Several threat operations including Sangria Tempest or FIN7, Storm-0569, Storm-1674, and Storm-1113 have exploited Microsoft's "ms-appinstaller protocol" for expediting Windows app installation to facilitate malware distribution, resulting in the deactivation of the protocol, reports The Record, a news site by cybersecurity firm Recorded Future.
Hundreds of cyberattacks daily have been spreading the novel Rugmi malware loader in October and November, representing a significant increase from the single-digit daily detections of the trojan beforehand, The Hacker News reports.
Ukraine has been noted by its Computer Emergency Response Team to be subjected to attacks by Russian state-backed threat operation APT28, also known as Strontium or Fancy Bear, deploying the novel MASEPIE malware downloader, according to BleepingComputer.
Threat actors have been targeting insecure Linux SSH servers with dictionary attack tools and port scanners in a bid to facilitate cryptocurrency mining and distributed denial-of-service attacks, The Hacker News reports.
New Nim-based malware, Editbot Stealer emerge Malicious Microsoft Word documents to facilitate the distribution of Nim-based malware, which has only recently gained traction with the emergence of the Nimbda and NimzaLoader malware loaders, according to The Hacker News.