Intrusions begin with the spread of a compressed ZIP archive containing a renamed jarsigner.exe file, which when executed prompts the loading of a tampered DLL library and eventual injection of XLoader malware, according to an analysis from the AhnLab Security Intelligence Center.
After initially compromising Check Point Security Gateways through the exploitation of the CVE-2024-24919 vulnerability, Green Nailao proceeded to deliver a stealthier variant of the ShadowPad malware and the PlugX backdoor to facilitate the execution of NailaoLocker, a report from Orange Cyberdefense researchers revealed.
Despite exploiting the Cisco IOS vulnerability, tracked as CVE-2018-0171, in one of the intrusions, Salt Typhoon mostly leveraged stolen credentials to facilitate initial compromise, which was followed by the exfiltration of network device configuration credentials and the alteration of network configurations to allow command execution and concealed account creation.
How vulnerable do you think your Macs are to Malware? Join Mac expert Slava Konstantinov to uncover the hidden data and security risks lurking in your macOS browsers and apps. This session will arm you with practical tips to identify and secure against these overlooked threats. This segment is sponsored by Zero Trust World. Visit https://securitywe...
Attacks involved the retrieval and decoding of the legitimate C2 domain in base64, enabling ACRStealer to exfiltrate browser data, FTP credentials, text files, emails, chat logs, remote access program information, password manager details, VPN data, browser extension information, and database details, according to findings from AhnLab Security Intelligence Center researchers.
With the exception of one device owned by a European government official, all of the other impacted phones belonged to business executives from Armenia, Bahrain, Poland, Switzerland, Spain, and the Czech Republic, threatening the potential exposure of confidential corporate and financial details, noted the iVerify report.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.