Major U.S. oil and fuel distributor Atlas Oil has been claimed to be compromised by the Black Basta ransomware operation, which purportedly stole 730 GB of data, Security Affairs reports.
Blockchain gaming platform Gala Games had nearly $22.2 million worth of cryptocurrency exfiltrated following a cryptocurrency heist on the evening of May 20, reports The Record, a news site by cybersecurity firm Recorded Future.
Novel cryptomining attacks deploying the GhostEngine payload to deactivate endpoint detection and response systems and distribute the XMRig miner through vulnerable kernel driver exploitation were described in separate reports from Elastic Security Labs and Antiy, according to BleepingComputer.
BleepingComputer reports that Israel and Albania have been subjected to attacks with an updated version of the BiBi Wiper malware with disk partition table deletion capabilities, which has been linked with suspected Iranian state-sponsored hacking group Void Manticore, also known as Storm-842.
Sophisticated Russian threat operation GitCaught has exploited both GitHub and FileZilla to facilitate the deployment of several malicious payloads, including the Atomic macOS Stealer, or AMOS, as well as the Octo, Lumma, and Vidar information-stealing malware strains, Security Affairs reports.
Attacks exploiting a design vulnerability in the Foxit PDF reader have been launched by various threat actors to facilitate the delivery of several malicious payloads, including Agent Tesla, Remcos RAT, AsyncRAT, and XWorm, among others, reports The Hacker News.
Threat actors have been distributing the novel Antidot Android banking trojan as fraudulent Google Play updates to facilitate credential compromise and other malicious actions, SecurityWeek reports.
More phishing campaigns have been leveraging the Latrodectus malware loader since March, with the loader updated with more extensive enumeration and execution capabilities, as well as self-delete functionality, according to The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.