Downloading the trojanized installers for the BeamNG.drive, Universe Sandbox, Garry's Mod, Plutocracy, and Dyson Sphere Program games uploaded to torrent sites in September triggers an installer screen luring targets to continue with the setup process when dropper extraction and execution occurs, according to an analysis from Kaspersky.
Aside from utilizing Hangul half-width and full-width characters to hide malicious code in a blank space that could be retrieved using a 'get()trap' JavaScript proxy, threat actors have also adopted base64 encoding and anit-debugging measures to further bypass analysis and detection systems, according to a report from Juniper Networks.
TA2727's attack campaign, which were discovered in late January, entailed the insertion of malicious "Update" buttons on legitimate websites, which when clicked trigger automated DMG file downloads and the evasion of macOS Gatekeeper to eventually install FrigidStealer, according to a Proofpoint report.
Despite featuring the same keystroke logging, screenshot capturing, and clipboard data gathering capabilities as earlier versions, such novel Snake Keylogger variant leverages an AutoIT-compiled binary as an executable file, which allows more effective concealment of malicious activity, a report from Fortinet FortiGuard Labs showed.
Intrusions involved the exploitation of an enterprise resource planning system's SQL injection vulnerability to facilitate the deployment of China Chopper and Behinder web shells, reconnaissance and lateral movement efforts, and the distribution of updated Winnti malware.
Mustang Panda commences intrusions with the delivery of spear-phishing emails with a malicious attachment that deploys malware components and legitimate files, as well as a PDF lure, according to an analysis from Trend Micro.
Execution of the payload, dubbed Trojan.Generic.37477095, triggers the "installSelf" function that ensures operation from the intended location before establishing C2 through a Telegram-interacting open-source package, according to an analysis from Netskope.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.