#threatlabz — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #threatlabz, aggregated by home.social.
-
TELESHIM malware hits Middle East governments and abuses Telegram C2 to hide traffic. Zscaler ThreatLabz found the new backdoor and its tooling.
#TELESHIM #Malware #TelegramC2 #Cybersecurity #ThreatLabz #MiddleEast
-
TELESHIM malware hits Middle East governments and abuses Telegram C2 to hide traffic. Zscaler ThreatLabz found the new backdoor and its tooling.
#TELESHIM #Malware #TelegramC2 #Cybersecurity #ThreatLabz #MiddleEast
-
Indirect prompt injection exploits AI agent vulnerabilities through malicious web content. Attackers manipulate language models using hidden instructions.
-
Indirect prompt injection exploits AI agent vulnerabilities through malicious web content. Attackers manipulate language models using hidden instructions.
-
Indirect prompt injection exploits AI agent vulnerabilities through malicious web content. Attackers manipulate language models using hidden instructions.
-
Indirect prompt injection exploits AI agent vulnerabilities through malicious web content. Attackers manipulate language models using hidden instructions.
-
Zscaler ThreatLabz 2024 Ransomware Report shows attacks surged year-over-year, with the manufacturing sector being targeted most frequently https://www.admin-magazine.com/News/Ransomware-Report-Shows-Increase-in-Attacks
#security #ransomware #manufacturing #healthcare #education #FinancialServices #ThreatLabz #vulnerability #zscaler -
Zscaler ThreatLabz 2024 Ransomware Report shows attacks surged year-over-year, with the manufacturing sector being targeted most frequently https://www.admin-magazine.com/News/Ransomware-Report-Shows-Increase-in-Attacks
#security #ransomware #manufacturing #healthcare #education #FinancialServices #ThreatLabz #vulnerability #zscaler -
Zscaler ThreatLabz 2024 Ransomware Report shows attacks surged year-over-year, with the manufacturing sector being targeted most frequently https://www.admin-magazine.com/News/Ransomware-Report-Shows-Increase-in-Attacks
#security #ransomware #manufacturing #healthcare #education #FinancialServices #ThreatLabz #vulnerability #zscaler -
Zscaler ThreatLabz 2024 Ransomware Report shows attacks surged year-over-year, with the manufacturing sector being targeted most frequently https://www.admin-magazine.com/News/Ransomware-Report-Shows-Increase-in-Attacks
#security #ransomware #manufacturing #healthcare #education #FinancialServices #ThreatLabz #vulnerability #zscaler -
Zscaler ThreatLabz 2024 Ransomware Report shows attacks surged year-over-year, with the manufacturing sector being targeted most frequently https://www.admin-magazine.com/News/Ransomware-Report-Shows-Increase-in-Attacks
#security #ransomware #manufacturing #healthcare #education #FinancialServices #ThreatLabz #vulnerability #zscaler -
Low-Drama ‘Dark Angels’ Reap Record Ransoms
https://krebsonsecurity.com/2024/08/low-drama-dark-angels-reap-record-ransoms/
#AmerisourceBergenCorporation #BleepingComputer #BrettStone-Gross #ALittleSunshine #DataBreaches #DunghillLeak #Ransomware #DarkAngels #ransomware #ThreatLabz #Cencora #Zscaler #sophos #Sabre #Sysco
-
Low-Drama ‘Dark Angels’ Reap Record Ransoms
https://krebsonsecurity.com/2024/08/low-drama-dark-angels-reap-record-ransoms/
