Installation of the malware in targeted routers facilitates the deployment of a cd00r variant scanning for five network signals, which when received triggers reverse shell creation on the local file system, enabling device takeover, data exfiltration, and additional malware compromise, according to an investigation by Black Lotus Labs researchers.
Attackers who made fraudulent but verified Ross Ulbricht accounts on X, formerly Twitter, sought to lure users into joining Telegram channels purporting to be Ulbricht portals, which provided a walk through on the bogus Safeguard identity verification process leading to a Telegram mini app with a hoax verification dialog.
Execution of a trojanized installer triggers deployment of a loader with another DLL eventually resulting in the running of SlowStepper, which supports commands enabling extensive system info theft, file deletion, Python module execution, and self-deletion, an analysis from ESET revealed.
The meeting, which was called for by the United States and 15 other nations, sought to address the proliferation and misuse of government and mercenary spyware.
Attackers have used a malicious Google ad with Homebrew's proper "brew.sh" URL to redirect to the typosquatted "brewe[.]sh" site, which lures targets into downloading the package manager that enables infostealer malware execution, according to security researcher Ryan Chenkie.
Threat actors leveraged a phishing webpage luring targets into downloading a legitimate software-spoofing Microsoft Installer package that conceals its malicious nature by launching the app while executing a malicious DLL to deploy the multi-stage PNGPlug loader, a report from Intezer showed.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.