#windowsmalware — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #windowsmalware, aggregated by home.social.
-
Ghost CMS Flaw Exploited to Hijack Over 700 Sites in ClickFix Attacks
Over 700 websites were hijacked in a massive campaign that exploited a critical Ghost CMS vulnerability, turning legitimate pages into gateways for Windows malware. This alarming attack was made possible by CVE-2026-26980, an SQL injection flaw with a near-perfect CVSS score of 9.4.
#GhostCms #Cve202626980 #SqlInjection #Clickfix #WindowsMalware
-
Malicious Hugging Face repository targets Windows users with infostealer malware
Malicious actors on Hugging Face tricked Windows users into downloading infostealer malware by creating a fake repository that mimicked OpenAI's popular Privacy Filter release. The rogue repository briefly shot to the top of Hugging Face's trending list, racking up 244,000 downloads before being swiftly removed.
#InfostealerMalware #HuggingFace #Typosquatting #AiModelAbuse #WindowsMalware
-
Malicious Site Exploits AI Interest to Deploy Beagle Backdoor
Beware of a fake website masquerading as Anthropic's Claude interface, tricking users into downloading a 505 MB ZIP archive that unleashes a new, previously undocumented Windows backdoor called Beagle. This malicious campaign uses a convincing imitation of the legitimate site to spread the infection.
#BeagleBackdoor #AiMalware #WindowsMalware #Malvertising #DllSideloading
-
Fake Claude AI site delivers Beagle Windows backdoor malware
Beware of a fake Claude AI site that's really a malware trap: a 505MB archive disguised as a legitimate installer delivers a sneaky Windows backdoor called Beagle. Clicking the download button on the site leads to trouble, not the AI tool you might be expecting.
#FakeClaudeAiSite #BeagleWindowsBackdoor #MalwareOperations #EmergingThreats #WindowsMalware
-
CloudZ Malware Exploits Phone Link to Harvest SMS OTPs
Beware of CloudZ malware, a sneaky Windows threat that's been stealing SMS messages and one-time passwords since January 2026 by exploiting Microsoft's Phone Link app. This malicious duo, paired with the Pheno plugin, can capture mobile authentication data without ever touching your smartphone.
#CloudzMalware #WindowsMalware #MicrosoftPhoneLink #SmsOtp #RemoteAccessTool
-
📬 ClickFix Malware-Kampagne: Fake-Cloudflare-Check installiert unbemerkt MIMICRAT
#ITSicherheit #Malware #AMSIBypass #ClickFix #ETWBypass #FilelessMalware #MIMICRAT #PowerShell #ReflectiveLoading #RemoteAccessTrojaner #socialengineering #WindowsMalware https://sc.tarnkappe.info/0dde49 -
📬 ClickFix Malware-Kampagne: Fake-Cloudflare-Check installiert unbemerkt MIMICRAT
#ITSicherheit #Malware #AMSIBypass #ClickFix #ETWBypass #FilelessMalware #MIMICRAT #PowerShell #ReflectiveLoading #RemoteAccessTrojaner #socialengineering #WindowsMalware https://sc.tarnkappe.info/0dde49 -
📬 Stealka Stealer: Fake-Roblox-Mods und Cheats plündern Krypto-Wallets
#ITSicherheit #Malware #Cheats #Infostealer #kaspersky #KryptoDiebstahl #KryptoWallets #Roblox #SoftwareCracks #SpielMods #StealkaStealer #WindowsMalware #ZweiFaktorAuthentifizierung https://sc.tarnkappe.info/3e3510 -
📬 Stealka Stealer: Fake-Roblox-Mods und Cheats plündern Krypto-Wallets
#ITSicherheit #Malware #Cheats #Infostealer #kaspersky #KryptoDiebstahl #KryptoWallets #Roblox #SoftwareCracks #SpielMods #StealkaStealer #WindowsMalware #ZweiFaktorAuthentifizierung https://sc.tarnkappe.info/3e3510 -
Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824 – Source: securelist.com https://ciso2ciso.com/evolution-of-the-pipemagic-backdoor-from-the-ransomexx-incident-to-cve-2025-29824-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Targetedattacks #vulnerabilities #Windowsmalware #GReATresearch #securelistcom #ransomware #PipeMagic #backdoor #Malware #Trojan
-
Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824 – Source: securelist.com https://ciso2ciso.com/evolution-of-the-pipemagic-backdoor-from-the-ransomexx-incident-to-cve-2025-29824-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Targetedattacks #vulnerabilities #Windowsmalware #GReATresearch #securelistcom #ransomware #PipeMagic #backdoor #Malware #Trojan
