BleepingComputer reports that updated variants of the Android malware XLoader, also known as MoqHao, that allowed automated execution after installation have emerged.
Major U.S. insurance firms Bankers Life and Casualty Company and Washington National Insurance Company disclosed having data from more than 66,000 customers stolen following a SIM swapping attack in November, according to Hackread.
Despite the win against the Chinese nation-state APT, government agencies issued fresh warnings about the dangers it poses to critical U.S. infrastructure.
Almost 150 Android devices across India and Pakistan have been compromised by suspected Indian state-sponsored threat operation PatchWork in a new attack campaign leveraging mostly messaging apps that have been laced with the VajraSpy remote access trojan, The Hacker News reports.
TechCrunch reports that mobile consumer-grade stalkerware apps Highster and PhoneSpector have seemingly ended operations following a settlement between Patrick Hinchy, whose tech firm consortium was behind both apps, and the New York Attorney General last February that involved the payment of $410,000 in fines to resolve charges of aggressive spyware promotions in New York state.
Health, transportation, logistics, and transportation organizations across Italy have been targeted by the UNC4990 threat operation in a new attack campaign involving weaponized USB drives used to facilitate the distribution of malware hosted on widely used websites, reports The Hacker News.