Threat actor solana-web-stable-huks' "solana-transaction-toolkit" and "solana-stable-web-huks" packages not only compromised Solana private keys through Nodemailer but also enabled the automated transfer of 98% of the targeted cryptocurrency wallets' assets to an attacker-controlled Solana address, according to a Socket analysis.
Installation of Tanzeem or Tanzeem Update triggers a bogus chat page containing a "Start Chat" button, which when clicked would lure targets into permitting accessibility permissions as the app seeks permissions enabling contact, call log, location, account information, and external storage file exfiltration activities, according to an analysis from Cyfirma.
Both campaigns involved the distribution of malicious emails purporting to be invoices, purchase orders, or quotation requests with attachments, which when opened triggers a PowerShell script fetching the trojanized image and executing a .NET-based loader to launch the payloads.
Attacks part of the campaign involved the delivery of phishing emails purporting to be freight invoices from DHL Express, which included a ZIP archive with a JavaScript file that facilitated the execution of a PowerShell script communicating with the attacker-controlled command-and-control server, according to an analysis from Infoblox.
Threat actors impersonating recruiters on LinkedIn provide targeted software developers with project tests and code reviews that redirect to malicious GitLab repositories that facilitate the distribution of modular information-stealing malware compatible with Windows, macOS, and Linux systems, a report from SecurityScorecard showed.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.