Posts

Showing posts with the label Malware

Fake Google Chrome errors trick you into running malicious PowerShell scripts

Image
By Bill Toulas,  Bleeping Computer A new malware distribution campaign uses fake Google Chrome, Word, and OneDrive errors to trick users into running malicious PowerShell "fixes" that install malware. The new campaign was observed being used by multiple threat actors, including those behind ClearFake, a new attack cluster called ClickFix, and the TA571 threat actor, known for operating as a spam distributor that sends large volumes of email, leading to malware and ransomware infections. Previous ClearFake attacks utilize website overlays that prompt visitors to install a fake browser update that installs malware. Threat actors also utilize JavaScript in HTML attachments and compromised websites in the new attacks. However, now the overlays display fake Google Chrome, Microsoft Word, and OneDrive errors. These errors prompt the visitor to click a button to copy a PowerShell "fix" into the clipboard and then paste and run it in a Run: dialog or PowerShell prompt. ...

Bogus npm Packages Used to Trick Software Developers into Installing Malware

Image
An ongoing social engineering campaign is targeting software developers with bogus npm packages under the guise of a job interview to trick them into downloading a Python backdoor. NPM is a package manager for the JavaScript programming language maintained by Microsoft's npm, Inc. npm is the default package manager for the JavaScript runtime environment Node.js and is included as a recommended feature in the Node.js installer. Wikipedia Cybersecurity firm Securonix is tracking the activity under the name DEV#POPPER, linking it to North Korean threat actors. "During these fraudulent interviews, the developers are often asked to perform tasks that involve downloading and running software from sources that appear legitimate, such as GitHub," security researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov said . "The software contained a malicious Node JS payload that, once executed, compromised the developer's system." Details of the campaign first emerged in l...

The Biggest Takeaways from Recent Malware Attacks

Image
Among the never-ending list of malicious software that threat actors use in cyber attacks are viruses, worms, trojans, ransomware, spyware, and adware. Today's malware is not just about causing immediate damage; some programs get embedded within systems to siphon off data over time, disrupt operations strategically, or lay the groundwork for massive, coordinated attacks.  A prime example is a recently found malicious backdoor in a popular compression tool, known as xz Utils. Thankfully the malicious code was identified early “due to bad actor sloppiness”, but the consequences could’ve been massive. Read on to get the lowdown on recent high-profile malware attacks along with strategies to help limit malware risks at your organization.  Recent High-Profile Malware Attacks Here's a detailed overview of recent malware attacks, highlighting key incidents and offering valuable insights and lessons learned from each event. StripedFly A prolific and advanced cross-platform malware fra...

Over 100 US and EU orgs targeted in StrelaStealer malware attacks

Image
By Bill Toulas, Bleeping Computer A new large-scale StrelaStealer malware campaign has impacted over a hundred organizations across the United States and Europe, attempting to steal email account credentials. StrelaStealer was first documented in November 2022 as a new information-stealing malware that steals email account credentials from Outlook and Thunderbird. One notable characteristic of the malware was using a polyglot file infection method to evade detection from security software. At the time, StrelaStealer was seen targeting predominately Spanish-speaking users. However, according to a recent report by Palo Alto Networks' Unit42, this has changed as the malware now targets people from the U.S. and Europe. StrelaStealer is distributed through phishing campaigns that showed a significant uptick in November 2023, some days targeting over 250 organizations in the U.S. The elevated phishing email distribution volumes continued into 2024, with a significant wave of activity bei...

Hackers steal 50,000 credit cards from 300 U.S. restaurants

By Bill Toulas,  Bleeping Computer Payment card details from customers of more than 300 restaurants have been stolen in two web-skimming campaigns targeting three online ordering platforms. Web-skimmers, or Magecart malware, are typically JavaScript code that collects credit card data when online shoppers type it on the checkout page. Recently, Recorded Future’s threat detection tools identified two Magecart campaigns injecting malicious code into the online ordering portals of MenuDrive, Harbortouch, and InTouchPOS. As a result, 50,000 payment cards were stolen and have already been offered for sale on various marketplaces on the dark web.

