Aside from featuring Chacha 20 encryption retained from older variants of the ransomware, Qilin.B has been strengthened with AES-256-CTR encryption, which could be leveraged to compromise AESNI-capable systems, as well as RSA-4096 with OAEP padding.
Identification of a Manscrypt backdoor malware compromise in May prompted the discovery of early exploitation of the Chrome vulnerability through the "detankzone[.]com" website for the fake NFT-based multiplayer online battle arena game DeTankZone, which contains source code stolen from the DeFiTankLand game.
Aside from determining the utilization of anti-malware solutions and banking security software in targeted systems, Grandoreiro has been enhanced with a CAPTCHA barrier, as well as keystroke logging, Outlook spam email discovery, and Outlook email keyword hunting capabilities, according to a Kaspersky analysis.
Malicious emails with phishing links have been leveraged to launch either remote access trojan but while DCRat has been deployed through a remote HTML file, PowerRAT has been spread through a malicious Microsoft Word file that executes a rogue Visual Basic macro.
Organizations in the financial, healthcare, and automotive industries have been primarily subjected to such attacks, which commence with the delivery of malicious emails with HTML or PDF attachments that launch a DLL resulting in the installation of Latrodectus.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.