Malware News
13K subscribers
1.63K photos
7 videos
130 files
7.78K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
CVE-2023-36025 Exploited for Defense Evasion in Phemedrone Stealer Campaign

This blog delves into the Phemedrone Stealer campaign's exploitation of CVE-2023-36025, the Windows Defender SmartScreen Bypass vulnerability, for its defense evasion and investigates the malware's payload.

https://www.trendmicro.com/en_us/research/24/a/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-steal.html


๐ŸŽ–@malwr
MoustachedBouncer: Espionage against foreign diplomats in Belarus

Long-term espionage against diplomats, leveraging email-based C&C protocols, C++ modular backdoors, and adversary-in-the-middle (AitM) attacksโ€ฆ Sounds like the infamous Turla? Think again!

https://www.welivesecurity.com/en/eset-research/moustachedbouncer-espionage-against-foreign-diplomats-in-belarus/


๐ŸŽ–@malwr
Beware: Lumma Stealer Distributed via Discord CDN

This blog discusses how threat actors abuse Discordโ€™s content delivery network (CDN) to host and spread Lumma Stealer, and talks about added capabilities to the information stealing malware.

https://www.trendmicro.com/en_us/research/23/j/beware-lumma-stealer-distributed-via-discord-cdn-.html


๐ŸŽ–@malwr
Kasseika Ransomware Deploys BYOVD Attacks, Abuses PsExec and Exploits Martini Driver

In this blog, we detail our investigation of the Kasseika ransomware and the indicators we found suggesting that the actors behind it have acquired access to the source code of the notorious BlackMatter ransomware.

https://www.trendmicro.com/en_us/research/24/a/kasseika-ransomware-deploys-byovd-attacks-abuses-psexec-and-expl.html


๐ŸŽ–@malwr
๐Ÿ‘1
Leaks and Revelations: A Web of IRGC Networks and Cyber Companies

Iranian intelligence and military, along with contractors, target democratic processes in Western countries, including the 2020 US election.

https://www.recordedfuture.com/leaks-and-revelations-irgc-networks-cyber-companies


๐ŸŽ–@malwr