Mass malware infection detected on Digium phones

By Damien Black,  Cyber News More than half a million instances of malware have been observed on software used by the popular landline brand Digium in the first three months of the year. Unit 42, the cyber-detective wing of infosecurity firm Palo Alto, said it had “witnessed more than 500,000 unique malware samples” over a three-month period to the end of March targeting the Elastix and Asterisk operating systems that Digium phones depend upon. Though ostensibly conventional wired handsets, the phones benefit from special features including voicemail, call logging and queuing, and phone status display, which require them to be connected to the internet of things. Unfortunately for businesses like call centers that rely on such features, they appear to have put the phones on the radar of cybercriminals. “The attacker implants a web shell to exfiltrate data by downloading and executing additional payloads inside the target's Digium phone software,” said Unit 42. “The malware installs...

Roaming Mantis hits Android and iOS users in malware, phishing attacks

By Bill Toulas,  Bleeping Computer After hitting Germany, Taiwan, South Korea, Japan, the US, and the U.K. the Roaming Mantis operation moved to targeting Android and iOS users in France, likely compromising tens of thousands of devices. Roaming Mantis is believed to be a financially-motivated threat actor that started targeting European users in February. In a recently observed campaign, the threat actor uses SMS communication to lure users into downloading malware on their Android devices. If the potential victim uses iOS, they are redirected to a phishing page for Apple credentials.

Toll fraud malware continues to evolve, says Microsoft: Here's how Android users can protect themselves

Toll fraud, one of the most prevalent types of Android malware, continues to evolve. In a blog post on Thursday, the Microsoft 365 Defender Research Team revealed the details of this threat - how it operates, how analysts can better identify such threats, and how Android security can be improved to mitigate this threat. According to Microsoft's blog, toll fraud malware is a subcategory of billing fraud in which malicious applications subscribe users to premium services without their knowledge or consent. The malware accounted for 34.8% of installed Potentially Harmful Application (PHA) from the Google Play Store in the first quarter of 2022, ranking second only to spyware. The malware has unique behaviors. While SMS or call frauds use a simple attack flow to send messages or calls to a premium number, toll fraud has a complex multi-step attack flow that malware developers continue to improve. Microsoft security researchers observed new capabilities related to how this threat target...

Russian state hackers swap malware with cloud-based attacks

By Vilius Petkauskas,  Cybernews Russian adversaries increasingly focus on targeting the cloud environment, Crowdstrike’s Global Threat Report on Cloud Security revealed. Fancy Bear, a Russian adversary associated with Russia’s Main Intelligence Directorate (GRU), used to rely on malware-based spear-phishing attacks, the report claims. However, with their tactics exposed by the US Department of Justice (DoJ), hackers have refocused their attention on cloud service providers. Since Fancy Bear’s primary source of intelligence comes from various credential harvesting practices that allow penetrating target organizations and individuals, it’s no surprise that the main targets are cloud-based email providers. According to the report, Fancy Bear focused their attention on service providers such as Microsoft 365, Google’s GSuite, as well as webmail providers that individuals usually use. Meanwhile, Cozy Bear, Russia’s state-sponsored hacker group controlled by the Federal Security service...

New ChromeLoader malware surge threatens browsers worldwide

By Bill Toulas,  Bleeping Computer The ChromeLoader malware is seeing an uptick in detections this month, following a relatively stable volume since the start of the year, causing the browser hijack to become a widespread threat. ChromeLoader is a browser hijacker that can modify the victim's web browser settings to show search results that promote unwanted software, fake giveaways and surveys, and adult games and dating sites.  The malware's operators receive financial gains through a system of marketing affiliation by redirecting user traffic to advertising sites. There are many hijackers of this kind, but ChromeLoader stands out for its persistence, volume, and infection route, which involves the aggressive use of PowerShell.

New Windows Subsystem for Linux malware steals browser auth cookies

Image
By Ionut Ilascu, Bleeping Computer Hackers are showing an increased interest in the Windows Subsystem for Linux (WSL) as an attack surface as they build new malware, the more advanced samples being suitable for espionage and downloading additional malicious modules. As the name of the feature implies, WSL allows running native Linux binaries to run on Windows in an environment that emulates the Linux kernel. WSL-based malware samples discovered recently rely on open-source code that routes communication through the Telegram messaging service and gives the threat actor remote access to the compromised system. RATs and shells Malicious Linux binaries for WSL were first discovered over a year ago, with researchers at Lumen Technologies’ Black Lotus Labs publishing a report on this new type of threat in September 2021. Since then, their number has grown constantly, with all variants enjoying low detection rates, despite being based on publicly available code. Black Lotus Labs researchers ...

