Attacks leveraging fraudulent Facebook job ads have been launched to facilitate the distribution of the new Ov3r_Stealer information-stealing malware that targets credentials, Microsoft Office documents, browser extensions, cryptocurrency wallets, and credit card information, according to The Hacker News.
Almost 150 Android devices across India and Pakistan have been compromised by suspected Indian state-sponsored threat operation PatchWork in a new attack campaign leveraging mostly messaging apps that have been laced with the VajraSpy remote access trojan, The Hacker News reports.
Mexico has been subjected to attacks with a new variant of the Mispadu banking trojan that involved the exploitation of a high-severity Windows SmartScreen vulnerability patched by Microsoft in November, according to The Hacker News.
Increasingly prevalent abuse of commercial spyware tools around the world has prompted the U.S. to introduce a new policy that would prohibit visas for individuals profiteering from commercial spyware, developing spyware, and managing companies providing such technologies to governments, reports The Record, a news site by cybersecurity firm Recorded Future.
TechCrunch reports that mobile consumer-grade stalkerware apps Highster and PhoneSpector have seemingly ended operations following a settlement between Patrick Hinchy, whose tech firm consortium was behind both apps, and the New York Attorney General last February that involved the payment of $410,000 in fines to resolve charges of aggressive spyware promotions in New York state.
Nearly half of the 2,300 internet-exposed Redis servers compromised with the HeadCrab malware as part of an attack campaign that was initially reported in early 2023 have been infected with an updated variant of the backdoor, according to The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.