Threat actors have leveraged a VBA downloader, VBA dropper, executable downloader, and link downloader to deploy the novel Fickle Stealer malware, Security Affairs reports.
SecurityWeek reports that organizations across China have been targeted with attacks using the new SquidLoader malware loader to deliver a Cobalt Strike beacon similarly configured as one used in previous campaigns against Chinese-speaking users.
Malicious MSI installers containing artificial intelligence tools, VPN clients, and Chinese language packs have been utilized by the new Void Arachne threat operation to target Chinese-speaking users with the WInos 4.0 backdoor, reports The Cyber Express.
Intrusions leveraging the fraudulent virtual meeting software Vortax have been launched by the threat actor dubbed "markopolo" as part of a sweeping cross-platform scam distributing the Atomic macOS Stealer, Rhadamanthys, and StealC payloads for cryptocurrency exfiltration activities, according to The Hacker News.
A Cisco Webex Meetings app disguised as free or cracked copies of the software have been launched to facilitate the deployment of the Vidar Stealer malware.
Ticketmaster and other organizations had their Snowflake accounts claimed to be compromised by a ShinyHunters hacker through the breach of software engineering firm EPAM Systems, supporting a Mandiant report linking some of the breaches to third-party contractor hacks, reports Wired.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.