Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
TargetCompany Ransomware Group Installs Mallox Ransomware on Vulnerable MS-SQL Servers

The TargetCompany ransomware group was discovered in June 2021, targeting improperly managed MS-SQL servers with malware variants such as Mallox ransomware. Using brute force and dictionary attacks, threat actors install Remocs RAT and remote screen control malware. The final stage involves installing Mallox ransomware, impacting file encryption and system functions. ASEC researchers have published a comprehensive report. Mitigation involves upgrading servers and enhancing password security. Indicators of Compromise are provided.

https://hackhunting.com/2024/05/03/targetcompany-ransomware-group-installs-mallox-ransomware-on-vulnerable-ms-sql-servers/


๐ŸŽ–@malwr
Flutter Windows Thick Client SSL Pinning Bypass | by Sourav Kalal | May, 2024 | Medium
Learn to bypass SSL Pinning in Flutter Windows Thick Client Application using Frida and Reverse Engineering. Also, find ouhow to configure Flutter for proxy.

https://blog.souravkalal.tech/flutter-windows-thick-client-ssl-pinning-bypass-492389ae1218


๐ŸŽ–@malwr
โ€œDirty Streamโ€ Attack : Android Apps with 4 Billion Installations are Affected

Mobile devices, especially Android, are targeted by hackers due to security vulnerabilities. Researchers at Microsoft discovered a Path Traversal attack that allows threat actors to overwrite files and execute arbitrary code in popular Android apps, like Xiaomi's File Manager. Developers should follow security guidelines and use Android Lint to avoid such vulnerabilities.

https://hackhunting.com/2024/05/04/dirty-stream-attack-android-apps-with-4-billion-installations-are-affected/


๐ŸŽ–@malwr
Custom Shellcode Creation in x64 | s4dbrdโ€™s blog
Investigating custom shellcode creation on x64 Windows architectures, also understanding the calling convention in order to obtain a reverse shell

https://s4dbrd.com/shellcode-creation-in-x64/


๐ŸŽ–@malwr
๐Ÿ‘1๐Ÿ”ฅ1
URB Excalibur: Virtual USB Controller Attack leading to Virtual Machine Escape in all VMware Platforms

At Black Hat Asia 2024, researchers unveiled "URB Excalibur," a Virtual Machine Escape vulnerability affecting VMware. The vulnerability, assigned CVE-2022-31705, allows for control over the hypervisor and potential network escape. Exploitation techniques and control of the Routing Information Protocol were demonstrated, exposing critical security risks. Various USB controller vulnerabilities were also highlighted.

https://hackhunting.com/2024/05/05/urb-excalibur-virtual-usb-controller-attack-leading-to-virtual-machine-escape-in-all-vmware-platforms/


๐ŸŽ–@malwr
๐Ÿ‘3
Hackers Distribute RokRAT LNK Files Pretending as a Certificate

A new campaign distributing RokRAT malware targets South Korean and North Korean-related users. LNK files with legitimate names contain PowerShell commands, malicious PE data, and script codes. The malware acts as a backdoor, using cloud APIs to collect and send user information to attacker-controlled cloud servers hosted in pCloud, Yandex, and Dropbox. Numerous malicious activities and potential threat actor email addresses have been uncovered. Users in South Korea are advised to exercise caution, and further details are available in a report by ASEC researchers. Indicators of compromise include file detections and specific hashes.

https://hackhunting.com/2024/05/07/hackers-distribute-rokrat-lnk-files-pretending-as-a-certificate/


๐ŸŽ–@malwr
Formbook Malware Analysis โ€“ CyberForensics
In the ever-evolving world, the art of forging genuine connections remains timeless. Whether itโ€™s with colleagues, clients, or partners, establishing a genuine rapport paves the way for collaborative success.

https://cyber-forensics.blog/2024/05/06/formbook-analysis/


๐ŸŽ–@malwr
๐Ÿ‘1
AWS CloudQuarry: Digging for Secrets in Public AMIs โ€“ Security Cafรฉ
Money, secrets and mass exploitation: This research unveils a quarry of sensitive data stored in public AMIs. Digging through each AMI we managed to collect 500 GB of credentials, private repositories, access keys and more. The present article is the detailed analysis of how we did it and what the data represents. We did aโ€ฆ

https://securitycafe.ro/2024/05/08/aws-cloudquarry-digging-for-secrets-in-public-amis/


๐ŸŽ–@malwr
APT28 campaign directed against Polish government institutions

CERT Polska is observing a malicious e-mail campaign conducted by the APT28 group against Polish government institutions.

https://cert.pl/en/posts/2024/05/apt28-campaign/


๐ŸŽ–@malwr
๐Ÿ‘1
Iran-Aligned Emerald Divide Influence Campaign Evolves to Exploit Israel-Hamas Conflict

Explore how Iran-aligned Emerald Divide exploits the Israel-Hamas conflict in an ongoing influence campaign to deepen divisions within Israeli society.

https://www.recordedfuture.com/iran-aligned-emerald-divide-influence-campaign-evolves-to-exploit-israel-hamas-conflict


๐ŸŽ–@malwr
๐Ÿ‘1
LNK File Disguised as Certificate Distributing RokRAT Malware - ASEC BLOG
AhnLab Security Emergency response Center

https://asec.ahnlab.com/en/65076/


๐ŸŽ–@malwr
Dissecting REMCOS RAT: An in-depth analysis of a widespread 2024 malware, Part Three โ€” Elastic Security Labs
In previous articles in this multipart series, malware researchers on the Elastic Security Labs team dove into the REMCOS execution flow. In this article, youโ€™ll learn more about REMCOS configuration structure and its C2 commands.

https://www.elastic.co/security-labs/dissecting-remcos-rat-part-three


๐ŸŽ–@malwr
JavaScript Debugging with Maglev Compiler | by VXRL | Medium
Other than fuzzing for vulnerabilities of our previous blogpost, it would be good to understand how Maglev compiler works via debugging. In the following article, we are going to briefly introduceโ€ฆ

https://vxrl.medium.com/javascript-debugging-with-maglev-compiler-6b2a26cb1a3a


๐ŸŽ–@malwr
CrowdStrike Enhances Cloud Asset Visualization to Accelerate Risk Prioritization

The massive increase in cloud adoption has driven adversaries to focus their efforts on cloud environments โ€” a shift that led to cloud intrusions increasing by 75% in 2023, emphasizing the need for stronger cloud security. Larger scale leads to larger risk. As organizations increase their quantity of cloud assets, their attack surface grows. Each...

https://www.crowdstrike.com/blog/enhanced-cloud-asset-visualization/


๐ŸŽ–@malwr
Russia-Linked CopyCop Uses LLMs to Weaponize Influence Content at Scale

Insikt Group shares research on CopyCop: a Russian-linked network using AI for disinformation to influence US, UK, and French politics. Dive into the details.

https://www.recordedfuture.com/russia-linked-copycop-uses-llms-to-weaponize-influence-content-at-scale


๐ŸŽ–@malwr