Researchers at Group-IB have identified that Gigabud is now being paired with Vwork, a modified version of the Shelter app, attributed to the GoldFactory threat group.
The RAT employs a concealed loader and a worm that actively scans for exposed Android Debug Bridge (ADB) services to install itself on vulnerable devices.
A Russian national has been charged by the U.S. Department of Justice for allegedly operating approximately 255 fake accounts on a freelance platform to distribute malware-laced Excel attachments to around 80,000 users in 2016 and 2017.
The malicious code performs two main functions: a mobile ad-fraud and gambling-redirect chain, and a WebKit-to-kernel exploit chain on iPhones that installs spyware.
The PackClient RAT, observed by Proofpoint, offers a wide range of capabilities including file theft, remote shell execution, screen capture, and keylogging.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.