Almost 10% of the infected IP addresses were in the U.S., which accounted for most of the impacted devices, followed by Germany, France, the UK, and Brazil, a report from the Shadowserver Foundation showed.
Malicious job offers from fashion and beauty brands Bershka, John Hardy, Fragrance Du Bois, and Dear Klairs have been used to deploy the PureHVNC remote access trojan as part of a multi-stage phishing campaign last year, GBHackers News reports.
Identification and analysis efforts have been evaded for weeks by a new Windows remote access trojan through the use of corrupted Disk Operating System and Portable Executable headers, which could have provided more insights regarding the executable, according to The Hacker News.
Investment, banking, energy, and insurance organizations around the world are having their chief financial officers and other finance executives subjected to a spear-phishing campaign distributing the NetBird malware, reports GBHackers News.
Threat actors have been leveraging bogus installers for several artificial intelligence platforms to facilitate compromise with the CyberLock and Lucky_Gh0$t ransomware payloads, as well as the novel Numero malware, The Hacker News reports.
Chinese state-sponsored hacking operation APT41, also known as Winnti, had attack infrastructure deploying the novel ToughProgress malware, which leverages Google Calendar for command-and-control, dismantled by the Google Threat Intelligence Group, BleepingComputer reports.
GBHackers News reports that Android devices are at risk of being completely taken over by the newly emergent GhostSpy malware, which features sophisticated persistence, anti-detection, and surveillance mechanisms.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.