More than 300 SMTP servers have been leveraged by yet-to-be-identified threat actors to facilitate the automated distribution of phishing emails purporting to be business proposals, contracts, or promotional materials from widely known brands, according to an analysis from CloudSEK.
Threat actors commenced scanning vulnerable online webcams and DVRs in the U.S., Canada, Australia, New Zealand, and the UK impacted by the CVE-2017-7921, CVE-2018-9995, CVE-2020-25078, CVE-2021-33044, and CVE-2021-36260 flaws, as well as default passwords, which were later compromised through the open-source authentication brute-force tool Medusa.
Android devices compromised by BADBOX, which include phones, tablets, media players, and digital picture frames, could be leveraged not only for residential proxy service purposes that enable stealthy internet traffic routing but also to establish Gmail and WhatsApp accounts.
Aside from targeting the widely used PHP frameworks ThinkPHP, Laravel, Dedecms, and Yii in code injection attacks, Glutton has also been leveraged to exfiltrate data from the Chinese server management tool Baota, an analysis from QAX's XLab research team revealed.
Attacks with Pumakit commence with the deployment of the cron dropper, which executes the '/memfd:tgt' and '/memfd:wpn' payloads, with the former eventually launching the 'puma.ko' LKM rootkit module that loads only after ensuring secure boot status and performing kernel symbol scanning.
Malicious battery charge tracking and photo gallery apps, as well as a phony Samsung Knox app and trojanized Telegram app, have been leveraged to distribute the similar BoneSpy and PlainGnome spyware, which facilitate compromise of device location, call logs, contact lists, SMS messages, and other sensitive information.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.