More than 2,000 computers across Ukraine were noted by the country's Computer Emergency Response Team to have been compromised as part of a widespread attack campaign with the modular Windows botnet payload PurpleFox, also known as DirtyMoe, which could be leveraged to facilitate further payload deployment and distributed denial-of-service intrusions, BleepingComputer reports.
Popular instant messaging service Telegram has become a haven for cybercriminals and other threat actors looking to conduct phishing attacks due to the widespread availability of malicious tools and hackers-for-hire services across the platform, according to The Hacker News.
Health, transportation, logistics, and transportation organizations across Italy have been targeted by the UNC4990 threat operation in a new attack campaign involving weaponized USB drives used to facilitate the distribution of malware hosted on widely used websites, reports The Hacker News.
More sophisticated attack techniques have been integrated into the updated version of the Zloader malware also known as Silent Night, DELoader, and Terdot distributed in a campaign almost two years after the botnet had its infrastructure disrupted, according to The Hacker News.
Operations of the Grandoreiro banking trojan have been dismantled by the Federal Police of Brazil with the help of Interpol, the Spanish National Police, ESET, and Caixa Bank, BleepingComputer reports.
This week in the Security Weekly News: the NSA admits to secretly buying your internet browsing data, malicious Google ads target Chinese users, Juniper releases update for Junos OS flaws, Outlook could be leaking your NTLM passwords, WhiteSnake malware on Windows, Jason Wood discusses new guidance on the Microsoft "Midnight Blizzard" attack, and m...
Malicious Google ads for Telegram, LINE, and other messaging apps banned in China have been used to facilitate a malvertising campaign against Chinese-speaking users, which is part of a series of attacks involving fraudulent WhatsApp and Telegram ads aimed at Hong Kong-based users in October, reports The Hacker News.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.