#AmerisourceBergenCorporation #BleepingComputer #BrettStone-Gross #ALittleSunshine #DataBreaches #DunghillLeak #Ransomware #DarkAngels #ransomware #ThreatLabz #Cencora #Zscaler #sophos #Sabre #Sysco
-
Low-Drama ‘Dark Angels’ Reap Record Ransoms
https://krebsonsecurity.com/2024/08/low-drama-dark-angels-reap-record-ransoms/
#AmerisourceBergenCorporation #BleepingComputer #BrettStone-Gross #ALittleSunshine #DataBreaches #DunghillLeak #Ransomware #DarkAngels #ransomware #ThreatLabz #Cencora #Zscaler #sophos #Sabre #Sysco
-
Low-Drama ‘Dark Angels’ Reap Record Ransoms
https://krebsonsecurity.com/2024/08/low-drama-dark-angels-reap-record-ransoms/
#AmerisourceBergenCorporation #BleepingComputer #BrettStone-Gross #ALittleSunshine #DataBreaches #DunghillLeak #Ransomware #DarkAngels #ransomware #ThreatLabz #Cencora #Zscaler #sophos #Sabre #Sysco
-
Low-Drama ‘Dark Angels’ Reap Record Ransoms
https://krebsonsecurity.com/2024/08/low-drama-dark-angels-reap-record-ransoms/
#AmerisourceBergenCorporation #BleepingComputer #BrettStone-Gross #ALittleSunshine #DataBreaches #DunghillLeak #Ransomware #DarkAngels #ransomware #ThreatLabz #Cencora #Zscaler #sophos #Sabre #Sysco
-
Low-Drama ‘Dark Angels’ Reap Record Ransoms https://krebsonsecurity.com/2024/08/low-drama-dark-angels-reap-record-ransoms/ #AmerisourceBergenCorporation #BleepingComputer #ALittleSunshine #BrettStoneGross #DataBreaches #DunghillLeak #Ransomware #DarkAngels #ransomware #ThreatLabz #Cencora #Zscaler #sophos #Sabre #Sysco
-
Low-Drama ‘Dark Angels’ Reap Record Ransoms https://krebsonsecurity.com/2024/08/low-drama-dark-angels-reap-record-ransoms/ #AmerisourceBergenCorporation #BleepingComputer #ALittleSunshine #BrettStoneGross #DataBreaches #DunghillLeak #Ransomware #DarkAngels #ransomware #ThreatLabz #Cencora #Zscaler #sophos #Sabre #Sysco
-
Low-Drama ‘Dark Angels’ Reap Record Ransoms https://krebsonsecurity.com/2024/08/low-drama-dark-angels-reap-record-ransoms/ #AmerisourceBergenCorporation #BleepingComputer #ALittleSunshine #BrettStoneGross #DataBreaches #DunghillLeak #Ransomware #DarkAngels #ransomware #ThreatLabz #Cencora #Zscaler #sophos #Sabre #Sysco
-
Low-Drama ‘Dark Angels’ Reap Record Ransoms https://krebsonsecurity.com/2024/08/low-drama-dark-angels-reap-record-ransoms/ #AmerisourceBergenCorporation #BleepingComputer #ALittleSunshine #BrettStoneGross #DataBreaches #DunghillLeak #Ransomware #DarkAngels #ransomware #ThreatLabz #Cencora #Zscaler #sophos #Sabre #Sysco
-
DreamBus Unleashes Metabase Mayhem With New Exploit Module
Zscaler’s ThreatLabz research team has been tracking the Linux-based malware family known as DreamBus. Not much has changed in the last few years other than minor bug fixes, and slight modifications to evade detection from security software. However, in the last 6 months, the threat actor operating DreamBus has introduced two new modules to target vulnerabilities in Metabase and Apache RocketMQ. This is likely in response to a decrease in new infections stemming from exploits utilized by DreamBus, many of which are dated and have been in use for several years. DreamBus also continues to use techniques that exploit implicit trust and weak passwords including Secure Shell (SSH), IT administration tools, cloud-based applications, and databases. The primary monetization vector for DreamBus infections is still through mining Monero cryptocurrency.
