BleepingComputer reports that Indian state-sponsored hacking operation DoNot, also known as APT-C-35, has leveraged three Android apps published by SecurITY Industry on the Google Play Store as part of a spyware campaign aimed at facilitating intelligence-gathering efforts.
Nearly 40 web browsers and more than 70 browser extensions, as well as cryptocurrency wallets, Telegram, and Steam, could have their credentials and other data exfiltrated by the novel Mystic Stealer information-stealing malware, according to The Hacker News.
MacOS targeted by new advanced toolkit Three malicious samples collectively known as JokerSpy have been identified to form a novel elaborate toolkit aimed at compromising macOS devices, reports The Hacker News.
Threat actors have been distributing the DcRAT information-stealing malware, a modified AsyncRAT variant, through fraudulent lures for adult content subscription service OnlyFans and other adult content since January, according to BleepingComputer.