-
Cobalt Strike Beacon delivered via GitHub and social media – Source: securelist.com https://ciso2ciso.com/cobalt-strike-beacon-delivered-via-github-and-social-media-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Targetedattacks #cyberespionage #DLLsideloading #Socialnetworks #Windowsmalware #securelistcom #CobaltStrike #DLLhijacking #shellcode #research #Malware #GitHub #Trojan
-
Cobalt Strike Beacon delivered via GitHub and social media – Source: securelist.com https://ciso2ciso.com/cobalt-strike-beacon-delivered-via-github-and-social-media-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Targetedattacks #cyberespionage #DLLsideloading #Socialnetworks #Windowsmalware #securelistcom #CobaltStrike #DLLhijacking #shellcode #research #Malware #GitHub #Trojan
-
😱 Siete al sicuro? Un nuovo malware sfrutta l'automazione di Windows per rubare i tuoi dati sensibili. Aggiorna il tuo antivirus e fai attenzione! #CyberSecurity #WindowsMalware
🔗 https://www.tomshw.it/hardware/coyote-primo-malware-che-sfrutta-windows-ui-2025-07-25
-
Batavia spyware steals data from Russian organizations – Source: securelist.com https://ciso2ciso.com/batavia-spyware-steals-data-from-russian-organizations-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #MicrosoftWindows #Targetedattacks #Windowsmalware #securelistcom #spearphishing #PowerShell #datatheft #Malware #Spyware #VBS
-
Batavia spyware steals data from Russian organizations – Source: securelist.com https://ciso2ciso.com/batavia-spyware-steals-data-from-russian-organizations-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #MicrosoftWindows #Targetedattacks #Windowsmalware #securelistcom #spearphishing #PowerShell #datatheft #Malware #Spyware #VBS
-
Toxic trend: Another malware threat targets DeepSeek – Source: securelist.com https://ciso2ciso.com/toxic-trend-another-malware-threat-targets-deepseek-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #MicrosoftWindows #Phishingwebsites #Defenseevasion #Windowsmalware #GReATresearch #securelistcom #GoogleChrome #Encryption #JavaScript #PowerShell #Webthreats #DeepSeek #browser #CAPTCHA #Malware #LLM #AI
-
Toxic trend: Another malware threat targets DeepSeek – Source: securelist.com https://ciso2ciso.com/toxic-trend-another-malware-threat-targets-deepseek-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #MicrosoftWindows #Phishingwebsites #Defenseevasion #Windowsmalware #GReATresearch #securelistcom #GoogleChrome #Encryption #JavaScript #PowerShell #Webthreats #DeepSeek #browser #CAPTCHA #Malware #LLM #AI
-
IT threat evolution in Q1 2025. Non-mobile statistics – Source: securelist.com https://ciso2ciso.com/it-threat-evolution-in-q1-2025-non-mobile-statistics-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #UnixandmacOSmalware #CyberSecurityNews #MalwareStatistics #internetofthings #MicrosoftWindows #Malwarereports #Windowsmalware #securelistcom #Trojanstealer #AppleMacOS #ransomware #TrojanSpy #Honeypot #Malware #adware #Trojan #Miner #ssh
-
IT threat evolution in Q1 2025. Non-mobile statistics – Source: securelist.com https://ciso2ciso.com/it-threat-evolution-in-q1-2025-non-mobile-statistics-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #UnixandmacOSmalware #CyberSecurityNews #MalwareStatistics #internetofthings #MicrosoftWindows #Malwarereports #Windowsmalware #securelistcom #Trojanstealer #AppleMacOS #ransomware #TrojanSpy #Honeypot #Malware #adware #Trojan #Miner #ssh
-
Exploits and vulnerabilities in Q1 2025 – Source: securelist.com https://ciso2ciso.com/exploits-and-vulnerabilities-in-q1-2025-source-securelist-com/ #Vulnerabilitiesandexploits #rssfeedpostgeneratorecho #VulnerabilityStatistics #Vulnerabilityreports #UnixandmacOSmalware #CyberSecurityNews #MalwareStatistics #MicrosoftWindows #bufferoverflows #MicrosoftOffice #Windowsmalware #securelistcom #Microsoft #browser #WinRAR #LINUX #APT #CVE
-