Pulse ID: 65a11e3746e6adfeb24af445
Pulse Link: https://otx.alienvault.com/pulse/65a11e3746e6adfeb24af445
Pulse Author: AlienVault
Created: 2024-01-12 11:10:47Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#OTX #OpenThreatExchange #InfoSec #bot #CyberSecurity #Malware #Linux #SSH #RAT #Apache #Opera #cryptocurrency #Cloud #Word #Passwords #Password #ThreatLabz #Rust #Zscaler #AlienVault
-
"🐰 BunnyLoader Unleashed: The Newest Kid on the Malware Block 🐰"
In a recent discovery, Zscaler ThreatLabz stumbled upon a new Malware-as-a-Service (MaaS) threat named "BunnyLoader" being peddled on various forums. This nefarious service offers a plethora of malicious functionalities including downloading and executing a second-stage payload, pilfering browser credentials and system information, keylogging, and even cryptocurrency theft through clipboard manipulation. 🕵️♀️💻
The malware, written in C/C++, is sold for a lifetime price of $250 and is under rapid development with multiple feature updates and bug fixes. It employs various anti-sandbox techniques during its attack sequence to evade detection and has a fileless loader feature which executes further malware stages in memory. BunnyLoader's C2 panel allows the threat actor to control infected machines remotely, showcasing a list of various tasks including keylogging, credential theft, and remote command execution among others. 🛑🔐
The detailed technical analysis reveals how BunnyLoader maintains persistence, performs anti-VM techniques, registers with the C2 server, and executes its core malicious tasks. The malware also harbors a clipper module to replace cryptocurrency addresses in a victim's clipboard with addresses controlled by the threat actor, targeting multiple cryptocurrencies like Bitcoin, Ethereum, and Monero. 🪙💸
The article is a comprehensive dive into the technical intricacies of BunnyLoader, shedding light on its modus operandi and the potential threat it poses to individuals and organizations alike. 🧐🔍
Source: Zscaler ThreatLabz
Tags: #BunnyLoader #MalwareAsAService #CyberSecurity #ThreatAnalysis #Malware #CryptocurrencyTheft #Zscaler #ThreatLabz #InfoSec
Authors: NIRAJ SHIVTARKAR, SATYAM SINGH
-
"🐰 BunnyLoader Unleashed: The Newest Kid on the Malware Block 🐰"
In a recent discovery, Zscaler ThreatLabz stumbled upon a new Malware-as-a-Service (MaaS) threat named "BunnyLoader" being peddled on various forums. This nefarious service offers a plethora of malicious functionalities including downloading and executing a second-stage payload, pilfering browser credentials and system information, keylogging, and even cryptocurrency theft through clipboard manipulation. 🕵️♀️💻
The malware, written in C/C++, is sold for a lifetime price of $250 and is under rapid development with multiple feature updates and bug fixes. It employs various anti-sandbox techniques during its attack sequence to evade detection and has a fileless loader feature which executes further malware stages in memory. BunnyLoader's C2 panel allows the threat actor to control infected machines remotely, showcasing a list of various tasks including keylogging, credential theft, and remote command execution among others. 🛑🔐
The detailed technical analysis reveals how BunnyLoader maintains persistence, performs anti-VM techniques, registers with the C2 server, and executes its core malicious tasks. The malware also harbors a clipper module to replace cryptocurrency addresses in a victim's clipboard with addresses controlled by the threat actor, targeting multiple cryptocurrencies like Bitcoin, Ethereum, and Monero. 🪙💸
The article is a comprehensive dive into the technical intricacies of BunnyLoader, shedding light on its modus operandi and the potential threat it poses to individuals and organizations alike. 🧐🔍
Source: Zscaler ThreatLabz
Tags: #BunnyLoader #MalwareAsAService #CyberSecurity #ThreatAnalysis #Malware #CryptocurrencyTheft #Zscaler #ThreatLabz #InfoSec
Authors: NIRAJ SHIVTARKAR, SATYAM SINGH
-
"🐰 BunnyLoader Unleashed: The Newest Kid on the Malware Block 🐰"
In a recent discovery, Zscaler ThreatLabz stumbled upon a new Malware-as-a-Service (MaaS) threat named "BunnyLoader" being peddled on various forums. This nefarious service offers a plethora of malicious functionalities including downloading and executing a second-stage payload, pilfering browser credentials and system information, keylogging, and even cryptocurrency theft through clipboard manipulation. 🕵️♀️💻
