Such malware compromise, which was only identified in late September, has impacted login information, names, phone numbers, emails, shipping and billing addresses, and payment card details with CVV codes and expiration dates belonging to individuals who had visited the SelectBlinds website's check-out page.
Attacks involving Winos4.0 commence with the retrieval of a bogus BMP file and the eventual extraction of the "you.dll" file, which downloads additional files to facilitate the installation of API-loading shellcode and the launching of a DLL file that facilitates crash restarts, clipboard content recording, system information gathering, and crypto wallet extension and antivirus app monitoring.
Threat actors using an account from a previously targeted organization dubbed "Org A" impersonated IT staff to target employees of a U.S. critical infrastructure entity dubbed "Org C" with Teams messages seeking remote system access permissions via Quick Assist, an analysis from Hunters revealed.
Malicious posts detailing instructions for downloading cracked software on torrent trackers and forums enable deployment of SteelFox and acquisition of administrator access, which is then leveraged to establish a WinRing0.sys driver susceptible to privilege escalation via the CVE-2020-14979 and CVE-2021-41285 flaws, according to an analysis from Kaspersky.
In the news: Pacific Rim, Linux on Windows for attackers, one of the worst cases of a former employee's retaliation, Zery-Day FOMO, we predicted that, hacking for fun, working hard for no PoC, an LLM that discovers software vulnerabilities, absurd fines, long usernames and Okta, and paying a ransom with dough!
Malicious emails purporting to be invoices that contain ZIP attachments have been delivered to facilitate the execution of a WebDAV-retrieved DLL that loads the updated Strela Stealer variant.
Widely used apps, including Google Chrome and Visa, have been impersonated by ToxicPanda, which when installed not only aims for privilege escalation and user input modification but also one-time password compromise to facilitate on-device fraud involving unauthorized money transfers.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.