Attacks with the new Coyote trojan variant over the past month involved the deployment of an LNK file executing a PowerShell command facilitating next-stage PowerShell script retrieval for the eventual launching of the trojan, which not only obtained system details and an antivirus product list but also sought to bypass sandbox discovery, according to a Fortinet FortiGuard Labs study.
Execution of the nefarious DeepSeek-spoofing "deepseeek" and "deepseekai" packages enabled the theft of user and system information, as well as database credentials.
Aside from being composed of half a dozen sub-teams distributing the StealC and AMOS stealers masquerading as WeChat, Zoom, Selenium Finance, and other platforms, Crazy Evil also sought to provide crypter services for various malware, a report from Recorded Future's Insikt Group revealed.
Attackers who targeted Casio UK's website between Jan. 14 and 24 deployed a two-stage skimmer that consisted of an unobfuscated loader purporting to be a third-party script that triggers the second-stage skimmer that not only encrypted and exfiltrated contact information, credit card details, and billing addresses but also concealed malicious activity through XOR-based string masking and custom encoding.
Advanced Pakistani cybercrime network HeartSender, also known as Saim Raza, had its operations disrupted by the U.S. Department of Justice and Dutch National Police following the sequestration of its domains and servers as part of "Operation Heart Blocker," reports CyberScoop.
Based on reporting from SecurityScorecard's STRIKE team, the North Korean state-backed threat actor employs a React and Node.js-based system in each C2 server to enable centralized management of stolen data, observation of compromised hosts, and payload distribution.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.