Security Warning For Facebook Users Who Login With Gmail OAuth Code

By Gordon Kelly, Forbes How do you sign into services? Because a newly disclosed Facebook exploit might change how you go about it in future... In an eye-opening blog post, security researcher Youssef Sammouda has revealed that chaining Gmail's OAuth authentication code with vulnerabilities in Facebook enabled him to hijack Facebook accounts when users logged in with their Gmail credentials. Speaking to The Daily Swing, Sammouda explained that he was able to use redirects in Google OAuth and chain them with elements of Facebook's logout, checkpoint and sandbox systems to break into accounts. He explained that while he demonstrated the proof of concept with Gmail credentials, "it was possible to target all Facebook users" Sammouda says Facebook paid him a $44,625 'bug bounty' for his disclosure of this vulnerability in February. Facebook subsequently patched it in March, though it was only made public this week. And while not directly responsible for the exploi...

Microsoft detects massive surge in Linux XorDDoS malware activity

Image
By Sergiu Gatlan, Bleeping Computer A stealthy and modular malware used to hack into Linux devices and build a DDoS botnet has seen a massive 254% increase in activity during the last six months, as Microsoft revealed today. This malware (active since at least 2014) is known as XorDDoS (or XOR DDoS) due to its use of XOR-based encryption when communicating with command-and-control (C2) servers and being employed to launch distributed denial-of-service (DDoS) attacks. As the company revealed, the botnet's success is likely due to its extensive use of various evasion and persistence tactics which allow it to remain stealthy and hard to remove. "Its evasion capabilities include obfuscating the malware's activities, evading rule-based detection mechanisms and hash-based malicious file lookup, as well as using anti-forensic techniques to break process tree-based analysis," Microsoft 365 Defender Research Team said. "We observed in recent campaigns that XorDdos hides m...

When Your Smart ID Card Reader Comes With Malware

Image
By  Krebs On Security Millions of U.S. government employees and contractors have been issued a secure smart ID card that enables physical access to buildings and controlled spaces, and provides access to government computer networks and systems at the cardholder’s appropriate security level. But many government employees aren’t issued an approved card reader device that lets them use these cards at home or remotely, and so turn to low-cost readers they find online. What could go wrong? Here’s one example. KrebsOnSecurity recently heard from a reader — we’ll call him “Mark” because he wasn’t authorized to speak to the press — who works in IT for a major government defense contractor and was issued a Personal Identity Verification (PIV) government smart card designed for civilian employees. Not having a smart card reader at home and lacking any obvious guidance from his co-workers on how to get one, Mark opted to purchase a $15 reader from Amazon that said it was made to handle U.S. ...

Iranian hackers exposed in a highly targeted espionage campaign

By Bill Toulas, Bleeping Computer Threat analysts have spotted a novel attack attributed to the Iranian hacking group known as APT34 group or Oilrig, who targeted a Jordanian diplomat with custom-crafted tools. The attack involved advanced anti-detection and anti-analysis techniques and had some characteristics that indicate lengthy and careful preparation. Security researchers at Fortinet have gathered evidence and artifacts from the attack in May 2022 and compiled a technical report to highlight APT34’s latest techniques and methods. Targeting diplomats The spear-phishing email seen by Fortinet targeted a Jordanian diplomat, pretending to be from a colleague in the government, with the email address spoofed accordingly. The email carried a malicious Excel attachment that contained VBA macro code that executes to create three files, a malicious executable, a configuration file, and a signed and clean DLL. The macro also creates persistence for the malicious executable (update.exe) by ...

Stealthy Raspberry Robin Worm Is Spreading Malware Via USB Drives

Image
by Zak Killian, Hot Hardware When you are investigating a crime, one of the most important things to establish is "motive." If you know a crime has been committed, having an understanding of why it happened is a critical step to figuring out who did it. In the strictest sense, installing software on someone else's computer isn't a crime. It's not until it becomes malicious software—"malware"—that it's a problem, and it doesn't become malware until it does something troublesome, like encrypting user files, opening security backdoors, or crashing the system altogether. Threat intelligence group Red Canary is tracking a worm that it calls Raspberry Robin, and it's definitely malware, but the question of "why" is still, in fact, a big question. Red Canary has found the worm in multiple of its customers' environments starting back in September 2021, though it says most of the activity from the threat has occurred since January of thi...