Exploits and vulnerabilities in Q1 2025 – Source: securelist.com https://ciso2ciso.com/exploits-and-vulnerabilities-in-q1-2025-source-securelist-com/ #Vulnerabilitiesandexploits #rssfeedpostgeneratorecho #VulnerabilityStatistics #Vulnerabilityreports #UnixandmacOSmalware #CyberSecurityNews #MalwareStatistics #MicrosoftWindows #bufferoverflows #MicrosoftOffice #Windowsmalware #securelistcom #Microsoft #browser #WinRAR #LINUX #APT #CVE
-
Lumma Stealer – Tracking distribution channels – Source: securelist.com https://ciso2ciso.com/lumma-stealer-tracking-distribution-channels-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Cryptocurrencies #IncidentResponse #Windowsmalware #securelistcom #Trojanstealer #Infostealers #Malvertizing #TIandIRposts #Phishing #Telegram #CAPTCHA #Malware #Trojan #Lumma #SOC
-
Lumma Stealer – Tracking distribution channels – Source: securelist.com https://ciso2ciso.com/lumma-stealer-tracking-distribution-channels-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Cryptocurrencies #IncidentResponse #Windowsmalware #securelistcom #Trojanstealer #Infostealers #Malvertizing #TIandIRposts #Phishing #Telegram #CAPTCHA #Malware #Trojan #Lumma #SOC
-
How ToddyCat tried to hide behind AV software – Source: securelist.com https://ciso2ciso.com/how-toddycat-tried-to-hide-behind-av-software-source-securelist-com/ #Vulnerabilitiesandexploits #AntivirusVulnerabilities #rssfeedpostgeneratorecho #zerodayvulnerabilities #APT(Targetedattacks) #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Defenseevasion #Windowsmalware #securelistcom #Encryption #Incidents #ToddyCat #Drivers #Malware #Trojan #BYOVD #APT #CVE #DLL
-
How ToddyCat tried to hide behind AV software – Source: securelist.com https://ciso2ciso.com/how-toddycat-tried-to-hide-behind-av-software-source-securelist-com/ #Vulnerabilitiesandexploits #AntivirusVulnerabilities #rssfeedpostgeneratorecho #zerodayvulnerabilities #APT(Targetedattacks) #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Defenseevasion #Windowsmalware #securelistcom #Encryption #Incidents #ToddyCat #Drivers #Malware #Trojan #BYOVD #APT #CVE #DLL
-
SideWinder targets the maritime and nuclear sectors with an updated toolset – Source: securelist.com https://ciso2ciso.com/sidewinder-targets-the-maritime-and-nuclear-sectors-with-an-updated-toolset-source-securelist-com/ #rssfeedpostgeneratorecho #APT(Targetedattacks) #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Targetedattacks #Defenseevasion #Windowsmalware #securelistcom #spearphishing #APTreports #JavaScript #SideWinder #shellcode #Malware #.NET #APT #HTA
-
StaryDobry ruins New Year’s Eve, delivering miner instead of presents – Source: securelist.com https://ciso2ciso.com/starydobry-ruins-new-years-eve-delivering-miner-instead-of-presents-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Financialthreats #Windowsmalware #Gamingmalware #securelistcom #spoofing #Malware #Torrent #Trojan #Miner #XMrig #DLL
-
StaryDobry ruins New Year’s Eve, delivering miner instead of presents – Source: securelist.com https://ciso2ciso.com/starydobry-ruins-new-years-eve-delivering-miner-instead-of-presents-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Financialthreats #Windowsmalware #Gamingmalware #securelistcom #spoofing #Malware #Torrent #Trojan #Miner #XMrig #DLL
-
Cloud Atlas seen using a new tool in its attacks – Source: securelist.com https://ciso2ciso.com/cloud-atlas-seen-using-a-new-tool-in-its-attacks-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Windowsmalware #Cloudservices #securelistcom #CloudAtlas #PowerShell #datatheft #backdoor #Phishing #Telegram #Malware #DLL #HTA #VBS
-
Cloud Atlas seen using a new tool in its attacks – Source: securelist.com https://ciso2ciso.com/cloud-atlas-seen-using-a-new-tool-in-its-attacks-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Windowsmalware #Cloudservices #securelistcom #CloudAtlas #PowerShell #datatheft #backdoor #Phishing #Telegram #Malware #DLL #HTA #VBS
-
Story of the Year: global IT outages and supply chain attacks – Source: securelist.com https://ciso2ciso.com/story-of-the-year-global-it-outages-and-supply-chain-attacks-source-securelist-com/ #Vulnerabilitiesandexploits #KasperskySecurityBulletin #rssfeedpostgeneratorecho #ArtificialIntelligence #UnixandmacOSmalware #Satellitereceivers #CyberSecurityNews #Supplychainattack #MicrosoftWindows #Windowsmalware #securelistcom #Triangulation #predictions #regreSSHion #JavaScript #opensource #Apple
