Malware News
13K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Analyzing AsyncRAT's Code Injection into aspnet_compiler.exe Across Multiple Incident Response Cases

This blog entry delves into MxDR's unraveling of the AsyncRAT infection chain across multiple cases, shedding light on the misuse of aspnet_compiler.exe, a legitimate Microsoft process originally designed for precompiling ASP.NET web applications.

https://www.trendmicro.com/en_us/research/23/l/analyzing-asyncrat-code-injection-into-aspnetcompiler-exe.html


๐ŸŽ–@malwr
๐Ÿ‘1
Operation Blacksmith: Lazarus targets organizations worldwide using novel Telegram-based malware written in DLang

Our latest findings indicate a definitive shift in the tactics of the North Korean APT group Lazarus Group.

https://blog.talosintelligence.com/lazarus_new_rats_dlang_and_telegram/


๐ŸŽ–@malwr
Mustang Pandaโ€™s PlugX new variant targetting Taiwanese government and diplomats

The Lab52 team has analysed a cyber campaign in which attackers deploy a new variant of the PlugX malware. Both the infection chain and the various artefacts used in the cyberattack share multiple similarities with the SmugX campaign, attributed to threat actors Red Delta and Mustang Panda, allegedly linked to the Chinese government. This time,...

https://lab52.io/blog/mustang-pandas-plugx-new-variant-targetting-taiwanese-government-and-diplomats/


๐ŸŽ–@malwr
2023-12-12 - Brazil malspam leds to Astaroth (Guildma) infection

https://www.malware-traffic-analysis.net/2023/12/11/index.html


๐ŸŽ–@malwr
CVE-2023-46604 (Apache ActiveMQ) Exploited to Infect Systems With Cryptominers and Rootkits

We uncovered the active exploitation of the Apache ActiveMQ vulnerability CVE-2023-46604 to download and infect Linux systems with the Kinsing malware (also known as h2miner) and cryptocurrency miner.

https://www.trendmicro.com/en_us/research/23/k/cve-2023-46604-exploited-by-kinsing.html


๐ŸŽ–@malwr
Rhadamanthys v0.5.0 โ€“ a deep dive into the stealerโ€™s components

https://research.checkpoint.com/2023/rhadamanthys-v0-5-0-a-deep-dive-into-the-stealers-components/


๐ŸŽ–@malwr
Aggressive Malign Influence Threatens to Shape US 2024 Elections

Russia, China, Iran, domestic violent extremists (DVEs), and hacktivist groups will very likely conduct influence operations at varying levels of magnitude and sophistication to shape or disrupt the United States (US) 2024 elections in pursuit of strategic geopolitical goals.

https://www.recordedfuture.com/aggressive-malign-influence-threatens-us-2024-elections


๐ŸŽ–@malwr
โค1
OilRigโ€™s persistent attacks using cloud service-powered downloaders

ESET researchers document a series of new OilRig downloaders, all relying on legitimate cloud service providers for C&C communications

https://www.welivesecurity.com/en/eset-research/oilrig-persistent-attacks-cloud-service-powered-downloaders/


๐ŸŽ–@malwr
โค1๐Ÿ‘1
2023-12-13 - Two AgentTesla infections (one FTP and one SMTP)

https://www.malware-traffic-analysis.net/2023/12/13/index.html


๐ŸŽ–@malwr
๐Ÿ”ฅ1
Decoding CVE-2023-50164: Unveiling the Apache Struts File Upload Exploit

In this blog entry, we discuss the technical details of CVE-2023-50164, a critical vulnerability that affects Apache Struts 2 and enables unauthorized path traversal.

https://www.trendmicro.com/en_us/research/23/l/decoding-cve-2023-50164--unveiling-the-apache-struts-file-upload.html


๐ŸŽ–@malwr