Malware News
12.9K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
DarkGate Opens Organizations for Attack via Skype, Teams

We detail an ongoing campaign abusing messaging platforms Skype and Teams to distribute the DarkGate malware to targeted organizations. We also discovered that once DarkGate is installed on the victimโ€™s system, additional payloads were introduced to the environment.

https://www.trendmicro.com/en_us/research/23/j/darkgate-opens-organizations-for-attack-via-skype-teams.html


๐ŸŽ–@malwr
Forensic Timeline of an IcedID Infection

The BackConnect and VNC parsers that were added to NetworkMiner 2.8.1 provide a unique possibility to trace the steps of an attacker with help of captured network traffic from a hacked computer. In this blog post I use the free and open source version of NetworkMiner to see how GzipLoader downloads...

https://www.netresec.com/?page=Blog&month=2023-10&post=Forensic-Timeline-of-an-IcedID-Infection


๐ŸŽ–@malwr
Top resources for Cybersecurity Awareness Month

Plus, many of the worldโ€™s largest cloud providers are warning of a vulnerability that attackers exploited in August to launch the largest distributed denial-of-service attack on record.

https://blog.talosintelligence.com/threat-source-newsletter-oct-12-2023/


๐ŸŽ–@malwr
Void Rabisu Targets Female Political Leaders with New Slimmed-Down ROMCOM Variant

Almost a year after Void Rabisu shifted its targeting from opportunistic ransomware attacks with an emphasis on cyberespionage, the threat actor is still developing its main malware, the ROMCOM backdoor.

https://www.trendmicro.com/en_us/research/23/j/void-rabisu-targets-female-leaders-with-new-romcom-variant.html


๐ŸŽ–@malwr
๐Ÿคทโ€โ™€1
2023-10-12 - DarkGate infection from Teams Chat

https://www.malware-traffic-analysis.net/2023/10/12/index.html


๐ŸŽ–@malwr
2023-10-13 - TA577 DarkGate infection

https://www.malware-traffic-analysis.net/2023/10/13/index.html


๐ŸŽ–@malwr
Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement

While monitoring Earth Lusca, we discovered an intriguing, encrypted file on the threat actor's server โ€” a Linux-based malware, which appears to originate from the open-source Windows backdoor Trochilus, which we've dubbed SprySOCKS due to its swift behavior and SOCKS implementation.

https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html


๐ŸŽ–@malwr