-
Story of the Year: global IT outages and supply chain attacks – Source: securelist.com https://ciso2ciso.com/story-of-the-year-global-it-outages-and-supply-chain-attacks-source-securelist-com/ #Vulnerabilitiesandexploits #KasperskySecurityBulletin #rssfeedpostgeneratorecho #ArtificialIntelligence #UnixandmacOSmalware #Satellitereceivers #CyberSecurityNews #Supplychainattack #MicrosoftWindows #Windowsmalware #securelistcom #Triangulation #predictions #regreSSHion #JavaScript #opensource #Apple
-
Kaspersky Security Bulletin 2024. Statistics – Source: securelist.com https://ciso2ciso.com/kaspersky-security-bulletin-2024-statistics-source-securelist-com/ #Vulnerabilitiesandexploits #KasperskySecurityBulletin #rssfeedpostgeneratorecho #VulnerabilityStatistics #Secureenvironment(IoT) #UnixandmacOSmalware #CyberSecurityNews #MalwareStatistics #Financialmalware #internetofthings #MicrosoftWindows #vulnerabilities #Windowsmalware #securelistcom #TrojanBanker #AppleMacOS #ransomware #LINUX #ATM
-
Kaspersky Security Bulletin 2024. Statistics – Source: securelist.com https://ciso2ciso.com/kaspersky-security-bulletin-2024-statistics-source-securelist-com/ #Vulnerabilitiesandexploits #KasperskySecurityBulletin #rssfeedpostgeneratorecho #VulnerabilityStatistics #Secureenvironment(IoT) #UnixandmacOSmalware #CyberSecurityNews #MalwareStatistics #Financialmalware #internetofthings #MicrosoftWindows #vulnerabilities #Windowsmalware #securelistcom #TrojanBanker #AppleMacOS #ransomware #LINUX #ATM
-
IT threat evolution in Q3 2024. Non-mobile statistics – Source: securelist.com https://ciso2ciso.com/it-threat-evolution-in-q3-2024-non-mobile-statistics-source-securelist-com/ #rssfeedpostgeneratorecho #UnixandmacOSmalware #CyberSecurityNews #MalwareStatistics #internetofthings #MicrosoftWindows #Malwarereports #Windowsmalware #securelistcom #Trojanstealer #AppleMacOS #ransomware #Lockbit #Malware #adware #Trojan #Miner
-
IT threat evolution in Q3 2024. Non-mobile statistics – Source: securelist.com https://ciso2ciso.com/it-threat-evolution-in-q3-2024-non-mobile-statistics-source-securelist-com/ #rssfeedpostgeneratorecho #UnixandmacOSmalware #CyberSecurityNews #MalwareStatistics #internetofthings #MicrosoftWindows #Malwarereports #Windowsmalware #securelistcom #Trojanstealer #AppleMacOS #ransomware #Lockbit #Malware #adware #Trojan #Miner
-
Scammer Black Friday offers: Online shopping threats and dark web sales – Source: securelist.com https://ciso2ciso.com/scammer-black-friday-offers-online-shopping-threats-and-dark-web-sales-source-securelist-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Thematicphishing #SpamandPhishing #Windowsmalware #Mobilethreats #securelistcom #Publications #Thematicspam #TrojanBanker #SpamLetters #datatheft #Phishing #Darknet #Trojan #fraud
-
Scammer Black Friday offers: Online shopping threats and dark web sales – Source: securelist.com https://ciso2ciso.com/scammer-black-friday-offers-online-shopping-threats-and-dark-web-sales-source-securelist-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Thematicphishing #SpamandPhishing #Windowsmalware #Mobilethreats #securelistcom #Publications #Thematicspam #TrojanBanker #SpamLetters #datatheft #Phishing #Darknet #Trojan #fraud
-
Ymir: new stealthy ransomware in the wild – Source: securelist.com https://ciso2ciso.com/ymir-new-stealthy-ransomware-in-the-wild-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #IncidentResponse #DataEncryption #Windowsmalware #securelistcom #Trojanstealer #PowerShell #ransomware #Malware #Trojan
-
Ymir: new stealthy ransomware in the wild – Source: securelist.com https://ciso2ciso.com/ymir-new-stealthy-ransomware-in-the-wild-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #IncidentResponse #DataEncryption #Windowsmalware #securelistcom #Trojanstealer #PowerShell #ransomware #Malware #Trojan
-
