Aside from leveraging Telegram bot API to facilitate stealthier exfiltration of targeted devices' sensitive and personal data, Angry Stealer has also been enhanced with the "MotherRussia.exe" payload, which could enable further malicious activity.
Aside from facilitating the comprehensive gathering and exfiltration of device information ManticoraLoader, which could be rented for $500 a month, also features extensive obfuscation capabilities enabling evasion of the 360 Total Security sandboxing tool, a report from Cyble Research and Intelligence Labs showed.
After obtaining initial network access through the exploitation of the VMware vulnerability, tracked as CVE-2023-38831, Head Mare proceeds with the deployment of the PhantomDL and PhantomCore backdoors that facilitate additional payload delivery.
Attackers who spoofed U.S., European, and Asian tax agencies distributed more than 20,000 phishing emails purporting to have updated tax information and links, which when clicked redirect to a search-ms URI file triggering a Python script that displays a decoy PDF while DLL side-loading Voldemort.
Attackers deliver phishing emails luring targets into installing the fraudulent GlobalProtect tool, which when executed triggers in-background malware loading during the setup process.
APT32's most recent attacks involved the compromise of four hosts with different Windows Registry keys and scheduled tasks that facilitated the deployment of Google Chrome cookie exfiltration, Cobalt Strike beacons, and embedded DLL payload loaders.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.