Malware News
12.9K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Top resources for Cybersecurity Awareness Month

Plus, many of the world’s largest cloud providers are warning of a vulnerability that attackers exploited in August to launch the largest distributed denial-of-service attack on record.

https://blog.talosintelligence.com/threat-source-newsletter-oct-12-2023/


πŸŽ–@malwr
Void Rabisu Targets Female Political Leaders with New Slimmed-Down ROMCOM Variant

Almost a year after Void Rabisu shifted its targeting from opportunistic ransomware attacks with an emphasis on cyberespionage, the threat actor is still developing its main malware, the ROMCOM backdoor.

https://www.trendmicro.com/en_us/research/23/j/void-rabisu-targets-female-leaders-with-new-romcom-variant.html


πŸŽ–@malwr
πŸ€·β€β™€1
2023-10-12 - DarkGate infection from Teams Chat

https://www.malware-traffic-analysis.net/2023/10/12/index.html


πŸŽ–@malwr
Earth Lusca Employs New Linux Backdoor, Uses Cobalt Strike for Lateral Movement

While monitoring Earth Lusca, we discovered an intriguing, encrypted file on the threat actor's server β€” a Linux-based malware, which appears to originate from the open-source Windows backdoor Trochilus, which we've dubbed SprySOCKS due to its swift behavior and SOCKS implementation.

https://www.trendmicro.com/en_us/research/23/i/earth-lusca-employs-new-linux-backdoor.html


πŸŽ–@malwr
πŸ“πŸ“πŸ“Forward posts to other groups πŸ“πŸ“πŸ“
❀2
Malware News pinned Β«πŸ“πŸ“πŸ“Forward posts to other groups πŸ“πŸ“πŸ“Β»
Trench Tales: The College Account Takeover That Never Happened

A story of mass-discovery of LDAP Anonymous Binding leading to the account takeover of all members of a college. Explore the methodology, the challenges and the discoveries of this research project.Continue reading

https://securitycafe.ro/2023/10/16/trench-tales-the-college-account-takeover-that-never-happened/


πŸŽ–@malwr
Beware: Lumma Stealer Distributed via Discord CDN

This blog discusses how threat actors abuse Discord’s content delivery network (CDN) to host and spread Lumma Stealer, and talks about added capabilities to the information stealing malware.

https://www.trendmicro.com/en_us/research/23/j/beware-lumma-stealer-distributed-via-discord-cdn-.html


πŸŽ–@malwr
Active exploitation of Cisco IOS XE Software Web Management User Interface vulnerability

Cisco has identified active exploitation of a previously unknown vulnerability in the Web User Interface (Web UI) feature of Cisco IOS XE software (CVE-2023-20198) when exposed to the internet or untrusted networks.

https://blog.talosintelligence.com/active-exploitation-of-cisco-ios-xe-software/


πŸŽ–@malwr