Stealer here, stealer there, stealers everywhere! – Source: securelist.com https://ciso2ciso.com/stealer-here-stealer-there-stealers-everywhere-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #UnixandmacOSmalware #CyberSecurityNews #Crimewarereports #MicrosoftWindows #Windowsmalware #securelistcom #Trojanstealer #Infostealers #AppleMacOS #crimeware #Malware
-
Stealer here, stealer there, stealers everywhere! – Source: securelist.com https://ciso2ciso.com/stealer-here-stealer-there-stealers-everywhere-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #UnixandmacOSmalware #CyberSecurityNews #Crimewarereports #MicrosoftWindows #Windowsmalware #securelistcom #Trojanstealer #Infostealers #AppleMacOS #crimeware #Malware
-
ShrinkLocker: Turning BitLocker into ransomware – Source: securelist.com https://ciso2ciso.com/shrinklocker-turning-bitlocker-into-ransomware-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #IncidentResponse #MicrosoftWindows #DataEncryption #Windowsmalware #securelistcom #TIandIRposts #ransomware #Malware #SOC
-
ShrinkLocker: Turning BitLocker into ransomware – Source: securelist.com https://ciso2ciso.com/shrinklocker-turning-bitlocker-into-ransomware-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #IncidentResponse #MicrosoftWindows #DataEncryption #Windowsmalware #securelistcom #TIandIRposts #ransomware #Malware #SOC
-
Stealers, stealers and more stealers – Source: securelist.com https://ciso2ciso.com/stealers-stealers-and-more-stealers-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Malwarereports #Windowsmalware #securelistcom #Trojanstealer #crimeware #datatheft #Malware #Trojan
-
Stealers, stealers and more stealers – Source: securelist.com https://ciso2ciso.com/stealers-stealers-and-more-stealers-source-securelist-com/ #rssfeedpostgeneratorecho #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #Malwarereports #Windowsmalware #securelistcom #Trojanstealer #crimeware #datatheft #Malware #Trojan
-
State of ransomware in 2024 – Source: securelist.com https://ciso2ciso.com/state-of-ransomware-in-2024-source-securelist-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Financialthreats #DataEncryption #Windowsmalware #securelistcom #Publications #ransomware #Lockbit
-
State of ransomware in 2024 – Source: securelist.com https://ciso2ciso.com/state-of-ransomware-in-2024-source-securelist-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Financialthreats #DataEncryption #Windowsmalware #securelistcom #Publications #ransomware #Lockbit
-
Financial cyberthreats in 2023 – Source: securelist.com https://ciso2ciso.com/financial-cyberthreats-in-2023-source-securelist-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Financialmalware #Financialthreats #MicrosoftWindows #SpamandPhishing #Windowsmalware #GoogleAndroid #MobileMalware #Mobilethreats #securelistcom #Publications #TrojanBanker #Phishing #Emotet #QakBot #fraud
-
Financial cyberthreats in 2023 – Source: securelist.com https://ciso2ciso.com/financial-cyberthreats-in-2023-source-securelist-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Financialmalware #Financialthreats #MicrosoftWindows #SpamandPhishing #Windowsmalware #GoogleAndroid #MobileMalware #Mobilethreats #securelistcom #Publications #TrojanBanker #Phishing #Emotet #QakBot #fraud
-
Using the LockBit builder to generate targeted ransomware – Source: securelist.com https://ciso2ciso.com/using-the-lockbit-builder-to-generate-targeted-ransomware-source-securelist-com/ #rssfeedpostgeneratorecho #APT(Targetedattacks) #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #IncidentResponse #Targetedattacks #DataEncryption #Windowsmalware #securelistcom #ransomware #Lockbit #Malware #Trojan
-
Using the LockBit builder to generate targeted ransomware – Source: securelist.com https://ciso2ciso.com/using-the-lockbit-builder-to-generate-targeted-ransomware-source-securelist-com/ #rssfeedpostgeneratorecho #APT(Targetedattacks) #MalwareDescriptions #MalwareTechnologies #CyberSecurityNews #IncidentResponse #Targetedattacks #DataEncryption #Windowsmalware #securelistcom #ransomware #Lockbit #Malware #Trojan
-
Interesting #windowsmalware tactic: redirecting malicious* code in from standard input rather than using a file or via args.