The malware, written in C/C++, is sold for a lifetime price of $250 and is under rapid development with multiple feature updates and bug fixes. It employs various anti-sandbox techniques during its attack sequence to evade detection and has a fileless loader feature which executes further malware stages in memory. BunnyLoader's C2 panel allows the threat actor to control infected machines remotely, showcasing a list of various tasks including keylogging, credential theft, and remote command execution among others. 🛑🔐
The detailed technical analysis reveals how BunnyLoader maintains persistence, performs anti-VM techniques, registers with the C2 server, and executes its core malicious tasks. The malware also harbors a clipper module to replace cryptocurrency addresses in a victim's clipboard with addresses controlled by the threat actor, targeting multiple cryptocurrencies like Bitcoin, Ethereum, and Monero. 🪙💸
The article is a comprehensive dive into the technical intricacies of BunnyLoader, shedding light on its modus operandi and the potential threat it poses to individuals and organizations alike. 🧐🔍
Source: Zscaler ThreatLabz
Tags: #BunnyLoader #MalwareAsAService #CyberSecurity #ThreatAnalysis #Malware #CryptocurrencyTheft #Zscaler #ThreatLabz #InfoSec
Authors: NIRAJ SHIVTARKAR, SATYAM SINGH
-
"🐰 BunnyLoader Unleashed: The Newest Kid on the Malware Block 🐰"
In a recent discovery, Zscaler ThreatLabz stumbled upon a new Malware-as-a-Service (MaaS) threat named "BunnyLoader" being peddled on various forums. This nefarious service offers a plethora of malicious functionalities including downloading and executing a second-stage payload, pilfering browser credentials and system information, keylogging, and even cryptocurrency theft through clipboard manipulation. 🕵️♀️💻
The malware, written in C/C++, is sold for a lifetime price of $250 and is under rapid development with multiple feature updates and bug fixes. It employs various anti-sandbox techniques during its attack sequence to evade detection and has a fileless loader feature which executes further malware stages in memory. BunnyLoader's C2 panel allows the threat actor to control infected machines remotely, showcasing a list of various tasks including keylogging, credential theft, and remote command execution among others. 🛑🔐
The detailed technical analysis reveals how BunnyLoader maintains persistence, performs anti-VM techniques, registers with the C2 server, and executes its core malicious tasks. The malware also harbors a clipper module to replace cryptocurrency addresses in a victim's clipboard with addresses controlled by the threat actor, targeting multiple cryptocurrencies like Bitcoin, Ethereum, and Monero. 🪙💸
The article is a comprehensive dive into the technical intricacies of BunnyLoader, shedding light on its modus operandi and the potential threat it poses to individuals and organizations alike. 🧐🔍
Source: Zscaler ThreatLabz
Tags: #BunnyLoader #MalwareAsAService #CyberSecurity #ThreatAnalysis #Malware #CryptocurrencyTheft #Zscaler #ThreatLabz #InfoSec
Authors: NIRAJ SHIVTARKAR, SATYAM SINGH
-
"🐰 BunnyLoader Unleashed: The Newest Kid on the Malware Block 🐰"
In a recent discovery, Zscaler ThreatLabz stumbled upon a new Malware-as-a-Service (MaaS) threat named "BunnyLoader" being peddled on various forums. This nefarious service offers a plethora of malicious functionalities including downloading and executing a second-stage payload, pilfering browser credentials and system information, keylogging, and even cryptocurrency theft through clipboard manipulation. 🕵️♀️💻
The malware, written in C/C++, is sold for a lifetime price of $250 and is under rapid development with multiple feature updates and bug fixes. It employs various anti-sandbox techniques during its attack sequence to evade detection and has a fileless loader feature which executes further malware stages in memory. BunnyLoader's C2 panel allows the threat actor to control infected machines remotely, showcasing a list of various tasks including keylogging, credential theft, and remote command execution among others. 🛑🔐
The detailed technical analysis reveals how BunnyLoader maintains persistence, performs anti-VM techniques, registers with the C2 server, and executes its core malicious tasks. The malware also harbors a clipper module to replace cryptocurrency addresses in a victim's clipboard with addresses controlled by the threat actor, targeting multiple cryptocurrencies like Bitcoin, Ethereum, and Monero. 🪙💸
The article is a comprehensive dive into the technical intricacies of BunnyLoader, shedding light on its modus operandi and the potential threat it poses to individuals and organizations alike. 🧐🔍
Source: Zscaler ThreatLabz
Tags: #BunnyLoader #MalwareAsAService #CyberSecurity #ThreatAnalysis #Malware #CryptocurrencyTheft #Zscaler #ThreatLabz #InfoSec
Authors: NIRAJ SHIVTARKAR, SATYAM SINGH