolved its tactics, techniques, and procedures (TTPs) significantly. Initially focused on web vulnerabilities and supply chain attacks, the group has
Continue ReadingAnalysis of Astral Stealer: A Comprehensive Threat Report
Threat Overview AlienVault's report on 'Astral Stealer' presents a detailed analysis of a powerful, multi-lingual malware tool designed for data theft and crypto wallet exploitation. Astral Stealer v1.8, coded in Python, C#, and JavaScript, targets gaming
Continue ReadingThreat Report: Cobalt Strike & SOCKS Proxies Lead to LockBit Ransomware
Threat Overview Microsoft Security Research has released a comprehensive analysis of an intrusion into a Windows environment, leading to the deployment of LockBit ransomware on the 11th day. The campaign demonstrates a well-resourced threat actor's ability
Continue ReadingThreat Report: Phishing Campaign Baits Hook With Malicious Amazon PDFs
Threat Overview A recent phishing campaign has emerged, employing a new tactic that uses malicious PDF files to trick victims into revealing their personal and financial information. Researchers at Palo Alto Networks Unit42 have discovered this
Continue ReadingAkira Ransomware: A Shifting Force in the RaaS Domain
Threat Overview The cyber threat landscape continues to evolve, with emerging threats posing significant risks to organizations worldwide. The Akira ransomware, first identified in late 2023, has since grown into a major concern for global cybersecurity.
Continue ReadingAlienVault Threat Report: Exposure of Trojanized XWorm RAT Builder Exploiting Cyber Enthusiasts
Threat Overview A significant cyber threat has been identified and detailed in a report published by AlienVault. The report, titled "No Honor Among Thieves: Uncovering a Trojanized XWorm RAT Builder Propagated by Threat Actors and Disrupting
Continue ReadingThreat Report: Hidden in Plain Sight – PDF Mishing Attack
Threat Overview A sophisticated phishing campaign targeting mobile devices has been discovered, hiding malicious links within PDF files using an advanced obfuscation technique. Disguised as documents from the United States Postal Service (USPS), this novel attack
Continue Reading