This means I can not (as easily) see what is being executed.
This is not new (I have played around with this tactic in the past, albit with bash rather than PowerShell). However, I have not seen this used before in the wildi.e.
powershell.exe -NoLogo -InputFormat Text -NoExit -ExecutionPolicy Unrestricted -Command -
* as I can not see the code, I can not say for sure what it does or if it is malware
-
🔍 Technical Analysis: Smoke Loader Malware Leveraging Wi-Fi Access Points for Geolocation
📅 Date: August 28, 2023
🖋️ Author: Eswar📌 Tags: #Malware #SmokeLoader #Geolocation #Wi-FiScanning #Cybersecurity
🛠️ The Smoke Loader malware, recently discovered, employs a novel technique to locate infected systems through Wi-Fi access points and Google's Geolocation API. This technical analysis sheds light on the key mechanisms used by this malware.
🔗 System Location Identification:
The malware, also known as "Whiffy Recon," utilizes a custom Wi-Fi scanning tool to identify an infected system's precise coordinates using nearby Wi-Fi access points. This is achieved by leveraging the Windows WLANSVC service and Google's Geolocation API.🔒 Infection Process:
The malware checks the existence of the WLANSVC service, regardless of its operational status. If the service exists, the malware creates a wlan.lnk shortcut in the Startup folder pointing to the malware's original location. On the other hand, if the service is absent, the malware terminates execution.🔄 Malware Loops:
There are two loops in the malware's execution flow:- The first loop checks for the presence of the file %APPDATA%\wlan\str-12.bin. If valid parameters are found, the malware proceeds to the next loop for Wi-Fi scanning.
- In the absence of the file, the malware registers the bot with the Command and Control (C2) server, sending a JSON payload in an HTTPS POST request with a hard-coded UUID for bot identification.
📥 Registration and Communication:
Upon successful registration, the server responds with a secret UUID, replacing the initial bot ID for future requests. Both UUIDs are stored in the str-12.bin file. The malware then scans for Wi-Fi access points using the Windows WLAN API, sending results to Google's Geolocation API via HTTPS POST requests.🌐 Google Geolocation API:
The Geolocation API provides system coordinates based on Wi-Fi access points and mobile network data. The obtained coordinates are integrated into a JSON structure along with encryption methods of access points. This data is sent to the C2 server through HTTP POST requests with Authorization UUID and specific URLs.🔎 Indicators of Compromise:
Whiffy Recon sample dropped by Smoke Loader
- MD5 hash: 009230972491f5f5079e8e86e19d5458
- SHA256 hash: 935b44784c055a897038b2cb6f492747c0a1487f0ee3d3a39319962317cd4087
Whiffy Recon sample dropped by Smoke Loader
- SHA1 hash: 8532e67e1fd8441dc8ef41f5e75ee35b0d12a087
Whiffy Recon C2 server
- 194.87.32[.]20
Whiffy Recon payload URL
🛡️ Recommendations:
Cybersecurity professionals are advised to be vigilant against Smoke Loader malware and Whiffy Recon malware. Monitoring for these indicators of compromise can aid in identifying and mitigating potential threats.Source: https://cybersecuritynews.com/smoke-loader-malware-locates-using-wi-fi/
#Cybersecurity #ThreatAnalysis #MalwareDetection #GeolocationTracking #WindowsMalware
-
📬 EvilExtractor: Windows-Malware stiehlt mehr als nur Passwörter
#Malware #Dropbox #EvilExtractor #Keylogger #Kodex #pdf #Phishing #PowerShell #Python #Ransomware #WindowsMalware https://tarnkappe.info/artikel/it-sicherheit/malware/evilextractor-windows-malware-stiehlt-mehr-als-nur-passwoerter-273352.html -
📬 Android Apps haben Malware im Schlepptau – dank “Zombinder”
#Malware #AndroidApps #AndroidMalware #darknet #GooglePlayProtect #KryptoWallet #WindowsMalware #Zombinder https://tarnkappe.info/artikel/malware/android-apps-haben-malware-im-schlepptau-dank-zombinder-260705.html -
#ActuLibre WARNING: Hackers Install Secret Backdoor on Thousands of Microsoft SQL Servers -> http://feedproxy.google.com/~r/TheHackersNews/~3/AaO1rKvJ0qM/backdoor-.html #databasesecurity #databasehacking #cryptocurrency #windowsmalware #Malwareattack #MSSQLhacking #CyberAttack #hackingnews #MySQL