Chinese-linked ValleyRAT trojan has been updated to include screenshot capturing, process filtering, Windows event log deletion, and forced shutdown capabilities as part of a new malware attack campaign, The Hacker News reports.
Threat actors launched an unsuccessful phishing attack against an industrial services firm last month that distributed the more_eggs malware with data exfiltration capabilities via fake resumes, which had been leveraged to spread the malware over two years ago, The Hacker News reports.
Attacks with the SPECTR information-stealing malware were discovered by Ukraine's Computer Emergency Response Team to have been deployed against the country's defense forces by Luhansk People's Republic-associated threat operation UAC-0020, also known as Vermin, as part of its SickSync cyberespionage campaign, The Hacker News reports.
More than 300 Russian defense, tech, manufacturing, aerospace, and education entities have been subjected to attacks by the Sapphire Werewolf hacking operation distributing the Amethyst information-stealing malware since March, reports The Record, a news site by cybersecurity firm Recorded Future.
Vulnerable Apache RocketMQ instances impacted by the critical remote code execution bug, tracked as CVE-2023-33246, are being targeted by the Muhstik botnet to facilitate more expansive distributed denial-of-service and cryptocurrency mining intrusions, reports The Hacker News.
Microsoft's new "Recall" feature, an artificial intelligence-powered functionality enabling the logging of past user activity in its recently introduced Copilot+ PCs, was regarded by cybersecurity researchers as vulnerable to cyberattacks that could compromise its stored data, Security Affairs reports.
Attacks with the DarkGate malware-as-a-service operation have since involved an AutoHotKey script instead of AutoIt ones to facilitate the stealthier distribution of the malware, according to The Hacker News.
App virtualization tool BoxedApp has been increasingly leveraged to facilitate the distribution of malicious payloads while bypassing static analysis during the past year, with threat actors particularly exploiting the tool's virtual storage, virtual processes, and virtual registry features, The Register reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.