Malware News
15.8K subscribers
1.64K photos
7 videos
130 files
8.1K links
The latest NEWS about malwares, DFIR, hacking, security issues, thoughts and ...

Partner channel: @cveNotify

For ads: https://telega.io/c/malwr
Download Telegram
Doctor Web’s annual virus activity review for 2023

https://news.drweb.com/show/?i=14851&lng=en&c=5


🎖@malwr
Exploring the Depths of SolarMarker's Multi-tiered Infrastructure

Uncover SolarMarker’s multi-tiered infrastructure and its impact on sectors like education, healthcare, and government. Learn more.

https://www.recordedfuture.com/exploring-the-depths-of-solarmarkers-multi-tiered-infrastructure


🎖@malwr
XWiki Remote Code Execution Vulnerability

Overview The SonicWall Capture Labs threat research team became aware of CVE-2024-31984, which is a code injection vulnerability in XWiki’s management of space titles and has a critical CVSS score of 9.9. After assessing the

https://blog.sonicwall.com/en-us/2024/05/xwiki-remote-code-execution-vulnerability/


🎖@malwr
GitCaught: Threat Actor Leverages GitHub Repository for Malicious Infrastructure

Discover how Russian-speaking hackers leverage GitHub to host malware disguised as legitimate software. Explore the campaign, implications, and protection strategies.

https://www.recordedfuture.com/gitcaught-threat-actor-leverages-github-repository-for-malicious-infrastructure


🎖@malwr
Remcos Is Pairing with PrivateLoader to Extend Its Capabilities

Overview This week, the SonicWall Capture Labs threat research team investigated a sample of the RemcosRAT that uses a PrivateLoader module to provide additional data and persistence on the victim’s machine. By installing VB scripts,

https://blog.sonicwall.com/en-us/2024/05/remcos-is-pairing-with-privateloader-to-extend-its-capabilities/


🎖@malwr
MICROSOFT SECURITY BULLETIN COVERAGE FOR MAY 2024

Overview Microsoft’s May 2024 Patch Tuesday has 59 vulnerabilities, 25 of which are Remote Code Execution vulnerabilities. The SonicWall Capture Labs threat research team has analyzed and addressed Microsoft’s security advisories for the month of

https://blog.sonicwall.com/en-us/2024/05/microsoft-security-bulletin-coverage-for-may-2024/


🎖@malwr
Ebury is alive but unseen: 400k Linux servers compromised for cryptocurrency theft and financial gain

One of the most advanced server-side malware campaigns is still growing, with hundreds of thousands of compromised servers, and it has diversified to include credit card and cryptocurrency theft

https://www.welivesecurity.com/en/eset-research/ebury-alive-unseen-400k-linux-servers-compromised-cryptotheft-financial-gain/


🎖@malwr
Tracking the Progression of Earth Hundun's Cyberespionage Campaign in 2024

This report describes how Waterbear and Deuterbear — two of the tools in Earth Hundun's arsenal — operate, based on a campaign from 2024.

https://www.trendmicro.com/en_us/research/24/e/earth-hundun-2.html


🎖@malwr
👍1
Talos releases new macOS open-source fuzzer

Compared to fuzzing for software vulnerabilities on Linux, where most of the code is open-source, targeting anything on macOS presents a few difficulties.

https://blog.talosintelligence.com/talos-releases-new-macos-fuzzer/


🎖@malwr
Hackers use Malicious OneNote files for Delivering Payloads to Victims

Microsoft OneNote is a digital note-taking app in the Microsoft Office Suite. Hackers use it to embed malicious objects like scripts and executables, tricking users into downloading malware. The malware aims to deliver malicious payloads like Qakbot, Emotet, and AsyncRAT. Attackers prefer lightweight malware for easier delivery, avoiding heavier files like EXE or Office 97-2003 files.

https://hackhunting.com/2024/05/17/hackers-use-malicious-onenote-files-for-delivering-payloads-to-victims/


🎖@malwr
This media is not supported in your browser
VIEW IN TELEGRAM
5